Zeth

294 posts

Zeth banner
Zeth

Zeth

@0xZeth

Katılım Temmuz 2024
125 Takip Edilen7 Takipçiler
Paul Moore - Security Consultant 
Bypassing #EU #AgeVerification using their own infrastructure. I've ported the Android app logic to a Chrome extension - stripping out the pesky step of handing over biometric data which they can leak... and pass verification instantly. Step 1: Install the extension Step 2: Register an identity (just once) Step 3: Continue using the web as normal The extension detects the QR code, generates a cryptographically identical payload and tells the verifier I'm over 18, which it "fully trusts". This isn't a bug... it's a fundamental design flaw they can't solve without irrevocably tying a key to you personally; which then allows tracking/monitoring. Of course, I could skip the enrolment process entirely and hard-code the credentials into the extension... and the verifier would never know.
Paul Moore - Security Consultant @Paul_Reviews

Hacking the #EU #AgeVerification app in under 2 minutes. During setup, the app asks you to create a PIN. After entry, the app *encrypts* it and saves it in the shared_prefs directory. 1. It shouldn't be encrypted at all - that's a really poor design. 2. It's not cryptographically tied to the vault which contains the identity data. So, an attacker can simply remove the PinEnc/PinIV values from the shared_prefs file and restart the app. After choosing a different PIN, the app presents credentials created under the old profile and let's the attacker present them as valid. Other issues: 1. Rate limiting is an incrementing number in the same config file. Just reset it to 0 and keep trying. 2. "UseBiometricAuth" is a boolean, also in the same file. Set it to false and it just skips that step. Seriously @vonderleyen - this product will be the catalyst for an enormous breach at some point. It's just a matter of time.

