Dan ๐Ÿช›

744 posts

Dan ๐Ÿช›

Dan ๐Ÿช›

@gigdotzip

i like android framework/platform development, flutter, and linux.

18 he/him ๐Ÿ‡ฎ๐Ÿ‡น๐Ÿ‡จ๐Ÿ‡ฟ ๊ฐ€์ž…์ผ Ocak 2022
219 ํŒ”๋กœ์ž‰212 ํŒ”๋กœ์›Œ
abu bouli al boulali
abu bouli al boulali@searchspIoitยท
@gigdotzip @fs0c131y Vous pouvez obtenir le token d'une victime (entiรจrement rรฉutilisable) en lui faisant scanner un QR code mdr
Franรงais
1
0
0
69
Baptiste Robert
Baptiste Robert@fs0c131yยท
Je confirme, Paul is right
Paul Moore - Security Consultant ๎จ€@Paul_Reviews

Hacking the #EU #AgeVerification app in under 2 minutes. During setup, the app asks you to create a PIN. After entry, the app *encrypts* it and saves it in the shared_prefs directory. 1. It shouldn't be encrypted at all - that's a really poor design. 2. It's not cryptographically tied to the vault which contains the identity data. So, an attacker can simply remove the PinEnc/PinIV values from the shared_prefs file and restart the app. After choosing a different PIN, the app presents credentials created under the old profile and let's the attacker present them as valid. Other issues: 1. Rate limiting is an incrementing number in the same config file. Just reset it to 0 and keep trying. 2. "UseBiometricAuth" is a boolean, also in the same file. Set it to false and it just skips that step. Seriously @vonderleyen - this product will be the catalyst for an enormous breach at some point. It's just a matter of time.

Portuguรชs
13
67
471
90.7K
Dan ๐Ÿช› ๋ฆฌํŠธ์œ—ํ•จ
Vadim Yuryev
Vadim Yuryev@VadimYuryevยท
Seriously just stop.. I HATE when Windows Laptop vendors sacrifice user experience for a couple of bucks from McAfee and Dropbox.. THIS is why people buy MacBooks
Vadim Yuryev tweet media
English
194
126
3K
85.5K
Dan ๐Ÿช› ๋ฆฌํŠธ์œ—ํ•จ
vx-underground
vx-underground@vxundergroundยท
The fundamental problem with this "hack" is it requires three things being true. 1. An attacker must possess the device 2. An attacker must be able to unlock the cell phone 3. The cell phone must be "rooted", all additional cell phone security already bypassed In the event all three of these conditions are true, you have far greater issues than someone modifying the PIN on your age verification app or... verify they're an adult using your stuff. If you want to do this, for whatever reason, using this you can now reset the PIN on your age verification app arbitrarily or give yourself unlimited verifications.
Paul Moore - Security Consultant ๎จ€@Paul_Reviews

Hacking the #EU #AgeVerification app in under 2 minutes. During setup, the app asks you to create a PIN. After entry, the app *encrypts* it and saves it in the shared_prefs directory. 1. It shouldn't be encrypted at all - that's a really poor design. 2. It's not cryptographically tied to the vault which contains the identity data. So, an attacker can simply remove the PinEnc/PinIV values from the shared_prefs file and restart the app. After choosing a different PIN, the app presents credentials created under the old profile and let's the attacker present them as valid. Other issues: 1. Rate limiting is an incrementing number in the same config file. Just reset it to 0 and keep trying. 2. "UseBiometricAuth" is a boolean, also in the same file. Set it to false and it just skips that step. Seriously @vonderleyen - this product will be the catalyst for an enormous breach at some point. It's just a matter of time.

