Brewna

9.4K posts

Brewna

Brewna

@_brewna_

b2b saas mines Katılım Şubat 2015
166 Takip Edilen104 Takipçiler
HowlingMutant
HowlingMutant@Howlingmutant0·
Yeah I “meal prep”
HowlingMutant tweet media
English
234
83
3.9K
170.7K
Brewna
Brewna@_brewna_·
@moultano CICO matters because obese people lie about how much they eat. And while losing weight can be more complicated than just eating less, you absolutely have to admit you are eating too much.
English
0
0
1
105
Ryan Moulton
Ryan Moulton@moultano·
All weight gain is due to CICO in the same sense that all deaths are due to a lack of oxygen in the brain.
English
21
8
335
14.2K
Brewna
Brewna@_brewna_·
@Paul_Reviews Wait a second, so it is actually private because it doesn't actually work?
English
0
0
0
324
Paul Moore - Security Consultant 
Bypassing #EU #AgeVerification using their own infrastructure. I've ported the Android app logic to a Chrome extension - stripping out the pesky step of handing over biometric data which they can leak... and pass verification instantly. Step 1: Install the extension Step 2: Register an identity (just once) Step 3: Continue using the web as normal The extension detects the QR code, generates a cryptographically identical payload and tells the verifier I'm over 18, which it "fully trusts". This isn't a bug... it's a fundamental design flaw they can't solve without irrevocably tying a key to you personally; which then allows tracking/monitoring. Of course, I could skip the enrolment process entirely and hard-code the credentials into the extension... and the verifier would never know.
Paul Moore - Security Consultant @Paul_Reviews

Hacking the #EU #AgeVerification app in under 2 minutes. During setup, the app asks you to create a PIN. After entry, the app *encrypts* it and saves it in the shared_prefs directory. 1. It shouldn't be encrypted at all - that's a really poor design. 2. It's not cryptographically tied to the vault which contains the identity data. So, an attacker can simply remove the PinEnc/PinIV values from the shared_prefs file and restart the app. After choosing a different PIN, the app presents credentials created under the old profile and let's the attacker present them as valid. Other issues: 1. Rate limiting is an incrementing number in the same config file. Just reset it to 0 and keep trying. 2. "UseBiometricAuth" is a boolean, also in the same file. Set it to false and it just skips that step. Seriously @vonderleyen - this product will be the catalyst for an enormous breach at some point. It's just a matter of time.

English
228
2K
8.3K
674.1K
Brewna
Brewna@_brewna_·
@_Kyou I dunno, it's every language (including some Japanese) vs a subset of Japanese anti-pirate retards.
English
0
0
13
1.7K
Kyou
Kyou@_Kyou·
I’m reading the piracy discourse It took like 1 week for the reverse Tower of Babel to start collapsing lmfao
English
25
212
5.1K
63K
Brewna
Brewna@_brewna_·
@CloutedMind It was expected from the start. No local computing is allowed for cattle, everything goes through a model trained to enforce compliance.
English
0
0
1
161
Clouted
Clouted@CloutedMind·
KYC on AI is insane bro
English
27
13
221
6K
𝓚𝑙𝑎𝑟 𝓝𝑎𝑚𝑒 💫 ✨🌟 ⭐️
Sie machen jetzt also die großen Plattformen dicht. Ein schwarzer Tag für die Meinungsfreiheit. Optimistisch stimmt mich, dass die Opposition nun in dezentrale Plattformen abwandern wird, die immer unkontrollierbarer werden. Die Paranoia der Staaten wird gigantisch sein. #NoID
Deutsch
2
13
93
1.1K
Brewna
Brewna@_brewna_·
@nvk Until they ask for ID to buy a GPU
English
0
0
0
18
nvk 🌞
nvk 🌞@nvk·
This is great news, it will greatly accelerate the inevitable move towards local non-hosted ai. Even the normies don't want to give their ID and ask about their taxes and genital-rash 🤣
RYAN SΞAN ADAMS - rsa.eth 🦄@RyanSAdams

AI KYC is here. New claude subscribers asked for gov ID & photo. Not even a regulatory requirement - Anthropic just doing it because they want to. But regulatory is coming Next up will be laws: No AI without gov-issued ID All AI use tracked to individual - no private AI