English
268
3.1K
12.3K
1.2M
Ali IDRISSI
Ali IDRISSI@MacroPsychoKine·
@manniefabian But why are you ignoring the fact that this is the plan for underground terror tunnels in Arad, "Israel", used to attack Iran?Stop using settlers as human shields.
English
1
2
7
675
Emanuel (Mannie) Fabian
Emanuel (Mannie) Fabian@manniefabian·
The wounded toll of the Iranian ballistic missile impact in the southern city of Arad rises to 64, Magen David Adom says. They include seven people in serious condition, 15 in moderate condition, and 42 others lightly hurt, according to the ambulance service. MDA says it is continuing to scan the scene for additional casualties. The 64 victims are being taken to hospitals by dozens of MDA ambulances, as well as MDA and Israeli Air Force helicopters.
English
11
41
131
28.7K
Faytuks Network
Faytuks Network@FaytuksNetwork·
WATCH: Israeli airstrike near RT reporter. RT reports its correspondent Steve Sweeney and a cameraman were wounded in an Israeli strike in southern Lebanon today. Lebanon’s state news agency says two journalists were lightly injured during an IDF strike on the al-Qasmiya bridge.
English
117
287
1.4K
512.7K
Dillon Mulroy
Dillon Mulroy@dillon_mulroy·
can't believe they renewed wordpress crash out for season 2
English
19
8
353
22.8K
Faytuks Network
Faytuks Network@FaytuksNetwork·
BREAKING: Two U.S. KC-135 refueling aircraft were involved in an apparent accident during Operation Epic Fury, U.S. Central Command says. One tanker crashed in western Iraq while the second landed safely. The incident was not caused by hostile or friendly fire.
English
34
97
724
65.9K
Zeth
Zeth@0xZeth·
@Tom663978014096 @gannemans @VP @BillWhiteUSA Why would they need to give any info alongside it? Thats why i hate reporting just say whatever happened without any opinion on it. We don’t need ur opinion.
English
1
0
2
37
Tom
Tom@Tom663978014096·
@gannemans @VP @BillWhiteUSA Get your facts straight please. Publication was not forbidden. The CJD only ruled that the website should have provided info alongside the speech. They received no fines or bans, only a warning, and were required to post the CDJ's ruling on their website for two days.
English
1
1
3
170
Zeth
Zeth@0xZeth·
@IditAbu Thank you ambassador. I hope the world sees whats going on in Belgium.
English
1
0
32
1.3K
Ambassador Idit Rosenzweig-Abu
Apparently if a Belgian paper publishes “I would like ram a knife in the neck of every Jew I see” that’s “freedom of speech” But if a Belgian TV channel broadcasts the speech of vice president JD Vance - they get sanctioned. Go figure.
Ambassador Idit Rosenzweig-Abu tweet mediaAmbassador Idit Rosenzweig-Abu tweet media
English
186
1.8K
7.2K
151.6K
Zeth
Zeth@0xZeth·
@stranger1434 @YoussefRaggi Why would they, Lebanon (hezbollah) attacked first, you reap what you sow. Lebanon should've dealt with Hezbollah long time ago.
English
1
0
1
91
Hana BK
Hana BK@stranger1434·
@YoussefRaggi Stand in solidarity with Cyprus but can’t stand in solidarity of your own country as you sit back and let israel invade? Do you think any EU country will stand in solidarity with Lebanon and try to protect it from israeli aggression?
English
2
0
9
1.1K
Youssef Raggi
Youssef Raggi@YoussefRaggi·
I called the Minister of Foreign Affairs of Cyprus, Konstantinos Kombos, to express my strong condemnation of the attacks targeting the island. I reaffirmed that Lebanon, as always, stands in solidarity with Cyprus in the face of any aggression against it. I also briefed him on the decision taken by the government during its emergency session and its determination to move forward with the decision to place all weapons under the authority of the state. 🇱🇧🇨🇾
English
37
108
772
40.9K
Zeth
Zeth@0xZeth·
@FaytuksNetwork So now its possible without juridicial approval?
English
0
0
0
1.3K
Faytuks Network
Faytuks Network@FaytuksNetwork·
BREAKING: Lebanese Army moving into southern towns to seize Hezbollah equipment - MTV
English
73
784
6.5K
346.3K
ℏεsam
ℏεsam@Hesamation·
isn’t this the same Jack Dorsey who over-hired by 40%-50% at Twitter back in 2021, then apologized after @elonmusk trimmed the fat, saying: “I grew the company size too quickly. I apologize for that.” why am i not surprised he laid off 40% of his employees yesterday.
ℏεsam tweet media
English
5
1
29
3.9K
Joseph Lyons
Joseph Lyons@MyDeathMachine·
The fact banks still use ACH is insane. Transfers should be instant in 2026.
English
1
0
2
179
Zeth
Zeth@0xZeth·
@Zeryther @theo It was good but idk what changed a couple days after release of 4.6
English
1
0
0
376
Theo - t3.gg
Theo - t3.gg@theo·
Just had to remind Opus 4.6 that env variables need to be read. Three separate times. And also remind it that it needs a package.json to have packages available. I don't know what they did but this is borderline unusable.
Theo - t3.gg tweet media
English
329
33
1.6K
374.9K
Joggie
Joggie@0xjoggie·
@beaverd $90B from 0.16% of providers. extrapolate that and the total fraud number is genuinely terrifying. open sourcing the data and letting random people on twitter find it faster than the government ever could is peak 2026
English
6
7
219
13K
Uday Yatnalli
Uday Yatnalli@udaysy·
@steipete the asymmetry wasnt new tho. low effort PRs always existed. ai just made the volume impossible to ignore. maintainers need review tooling that scales the same way contributor tooling did
English
1
0
5
431
Peter Steinberger 🦞
Peter Steinberger 🦞@steipete·
"Just because a tool—whether a static analyzer or an LLM—makes it easy to generate a report or a fix, it doesn’t mean that contribution is valuable to the project. The ease of creation often adds a burden to the maintainer because there is an imbalance of benefit. The contributor maybe gets the credit (or the CVE, or the visibility), while the maintainer gets the maintenance burden." github.blog/open-source/ma…
English
62
39
580
42.4K
GitButler
GitButler@gitbutler·
Now GitButler has a CLI! Stacked and parallel branches, smartlog, simple commit editing, easy undo, json output to every command. And it just works in any Git repo. Check it out: blog.gitbutler.com/but-cli
English
14
27
248
48.9K
Zeth
Zeth@0xZeth·
@pankajkumar_dev What does this have to do with sonnet 5 and opus 4.6?
English
0
0
0
127
Pankaj Kumar
Pankaj Kumar@pankajkumar_dev·
Claude Sonnet 5 "Fennec" & Opus 4.6 Leaks - Launch Crash: 4 separate outages on Feb 3rd confirm a failed deployment and forced rollback of the new models. - Double Drop: Vertex AI logs reveal two hidden models permission-gated in the backend: claude-sonnet-5 and claude-opus-4-6. - Leaderboard King: Leaked benchmarks show Sonnet 5 hitting a massive 83.3% on SWE-bench Verified, destroying the current meta. - Fennec Agents: New "Claude Code" features spawn autonomous sub-agents (QA, Backend) that act as a full dev team in your terminal. - Pricing Shock: Rumored to be 50% cheaper than Opus 4.5 while running significantly faster on Google TPUs. - Countdown: v0 teased an announcement within "3-4 hours," signaling the fix is in and launch is imminent. (Unverified leaks; treat timelines and benchmarks with caution.)
Pankaj Kumar tweet media
English
74
84
1.1K
172K
Zeth
Zeth@0xZeth·
@iamdothash Woild be cool to have a theme for zed! Zed’s Void
English
1
0
1
1.5K
Bjarne Øverli
Bjarne Øverli@iamdothash·
On certain days, you choose the black void.
Bjarne Øverli tweet media
English
18
9
532
32.3K
Bjarne Øverli
Bjarne Øverli@iamdothash·
It's been a while since I posted a theme. I finally found a great color combination with blueish tones. Not too weak, and not too vibrant. Pleasant to use for hours. What should we name it?
Bjarne Øverli tweet media
English
34
8
229
16K