Amyd Caballero

5.9K posts

Amyd Caballero banner
Amyd Caballero

Amyd Caballero

@Amyd_Samo

Founder. @_Think_AI - The power of an LLM rises on the creativity of the human mind to create words that materialize a digital action.

Mexico Bergabung Ocak 2021
44 Mengikuti145 Pengikut
Beaver 🦁
Beaver 🦁@beaverd·
They waited for me to pay my taxes so they could de-bank me Unfortunately for them, this is EXTREMELY anti-semetic.
Beaver 🦁 tweet media
English
24
15
657
25.7K
Amyd Caballero me-retweet
Het Mehta
Het Mehta@hetmehtaa·
Be Anthropic > Give people Opus 4.6 > People love it. > For 2 months you degrade Opus 4.6 > You give back normal Opus 4.6 and call it Opus 4.7. > People love it. That's the business model.
English
223
599
13.5K
443.8K
james hawkins
james hawkins@james406·
well this is a first
james hawkins tweet media
English
38
79
6.5K
403.5K
Paul Moore - Security Consultant 
Hacking the #EU #AgeVerification app in under 2 minutes. During setup, the app asks you to create a PIN. After entry, the app *encrypts* it and saves it in the shared_prefs directory. 1. It shouldn't be encrypted at all - that's a really poor design. 2. It's not cryptographically tied to the vault which contains the identity data. So, an attacker can simply remove the PinEnc/PinIV values from the shared_prefs file and restart the app. After choosing a different PIN, the app presents credentials created under the old profile and let's the attacker present them as valid. Other issues: 1. Rate limiting is an incrementing number in the same config file. Just reset it to 0 and keep trying. 2. "UseBiometricAuth" is a boolean, also in the same file. Set it to false and it just skips that step. Seriously @vonderleyen - this product will be the catalyst for an enormous breach at some point. It's just a matter of time.
Paul Moore - Security Consultant @Paul_Reviews

.@vonderleyen "The European #AgeVerification app is technically ready. It respects the highest privacy standards in the world. It's open-source, so anyone can check the code..." I did. It didn't take long to find what looks like a serious #privacy issue. The app goes to great lengths to protect the AV data AFTER collection (is_over_18: true is AES-GCM'd); it does so pretty well. But, the source image used to collect that data is written to disk without encryption and not deleted correctly. For NFC biometric data: It pulls DG2 and writes a lossless PNG to the filesystem. It's only deleted on success. If it fails for any reason (user clicks back, scan fails & retries, app crashes etc), the full biometric image remains on the device in cache. This is protected with CE keys at the Android level, but the app makes no attempt to encrypt/protect them. For selfie pictures: Different scenario. These images are written to external storage in lossless PNG format, but they're never deleted. Not a cache... long-term storage. These are protected with DE keys at the Android level, but again, the app makes no attempt to encrypt/protect them. This is akin to taking a picture of your passport/government ID using the camera app and keeping it just in case. You can encrypt data taken from it until you're blue in the face... leaving the original image on disk is crazy & unnecessary. From a #GDPR standpoint: Biometric data collected is special category data. If there's no lawful basis to retain it after processing, that's potentially a material breach. youtube.com/watch?v=4VRRri…

English
599
5.4K
21.9K
2.7M
Amyd Caballero me-retweet
rabbitholebot
rabbitholebot@rabbitholebot·
rabbitholebot tweet media
ZXX
13
1.4K
14.2K
74.3K
Amyd Caballero me-retweet
Kruptos
Kruptos@KuptoKosmos·
🇪🇺 L’app European Age Verification est vendue comme open source, privacy-by-design et ultra-respectueuse de la vie privée... ⚠️ Pourtant, sa doc officielle donne le mode d’emploi exact pour que quelqu’un (police, services de renseignement, cabinet du Premier ministre…) puisse se placer au milieu des échanges de l’app et lire ou modifier les données en toute discrétion !! 🚨 La backdoor MITM est intégrée au cœur technique de tout le projet EUDI Wallet / European Digital Identity Dites non à la surveillance de masse abusive et protégez le futur de vos enfants contre ces gens 🤥 👁️ #AgeVerification #Backdoor
Kruptos tweet mediaKruptos tweet mediaKruptos tweet media
☠ Bluetouff@bluetouff

Heu ... lol C'est le SDK du wallet de l'European Digital Identity ça ? Dites moi que c'est une blague pitié 🤣 Le MITM documenté c'est pour la police ou le cab du premier ministre ? #scoped-issuance-document-configuration" target="_blank" rel="nofollow noopener">ageverification.dev/av-app-ios-wal…

