Hrollod
40 posts

Hrollod
@hrollod
Soy un apasionado de la informática, los videojuegos y la tecnología.


imagínate llevar parado media hora en el puto tren, sabiendo que vas a llegar tarde por quinta vez esta semana al trabajo y tu curro pende de un hilo y para rematar se te ponen las paletas de turno a cantar y bailar "la morocha" creo que me suicidaría delante de todo el vagón





El fundador de Telegram afirma que hackeó la app europea para verificar la edad de usuarios. theobjective.com/tecnologia/202…










Hacking the #EU #AgeVerification app in under 2 minutes. During setup, the app asks you to create a PIN. After entry, the app *encrypts* it and saves it in the shared_prefs directory. 1. It shouldn't be encrypted at all - that's a really poor design. 2. It's not cryptographically tied to the vault which contains the identity data. So, an attacker can simply remove the PinEnc/PinIV values from the shared_prefs file and restart the app. After choosing a different PIN, the app presents credentials created under the old profile and let's the attacker present them as valid. Other issues: 1. Rate limiting is an incrementing number in the same config file. Just reset it to 0 and keep trying. 2. "UseBiometricAuth" is a boolean, also in the same file. Set it to false and it just skips that step. Seriously @vonderleyen - this product will be the catalyst for an enormous breach at some point. It's just a matter of time.




Heu ... lol C'est le SDK du wallet de l'European Digital Identity ça ? Dites moi que c'est une blague pitié 🤣 Le MITM documenté c'est pour la police ou le cab du premier ministre ? #scoped-issuance-document-configuration" target="_blank" rel="nofollow noopener">ageverification.dev/av-app-ios-wal…







