Potat

553 posts

Potat banner
Potat

Potat

@Supreme_Tiny

I do stuff.

Katılım Mart 2018
258 Takip Edilen38 Takipçiler
Potat
Potat@Supreme_Tiny·
@awesomekling @dhh I'd like one as well but so hecking expensive. Serious note it's epic they're giving them away. Rewarding opensource work. Does ladybird take monetary contributions? I want to send you some.
English
0
0
0
219
Andreas Kling
Andreas Kling@awesomekling·
@dhh you guys are getting free nazibooks?
Andreas Kling tweet media
English
8
0
605
10.4K
DHH
DHH@dhh·
There's never any appeasement possible with these lunatics. Whatever concession or apology you offer, there's always another round of demands coming. The sooner you learn to say no to these people the better.
🐝🇬🇷@bee_fumo

NAZIBOOK 13 PRO

English
153
126
3.2K
109.4K
Potat
Potat@Supreme_Tiny·
@TehRockettek @FrameworkPuter Sweet. Someone I know I going to get the pro test driving woo. I'm not fond of the old touchpad at all. Man. I'm hella excited for this. Thanks for the info much appreciated.
English
0
0
0
12
ImRock
ImRock@TehRockettek·
@Supreme_Tiny @FrameworkPuter The input module on the pro should work on the non-pro laptops, but not the other way around. The display should work completely fine with the old motherboard too.
English
1
0
0
8
Framework
Framework@FrameworkPuter·
Our biggest breakthrough in efficiency yet, the Framework Laptop 13 Pro with 20 hours of battery life. In Graphite. Linux-first with options for Ubuntu pre-installed. Featuring Intel® Core™ Ultra Series 3 processors, LPCAMM2 Memory, a new haptic touchpad, and a touchscreen display. Pre-orders for the Framework Laptop 13 Pro open now: frame.work
Framework tweet mediaFramework tweet media
English
507
1.2K
15.9K
2.4M
Potat
Potat@Supreme_Tiny·
@sophiefleur__nl @PetradeBoevere Ik vind het vrij normaal om luie uitvreters en nuttelozen uit de zandbak te bestempelen als onrendabel ja. Ben wel klaar met belasting betalen voor die groepen. Wat ik zeg en of ik doe bepaal ik zelf overigens wel pedante muts.
Nederlands
0
0
0
14
Sophie Fleur
Sophie Fleur@sophiefleur__nl·
@Supreme_Tiny @PetradeBoevere Nee? Kinderopvangtoeslag? Zorgtoeslag? Kindgebonden budget? Bijstand? De overheid doet meer dan genoeg. Onrendabel? Mijn hemel, doe normaal.
Nederlands
1
0
0
38
Petra de Boevere
Petra de Boevere@PetradeBoevere·
"Ik moet naar mijn werk, maar kan die tank benzine niet meer betalen." Ons kabinet: "Je krijgt een sloopvergoeding voor je auto, je bier wordt duurder en we hebben subsidie voor je dakisolatie." Dan kun je nog steeds niet naar je werk.
Nederlands
104
525
2.8K
61.5K
Potat
Potat@Supreme_Tiny·
@sophiefleur__nl @PetradeBoevere Als die overheid steeds neemt en blijft nemen mag je op een gegeven moment wel wat terug verwachten. Alleen dat gebeurd niet. We blijven betalen en dan komen ze met maatregelen die grotendeels alleen onrendabelen helpen.
Nederlands
1
0
0
43
Sophie Fleur
Sophie Fleur@sophiefleur__nl·
@PetradeBoevere Wat een gejank. Doe eens volwassen en zet je in- en uitgaven tegenover elkaar. Lukt het niet, dan fiets of zoek een baan dichterbij je huis. Hoezo moet de overheid alles voor je regelen?
Nederlands
13
0
3
952
bruno
bruno@brunocbreis·
guy on the train was like “do you speak dutch?” bro i’m 1,67m
English
71
502
17.7K
422.4K
Paul Moore - Security Consultant 
Hacking the #EU #AgeVerification app in under 2 minutes. During setup, the app asks you to create a PIN. After entry, the app *encrypts* it and saves it in the shared_prefs directory. 1. It shouldn't be encrypted at all - that's a really poor design. 2. It's not cryptographically tied to the vault which contains the identity data. So, an attacker can simply remove the PinEnc/PinIV values from the shared_prefs file and restart the app. After choosing a different PIN, the app presents credentials created under the old profile and let's the attacker present them as valid. Other issues: 1. Rate limiting is an incrementing number in the same config file. Just reset it to 0 and keep trying. 2. "UseBiometricAuth" is a boolean, also in the same file. Set it to false and it just skips that step. Seriously @vonderleyen - this product will be the catalyst for an enormous breach at some point. It's just a matter of time.
Paul Moore - Security Consultant @Paul_Reviews