Français
96
2.5K
7.5K
375.7K
EndeavourOS
EndeavourOS@OsEndeavour·
@Amyd_Samo This looks like a very specific issue, concerning your setup or even hardware settings. I suggest looking for help on our forum for a faster response. forum.endeavouros.com
English
1
0
1
22
Amyd Caballero
Amyd Caballero@Amyd_Samo·
@OsEndeavour Hey guys! Where can I help yall fix some problems with the software? I recently setup the OS on one of my machines and there are a lot of problems, I would like to help. Cheers.
English
1
0
0
15
Amyd Caballero
Amyd Caballero@Amyd_Samo·
I’m glad I built V4 Jarvis Open Source for Open Source LLMs specifically. This is getting a lil crazy.
English
0
0
0
10
Amyd Caballero
Amyd Caballero@Amyd_Samo·
@ZynxBTC This doctor came out of nowhere. And started saying very weird things. I hope he himself is not a CIA psyop.
English
0
0
0
25
Zynx
Zynx@ZynxBTC·
Bitcoin is ultimately an IQ test and this "Professor" has failed. 1) It doesn't matter who created it. It is decentralised and controlled by no single entity. That's kind of the whole point. 2) As for "where are the blockchain servers?" They're everywhere. Tens of thousands of nodes running across the globe. No single point of failure. No off switch. It's been 17 years and they still fail to understand the basics. It's okay to say "I don't know" sometimes, you know.
Watcher.Guru@WatcherGuru

JUST IN: 🇨🇳 Popular Chinese commentator 'Professor Jiang' claims Bitcoin is a "CIA operation."

English
428
341
4.5K
362.7K
Politics UK
Politics UK@PolitlcsUK·
🚨 NEW: MPs have voted against banning social media for under-16s for the second time Yes: 150 No: 256
English
199
495
6.5K
305.8K
MJ
MJ@mjackson·
This is wrong. Open source isn’t dead just because AI can more easily reverse engineer your codebase. AI can reverse engineer your closed source system just as easily. The solution isn’t to hide the source. The solution is transparency, publishing advisories, and hardening.
Bailey Pumfleet@pumfleet

Open source is dead. That’s not a statement we ever thought we’d make. @calcom was built on open source. It shaped our product, our community, and our growth. But the world has changed faster than our principles could keep up. AI has fundamentally altered the security landscape. What once required time, expertise, and intent can now be automated at scale. Code is no longer just read. It is scanned, mapped, and exploited. Near zero cost. In that world, transparency becomes exposure. Especially at scale. After a lot of deliberation, we’ve made the decision to close the core @calcom codebase. This is not a rejection of what open source gave us. It’s a response to what risks AI is making possible. We’re still supporting builders, releasing the core code under a new MIT-licensed open source project called cal. diy for hobbyists and tinkerers, but our priority now is simple: Protecting our customers and community at all costs. This may not be the most popular call. But we believe many companies will come to the same conclusion. My full explanation below ↓

English
51
37
354
30.2K
Amyd Caballero
Amyd Caballero@Amyd_Samo·
@mitsuhiko Btw V4 Jarvis does everything their app does and with immense amount of security and privacy. Something to think about….
English
0
0
0
6
Amyd Caballero
Amyd Caballero@Amyd_Samo·
@mitsuhiko They think that close sourcing will automatically fix their shitty cybersecurity. Excuses only.
English
1
0
0
35
Armin Ronacher ⇌
Armin Ronacher ⇌@mitsuhiko·
We have to close source because AI finds out security issues is a pretty weak argument honestly.
Bailey Pumfleet@pumfleet

Open source is dead. That’s not a statement we ever thought we’d make. @calcom was built on open source. It shaped our product, our community, and our growth. But the world has changed faster than our principles could keep up. AI has fundamentally altered the security landscape. What once required time, expertise, and intent can now be automated at scale. Code is no longer just read. It is scanned, mapped, and exploited. Near zero cost. In that world, transparency becomes exposure. Especially at scale. After a lot of deliberation, we’ve made the decision to close the core @calcom codebase. This is not a rejection of what open source gave us. It’s a response to what risks AI is making possible. We’re still supporting builders, releasing the core code under a new MIT-licensed open source project called cal. diy for hobbyists and tinkerers, but our priority now is simple: Protecting our customers and community at all costs. This may not be the most popular call. But we believe many companies will come to the same conclusion. My full explanation below ↓

English
28
33
439
34.2K
Amyd Caballero me-retweet
Andrey
Andrey@thisiswhyibuilt·
@vxdb Because they can't verify whether the app is authentic or what it actually does.
English
2
0
2
921