Grumpy Eir Lady
48.6K posts

Grumpy Eir Lady
@Grumpy_Eir
Finally on Twitter. I hope I won't regret registering:)




Hacking the #EU #AgeVerification app in under 2 minutes. During setup, the app asks you to create a PIN. After entry, the app *encrypts* it and saves it in the shared_prefs directory. 1. It shouldn't be encrypted at all - that's a really poor design. 2. It's not cryptographically tied to the vault which contains the identity data. So, an attacker can simply remove the PinEnc/PinIV values from the shared_prefs file and restart the app. After choosing a different PIN, the app presents credentials created under the old profile and let's the attacker present them as valid. Other issues: 1. Rate limiting is an incrementing number in the same config file. Just reset it to 0 and keep trying. 2. "UseBiometricAuth" is a boolean, also in the same file. Set it to false and it just skips that step. Seriously @vonderleyen - this product will be the catalyst for an enormous breach at some point. It's just a matter of time.

State spends €1.8m fighting court cases against families seeking special education classes for their children irishexaminer.com/news/arid-4182…







ICYMI - OpenAI's Sam Altman warns that the next AI models could be misused by terrorist groups to create novel pathogens, "that's no longer a theoretical thing, or it's not going to be for much longer," and agrees that there could be a "world shaking cyber attack this year."


🇪🇺 EU’s central age verification app is ready to use. The app: 1) Is user-friendly: upload your passport and you’re done. 2) Is anonymous—users can’t be tracked. 3) Works on all devices. 4) Is open source, so others can implement it.
