.@vonderleyen "The European #AgeVerification app is technically ready. It respects the highest privacy standards in the world. It's open-source, so anyone can check the code..." I did. It didn't take long to find what looks like a serious #privacy issue. The app goes to great lengths to protect the AV data AFTER collection (is_over_18: true is AES-GCM'd); it does so pretty well. But, the source image used to collect that data is written to disk without encryption and not deleted correctly. For NFC biometric data: It pulls DG2 and writes a lossless PNG to the filesystem. It's only deleted on success. If it fails for any reason (user clicks back, scan fails & retries, app crashes etc), the full biometric image remains on the device in cache. This is protected with CE keys at the Android level, but the app makes no attempt to encrypt/protect them. For selfie pictures: Different scenario. These images are written to external storage in lossless PNG format, but they're never deleted. Not a cache... long-term storage. These are protected with DE keys at the Android level, but again, the app makes no attempt to encrypt/protect them. This is akin to taking a picture of your passport/government ID using the camera app and keeping it just in case. You can encrypt data taken from it until you're blue in the face... leaving the original image on disk is crazy & unnecessary. From a #GDPR standpoint: Biometric data collected is special category data. If there's no lawful basis to retain it after processing, that's potentially a material breach. youtube.com/watch?v=4VRRri…

English
668
6.2K
24.7K
3.3M
Nick
Nick@maietta·
@LundukeJournal Wait, so the Arch Wiki, which has been traditionally a reliable and detailed source of valid information on how things work and how to solve problems, is playing politics when it comes to information gatekeeping? Omarchy, my daily driver OS, is built on Arch. I hate this.
English
17
27
727
13.8K
The Lunduke Journal
The Lunduke Journal@LundukeJournal·
The XLibre page on the Arch Linux Wiki has been deleted, with the following reason given: “The Xlibre project goes against [Arch Linux Code of Conduct] and should not be listed on ArchWiki.” The deletion appears to have been done by Alad Wenter, an Arch package maintainer and Wiki Administrator. wiki.archlinux.org/title/Xlibre
The Lunduke Journal tweet media
English
174
193
1.6K
104.7K
Potat
Potat@Supreme_Tiny·
@GamewithDave Not pc sorry, but adored Perfect dark on the n64.
GIF
English
0
0
0
20
Dave
Dave@GamewithDave·
For anyone who used a computer between 1990 & 2005… what’s the one game you still think about?
English
40.9K
723
14.4K
10.1M
Potat
Potat@Supreme_Tiny·
@Paul_Reviews I'm howling. This just keeps getting better. Gg my dude.
English
0
0
1
147
Paul Moore - Security Consultant 
Bypassing #EU #AgeVerification using their own infrastructure. I've ported the Android app logic to a Chrome extension - stripping out the pesky step of handing over biometric data which they can leak... and pass verification instantly. Step 1: Install the extension Step 2: Register an identity (just once) Step 3: Continue using the web as normal The extension detects the QR code, generates a cryptographically identical payload and tells the verifier I'm over 18, which it "fully trusts". This isn't a bug... it's a fundamental design flaw they can't solve without irrevocably tying a key to you personally; which then allows tracking/monitoring. Of course, I could skip the enrolment process entirely and hard-code the credentials into the extension... and the verifier would never know.
Paul Moore - Security Consultant @Paul_Reviews

