Dogson

5.8K posts

Dogson

Dogson

@Dogson20

Developer for #FurryVNE. 3D artist on spare time. @furryodes Bro & colleague. MINORS BEGONE.

Over the rainbow Katılım Ekim 2018
1.5K Takip Edilen3.5K Takipçiler
Sabitlenmiş Tweet
Dogson
Dogson@Dogson20·
PSA: Please don't ask me about the old yiffalicious models. I don't have and don't want access to them anymore since I consider them a closed chapter in my life. Thank you.
English
5
1
21
0
Dogson retweetledi
粼Mzhh
粼Mzhh@M_zhh_·
经历许久的修改打磨之后白露半身像手办终于开始预售了,虽然还有些许遗憾和不完美,但终究是有一个结果啦,希望将来有机会做一个更好的! 《白露》1:6比例半身胸像 (Gk白模) 比例:1/6(全高约18cm) 原型创作:@mzhh 3D建模:@mrmistartist 更多信息请见商品链接详细介绍
粼Mzhh tweet media
中文
6
50
356
9K
Dogson retweetledi
Floreum 🔞🎨
Floreum 🔞🎨@muerolf·
My Rosa figure arrived safely! 👀💦 She's beautiful @aruurara!
Floreum 🔞🎨 tweet mediaFloreum 🔞🎨 tweet mediaFloreum 🔞🎨 tweet mediaFloreum 🔞🎨 tweet media
English
1
14
217
6.3K
Dogson retweetledi
LizzyGlizzy | LYGY | 🔞
LizzyGlizzy | LYGY | 🔞@LizzyGlizzyArt·
Are you a dinosaur kisser? You look like a dinosaur kisser to me. 🥰
English
25
199
1.7K
13.3K
Dogson retweetledi
Chy Anna
Chy Anna@ChyAnna78882403·
Coco Bandicoot - crash bandicoot series
English
0
5
55
1.1K
Dogson retweetledi
Dogson retweetledi
VulgarVictor🔞
VulgarVictor🔞@VulgarVictor583·
Lizurd
VulgarVictor🔞 tweet mediaVulgarVictor🔞 tweet mediaVulgarVictor🔞 tweet media
English
11
34
475
14.2K
Dogson retweetledi
Pirat_Nation 🔴
Pirat_Nation 🔴@Pirat_Nation·
Security researcher Paul Moore has demonstrated how the EU age verification app can be compromised in under 2 minutes with nothing more than physical access to a device. By editing the app’s shared preferences file an attacker can remove the encrypted PIN values, reset the rate limiting counter to zero, and disable biometric requirements entirely. The app then accepts a new PIN and grants access to the existing age verification credentials. His earlier analysis of the open source code also revealed that the app stores NFC biometric facial data and user selfies as unencrypted lossless PNG files on the device. Deletion is incomplete, leaving the images at risk even after processing. Europe is so cooked
Pirat_Nation 🔴 tweet mediaPirat_Nation 🔴 tweet media
English
178
1.5K
8.1K
242.2K
Dogson retweetledi
Paul Moore - Security Consultant 
Hacking the #EU #AgeVerification app in under 2 minutes. During setup, the app asks you to create a PIN. After entry, the app *encrypts* it and saves it in the shared_prefs directory. 1. It shouldn't be encrypted at all - that's a really poor design. 2. It's not cryptographically tied to the vault which contains the identity data. So, an attacker can simply remove the PinEnc/PinIV values from the shared_prefs file and restart the app. After choosing a different PIN, the app presents credentials created under the old profile and let's the attacker present them as valid. Other issues: 1. Rate limiting is an incrementing number in the same config file. Just reset it to 0 and keep trying. 2. "UseBiometricAuth" is a boolean, also in the same file. Set it to false and it just skips that step. Seriously @vonderleyen - this product will be the catalyst for an enormous breach at some point. It's just a matter of time.
Paul Moore - Security Consultant @Paul_Reviews

.@vonderleyen "The European #AgeVerification app is technically ready. It respects the highest privacy standards in the world. It's open-source, so anyone can check the code..." I did. It didn't take long to find what looks like a serious #privacy issue. The app goes to great lengths to protect the AV data AFTER collection (is_over_18: true is AES-GCM'd); it does so pretty well. But, the source image used to collect that data is written to disk without encryption and not deleted correctly. For NFC biometric data: It pulls DG2 and writes a lossless PNG to the filesystem. It's only deleted on success. If it fails for any reason (user clicks back, scan fails & retries, app crashes etc), the full biometric image remains on the device in cache. This is protected with CE keys at the Android level, but the app makes no attempt to encrypt/protect them. For selfie pictures: Different scenario. These images are written to external storage in lossless PNG format, but they're never deleted. Not a cache... long-term storage. These are protected with DE keys at the Android level, but again, the app makes no attempt to encrypt/protect them. This is akin to taking a picture of your passport/government ID using the camera app and keeping it just in case. You can encrypt data taken from it until you're blue in the face... leaving the original image on disk is crazy & unnecessary. From a #GDPR standpoint: Biometric data collected is special category data. If there's no lawful basis to retain it after processing, that's potentially a material breach. youtube.com/watch?v=4VRRri…

English
670
6.2K
24.8K
3.4M
Dogson retweetledi
Brutal Segs
Brutal Segs@Bugoi45·
🥶
Brutal Segs tweet media
QME
12
283
2.9K
28.4K
Dogson retweetledi
Ribbon+
Ribbon+@ribbonplush·
Ribbon+ tweet media
ZXX
4
272
3.4K
24.6K