Floki der Große
1.3K posts


Hacking the #EU #AgeVerification app in under 2 minutes. During setup, the app asks you to create a PIN. After entry, the app *encrypts* it and saves it in the shared_prefs directory. 1. It shouldn't be encrypted at all - that's a really poor design. 2. It's not cryptographically tied to the vault which contains the identity data. So, an attacker can simply remove the PinEnc/PinIV values from the shared_prefs file and restart the app. After choosing a different PIN, the app presents credentials created under the old profile and let's the attacker present them as valid. Other issues: 1. Rate limiting is an incrementing number in the same config file. Just reset it to 0 and keep trying. 2. "UseBiometricAuth" is a boolean, also in the same file. Set it to false and it just skips that step. Seriously @vonderleyen - this product will be the catalyst for an enormous breach at some point. It's just a matter of time.




Heu ... lol C'est le SDK du wallet de l'European Digital Identity ça ? Dites moi que c'est une blague pitié 🤣 Le MITM documenté c'est pour la police ou le cab du premier ministre ? #scoped-issuance-document-configuration" target="_blank" rel="nofollow noopener">ageverification.dev/av-app-ios-wal…










🚨🇺🇸🇮🇷 BREAKING: The USS George H.W. Bush carrier strike group is deploying to the Middle East with three guided-missile destroyers already underway. The Bush carries 60+ aircraft including F/A-18 Super Hornets, can launch sorties around the clock, and just completed certification for major combat operations. It replaces the Ford, sidelined in Crete after an onboard fire. America is swapping carriers mid-war like changing tires at a pit stop. Source: CBS News / MIL3010 YT / TacSYS





Maybe instead of murdering the victim of gangrape, the rapists should be hanged. Just a thought.