English
9
8
81
5.8K
Bug
Bug@CoolPerson2008·
@Nobody_D_Emon @HosayJumbo You mean eva, the character who has a daughter (that looks like an elementary schooler or middle schooler), is the same age range as the characters meant to be teenagers?
English
3
0
0
428
Brewna
Brewna@_brewna_·
@spqr_sulla Yeah but it's different now. With global communication and trade internal competition between small states just means you lose to the big ones. Especially in terms of culture, which really just means propaganda.
English
1
0
5
109
Brewna
Brewna@_brewna_·
@Leonidas1747 @N104AP I'm not going to age verify. But I'm also not going to stop using the internet either.
English
0
0
2
32
Ellie Winters
Ellie Winters@N104AP·
i mean it when i say ill leave services if theres ever any form of mandatory age verification if discord adds it worldwide, im gone, if anywhere else adds it worldwide, im also going, no service is worth it for me to give my ID to
English
23
330
2K
17.3K
Brewna
Brewna@_brewna_·
@neyroneko @N104AP Yeah, if you try to find ways that's fine, but giving up and accepting that people are *taking away* stuff from us is bad.
English
1
0
0
38
Kikuryo
Kikuryo@neyroneko·
@_brewna_ @N104AP Who's talking about punishment? If a service is inconvenient or unpleasant, why use it? If I'm required to show my passport to access Twitter, I'll try to circumvent these restrictions, but otherwise, I'll simply stop using it
English
1
1
9
59
Chunky Buttons
Chunky Buttons@Chunky_Buttons·
Anyone else get belly button infections?
English
12
1
34
952
Brewna
Brewna@_brewna_·
@eigenrobot aura rotation factory aura farming ultra processed aura products
Italiano
0
0
0
11
eigenrobot
eigenrobot@eigenrobot·
2024 brought us aura farming and by 2027 we will be familiar with aura salting the earth
English
15
6
155
5.2K
Brewna
Brewna@_brewna_·
@gvanrossum "we just have to prevent the technology from created" => it always will be created
English
0
0
1
90
Guido van Rossum
Guido van Rossum@gvanrossum·
"If the technology fell in the wrong hands" => Yes, it will. Every. Single. Time.
English
46
165
1.2K
39.2K
Brewna
Brewna@_brewna_·
@IdkNtm1 slowly? it's been known before the anime was even announced
English
0
0
0
308
Rain.
Rain.@IdkNtm1·
Slowly realizing that the WHA fanbase is sadly "one of those"
English
9
2
125
8.4K
Brewna
Brewna@_brewna_·
@micah_erfan that would ensure they get no money from these companies the next time they are in power
English
0
0
0
31
Micah
Micah@micah_erfan·
Reminder: Any Democratic Attorney General could sue under the Clayton Act to prevent this, but not a single one has.
Democrats@TheDemocrats

Reminder

English
160
8.5K
43K
838.8K
Brewna
Brewna@_brewna_·
@TheJevil2005 how, if you can't turn on a computer without an ID check?
English
0
0
0
41
Brewna
Brewna@_brewna_·
@N104AP it's gonna be next to useless if it fails remote attestation anyway
English
1
0
0
709
Ellie Winters
Ellie Winters@N104AP·
> GrapheneOS is nowhere near good enough the GrapheneOS team is saying this about their own fucking OS, when its literally the most secure and private OS in the world. that is how much they care. especially with these age verification laws and OS scanning laws, get a pixel, do it
GrapheneOS@GrapheneOS

Privacy and security on computing devices need to become far stronger to protect people from pervasive violations of their rights. Users have their privacy pervasively violated by corporations, criminals and governments. There are endless privacy and security weaknesses in software with exploits of those happening on a large scale. Operating systems, browsers and other apps need to do a much better job protecting users. Enormous progress is needed on both privacy and security. GrapheneOS provides a massive upgrade for privacy and security over the standard Android Open Source Project. GrapheneOS is nowhere near good enough and we have an enormous amount of work to do improving both. Our work is an ongoing process and doesn't have an end point. Privacy and security heavily involve competition between attackers and defenders. Most defenders are making little progress and falling increasingly far behind. Attackers continue improving their exploits of privacy and security weaknesses. Commercial exploit tools are increasingly widely deployed for broad attacks. Software has a very high density of privacy and security vulnerabilities. LLMs are accelerating both vulnerability discovery and exploit development. For most computing devices, defense is increasingly far behind offense. iOS and GrapheneOS are exceptional cases not representative of degrading privacy and security across computing devices. Growing numbers of internet connected devices are incorporated into botnets. This harms the privacy and security of the internet as a whole through heavily pushing it towards centralization behind services such as Cloudflare. Insecure devices without security patches harm the internet as a whole. It isn't only embedded devices but also desktops, mobile devices and servers being used as part of these botnets. It isn't only people with these insecure devices who are harmed. It can get much worse. We're building GrapheneOS to protect everyone's privacy and security. It's aimed at widespread adoption and is highly usable. It's compatible with the vast majority of Android apps. It has major privacy benefits for every user including stopping a lot of data collection by apps and services with a better permission model increasingly addressing being coerced to grant access. GrapheneOS has many users with little technical knowledge and isn't hard to install or use. We're continuing to work on improving privacy, security, usability and app compatibility for all of our users. Contact Scopes, Storage Scopes, per-app Sensors toggle, VPN leak protection and many other features we provde are very important privacy protections. We're building alternatives to the Camera, Microphone and other permissions too. Our major improvements to exploit protections are there to protect user privacy. Privacy depends on security and that's why we heavily work on security too. Contrary to what's often claimed, GrapheneOS is far more usable and requires far less sacrifice compared to other alternatives. Providing far better protection against sophisticated exploits isn't at the expense of that. Our opt-in sandboxed Google Play compatibility layer combines privacy and high usability. We're gradually making replacements for more Google services apps rely on. Location services, network-based location, geocoding and more has already been replaced and much more is coming.

English
8
62
537
14.2K
Brewna
Brewna@_brewna_·
@onehappyfellow ultimately you are trying to do their work (reconciling conflicting states) without reading their minds and in fact by resolving the easy ones you are letting them create state conflicts they themselves are in fact too stupid to resolve
English
0
0
1
16
One Happy Fellow
One Happy Fellow@onehappyfellow·
@_brewna_ so it is hard, engineering has to account for stupid people and time constraints
English
1
0
3
27
One Happy Fellow
One Happy Fellow@onehappyfellow·
"Well designed applications are stateless" stateless code is the simples code to write, to wit: llm inference = stateless code = anthropic has it down and it works synchronising chats, load balancing, race conditions relating to state changes = all broken as fuck
English
3
0
42
1K