Hacking the #EU #AgeVerification app in under 2 minutes. During setup, the app asks you to create a PIN. After entry, the app *encrypts* it and saves it in the shared_prefs directory. 1. It shouldn't be encrypted at all - that's a really poor design. 2. It's not cryptographically tied to the vault which contains the identity data. So, an attacker can simply remove the PinEnc/PinIV values from the shared_prefs file and restart the app. After choosing a different PIN, the app presents credentials created under the old profile and let's the attacker present them as valid. Other issues: 1. Rate limiting is an incrementing number in the same config file. Just reset it to 0 and keep trying. 2. "UseBiometricAuth" is a boolean, also in the same file. Set it to false and it just skips that step. Seriously @vonderleyen - this product will be the catalyst for an enormous breach at some point. It's just a matter of time.

English
270
3.1K
12.3K
1.2M
Potat
Potat@Supreme_Tiny·
@csmproject @Paul_Reviews Oh my days. That's fricking child's play. This is horrendously bad. I wonder how much they paid for the development. "Secure by design" 😂😂
English
1
0
5
426
The Collective Sensemaking Project
@Paul_Reviews Apart from the things you highlighted, why do users only have a certain number of age verifications available? Why does proof of age have an expiration date? Once I'm over 18, I will always be over 18. I'm not turning any younger!
The Collective Sensemaking Project tweet mediaThe Collective Sensemaking Project tweet media
English
39
114
1.6K
88.8K
Potat
Potat@Supreme_Tiny·
@blk19_ You sir are a certified madlad.
English
0
0
1
67
Potat
Potat@Supreme_Tiny·
@sudox7 Nested json is horror.
English
0
0
0
10
SudoX7
SudoX7@sudox7·
25 years later and we're still using JSON for configs like nobody ever came up with anything better
English
233
16
1.3K
102.9K
Potat
Potat@Supreme_Tiny·
@eagleeye2805 Brother don't forget about Luxembourg, Lichenstein maybe Monaco? Banker money man.
English
0
0
1
276
Kaiser
Kaiser@eagleeye2805·
I say it again and again...given the new geopolitical and economic realities, the internal weakness of the EU itself, the future is the United Confederation of Germania with Germany, Netherlands and Austria as nucleus. 112 million people with an economic power of 7.3 trillion USD (PPP: 8.6 trillion USD), the high tech and logistics core of Europe. These 3 countries already today have the closest partnership within the EU due to similar cultural and fiscal values. This Confederation could be operational in the shortest time. Can the Swiss, Czech, Slovenes, and Danes join? in principle yes, if they want to. Belgium only Flanders.
Kaiser tweet media
English
883
136
2K
244.1K
Potat
Potat@Supreme_Tiny·
@rekdt That's a good start for the John Mcafee lifestyle.
English
0
0
0
196
Potat
Potat@Supreme_Tiny·
Well yes. Since biggest part of the total Dutch petrol price is vat and excise tax. It's currently like 85 cent excluding vat of 21%. That boils down to roughly 50% or more of the total petrol price is going to the government. They've got plenty of margin. Except they're greedy bastards.
English
0
0
1
75
Samo the Trader
Samo the Trader@smlngface·
I mean, you’re acting like he can just pull that cash out of his pocket. Either it comes back as inflation if they print more money which hurts the same people you mention, or they have to take it from somewhere else, like infrastructure, hospitals, etc. which hurts somone aswell 🤷‍♂️
English
4
0
2
863
Michaël van de Poppe
Michaël van de Poppe@CryptoMichNL·
Dutch Minister of Finance doesn't see urgency in lowering the taxes on petrol. 'We're waiting to see whether further escalations happen. Every 10 cent decrease on the price costs us €1 billion.' Yeah, well, the price of petrol was 60 cents lower a month ago. This costs the society literally everything on their day to day life. Stupidity.
English
42
24
288
25.3K
Potat
Potat@Supreme_Tiny·
@0gtweet @UK_Daniel_Card Ah yeah. I mostly familiar with doing things locally. My co-worker has got his whole house automated with Shelly Pro 1PM's. Shelly cloud is pretty allright. As far as I've heard.
English
0
0
0
21
mRr3b00t
mRr3b00t@UK_Daniel_Card·
tweeps, who make the best Smart Plugs?
English
39
0
16
6.5K