English
55
61
852
76.6K
Liam Castaigne
Liam Castaigne@voird33rยท
@fs0c131y What's the threat model here? An attacker has ADB access to your device? The biometrics are there to stop minors living in your home (like your kids) from using your age verification credentials. You could argue it should be more locally secure, but calling it a bypass is silly.
English
1
0
4
191
Dan ๐Ÿช›
Dan ๐Ÿช›@gigdotzipยท
@fs0c131y here's what happens on an unrooted Pixel 7A for reference. literally where is the security issue here?
Dan ๐Ÿช› tweet media
English
1
0
1
109
Dan ๐Ÿช›
Dan ๐Ÿช›@gigdotzipยท
@fs0c131y If a malicious actor has root permissions on your phone then you have other issues mate. Can you reproduce it on a phone/emulator without adb root and Magisk? Itโ€™s not good that they put it in shared preferences but itโ€™s not that big of a deal especially since itโ€™s a demo
English
1
0
0
247
Dan ๐Ÿช› ๋ฆฌํŠธ์œ—ํ•จ
NikTek
NikTek@NikTekยท
The craziest thing ever happened on YouTube. La7, an Italian television channel has used footage from Nvidia DLSS 5 Trailer and then sent a copyright strike to every YouTube video that supposedly used โ€œtheir footageโ€, including Nvidia themselves. Nvidiaโ€™s own DLSS 5 announcement video has now been taken down by La7 as you can see here.
NikTek tweet mediaNikTek tweet media
English
1.1K
3.4K
53.5K
4.3M
Dan ๐Ÿช› ๋ฆฌํŠธ์œ—ํ•จ
Jehff Mk. III
Jehff Mk. III@JehffMacbookยท
@MNateShyamalan bespoke; confidently using only semicolons even though youre doing it wrong 90% of the time
English
1
11
119
3.7K
Dan ๐Ÿช› ๋ฆฌํŠธ์œ—ํ•จ
soul nate
soul nate@MNateShyamalanยท
TIRED: using โ€œโ€”โ€œ and everyone thinks youโ€™re a bot WIRED: never learning the difference between colons and semicolons: dont let it stop you INSPIRED: assert dominance with the mega-hyphen. itโ€™s not just punctuation โ€”โ€”โ€”โ€”โ€” itโ€™s a statement.
English
30
1.9K
18.7K
216.8K
Dan ๐Ÿช› ๋ฆฌํŠธ์œ—ํ•จ
P
P@makecazznesoยท
Meloni con i bambini del bosco ora che ha vinto il NO
Italiano
2
78
2.1K
25.8K
Dan ๐Ÿช› ๋ฆฌํŠธ์œ—ํ•จ
Yannick Comte
Yannick Comte@cyannickยท
This is it, native PCVR on MacOS! The OpenXR SDK can be compiled on MacOS, So I implemented a runtime and a streaming app. Godot supports OpenXR on MacOS so I use it to test my integration. Unity could work too and of course native C++. 1/x
English
22
47
387
36.8K
Dan ๐Ÿช› ๋ฆฌํŠธ์œ—ํ•จ
Francesco
Francesco@Franker_Tacoยท
E anche il voto delle diciottenni del booktok รจ conquistato, per una volta ottima mossa smm del PD!
Italiano
0
18
938
39.6K
Dan ๐Ÿช› ๋ฆฌํŠธ์œ—ํ•จ
sankalp
sankalp@dejavucoderยท
claude after compaction
sankalp tweet media
English
30
73
2.7K
76.6K
Dan ๐Ÿช› ๋ฆฌํŠธ์œ—ํ•จ
๐ŸŽญ
๐ŸŽญ@deepfatesยท
Opus 4.6 be like "Did you want to actually get that done right now, or just pretend we did and call it done? The first would be a big push. The second is a much simpler option. "
English
15
13
473
14.9K
Dan ๐Ÿช› ๋ฆฌํŠธ์œ—ํ•จ
Buzzo
Buzzo@biasinvermeยท
A metร  funerale di Roberto Benigni dovrebbe essere organizzato uno show di intervallo tipo Superbowl
Italiano
32
160
2.5K
85.3K
Dan ๐Ÿช› ๋ฆฌํŠธ์œ—ํ•จ
liam
liam@DrDomodoPhDยท
that part of the haircut where you realize it wouldโ€™ve been better to have never been born than to suffer this fate
English
50
5.1K
54.7K
642.7K
Dan ๐Ÿช› ๋ฆฌํŠธ์œ—ํ•จ
Incentivising
Incentivising@incentivisingยท
"Disappearing for 6 months" is literally the dumbest thing you can do. You will lose most of your contacts, lose leverage across the board, and slowly become irrelevant. People will learn to live without you; that's what humans do. They adapt. And then, when you return, they will perhaps be happy, but you will be demoted to a short 'novelty'. If you truly want to change, do it without the unnecessary disappearing. You're not a ghost.
English
218
556
7.5K
543.3K
Dan ๐Ÿช› ๋ฆฌํŠธ์œ—ํ•จ
rose โ™ก
rose โ™ก@RoseZBatยท
streaming your game for someone is a form of intimacy
English
123
6.9K
64.3K
1.4M