AFCM

362 posts

AFCM

AFCM

@AFCM_Dev

French student 🇫🇷

France Katılım Eylül 2022
1.4K Takip Edilen63 Takipçiler
AFCM retweetledi
Claude
Claude@claudeai·
Claude now connects to the tools creative professionals already use. With the new Blender connector, you can debug a scene, build new tools, or batch-apply changes across every object, directly from Claude.
English
1.6K
4.3K
46.4K
12.7M
NVIDIA GeForce FR
NVIDIA GeForce FR@NVIDIAGeForceFR·
[🌕#GIVEAWAY🌕] PRAGMATA est #RTXON grâce au path tracing et DLSS 4 ! À l'occasion de sa sortie, tentez de GAGNER cette NVIDIA GeForce RTX 5090 FE custom aux couleurs de Hugh et Diana, parfaite pour l’aventure sur la Lune qui vous attend. Vous la voulez ? Voici comment PARTICIPER : 💬 Commentez simplement avec “ PRAGMATA RTX ”
NVIDIA GeForce FR tweet media
Français
5K
998
2.8K
241.1K
AFCM retweetledi
Pavel Durov
Pavel Durov@durov·
France’s “Agency for Secure Documents” got hacked — names, addresses, emails and phone numbers of 19 million people leaked. Future leaks will become even uglier if the French government gets what it wants: access to encrypted chats and Digital IDs of social media users.
English
463
4.7K
15.7K
420.3K
AFCM retweetledi
Pavel Durov
Pavel Durov@durov·
This is how the EU/UK now regulates social media: 🤐 Offer CEOs secret deals to censor dissent. 🚨 If they refuse, open criminal cases against them. 😑 When people push back, say it's "all for the children". 🎭 "Protecting children" has become the standard legal/PR cover.
English
2.2K
14.4K
67.1K
53.8M
AFCM retweetledi
Pavel Durov
Pavel Durov@durov·
The “age verification app” the EU wants to impose on the world got hacked in 2 minutes. Step 1: Present a “privacy-respecting” but hackable solution. Step 2: Get hacked (you are here). Step 3: Remove privacy to "fix" it. Result: a surveillance tool sold as “privacy-respecting”.
English
458
7.2K
25.1K
634.9K
AFCM retweetledi
Paul Moore - Security Consultant 
Hacking the #EU #AgeVerification app in under 2 minutes. During setup, the app asks you to create a PIN. After entry, the app *encrypts* it and saves it in the shared_prefs directory. 1. It shouldn't be encrypted at all - that's a really poor design. 2. It's not cryptographically tied to the vault which contains the identity data. So, an attacker can simply remove the PinEnc/PinIV values from the shared_prefs file and restart the app. After choosing a different PIN, the app presents credentials created under the old profile and let's the attacker present them as valid. Other issues: 1. Rate limiting is an incrementing number in the same config file. Just reset it to 0 and keep trying. 2. "UseBiometricAuth" is a boolean, also in the same file. Set it to false and it just skips that step. Seriously @vonderleyen - this product will be the catalyst for an enormous breach at some point. It's just a matter of time.
Paul Moore - Security Consultant @Paul_Reviews

.@vonderleyen "The European #AgeVerification app is technically ready. It respects the highest privacy standards in the world. It's open-source, so anyone can check the code..." I did. It didn't take long to find what looks like a serious #privacy issue. The app goes to great lengths to protect the AV data AFTER collection (is_over_18: true is AES-GCM'd); it does so pretty well. But, the source image used to collect that data is written to disk without encryption and not deleted correctly. For NFC biometric data: It pulls DG2 and writes a lossless PNG to the filesystem. It's only deleted on success. If it fails for any reason (user clicks back, scan fails & retries, app crashes etc), the full biometric image remains on the device in cache. This is protected with CE keys at the Android level, but the app makes no attempt to encrypt/protect them. For selfie pictures: Different scenario. These images are written to external storage in lossless PNG format, but they're never deleted. Not a cache... long-term storage. These are protected with DE keys at the Android level, but again, the app makes no attempt to encrypt/protect them. This is akin to taking a picture of your passport/government ID using the camera app and keeping it just in case. You can encrypt data taken from it until you're blue in the face... leaving the original image on disk is crazy & unnecessary. From a #GDPR standpoint: Biometric data collected is special category data. If there's no lawful basis to retain it after processing, that's potentially a material breach. youtube.com/watch?v=4VRRri…

English
661
6.2K
24.6K
3.4M
AFCM
AFCM@AFCM_Dev·
@4AGames Metro Exodus is my best game of all time, I have a lot of hope for the sequel 🙏 (please no Epic exclusivity this time)
English
0
0
2
776
AFCM retweetledi
4A Games
4A Games@4AGames·
Join us for the global reveal of #METRO2039 16 April 2026 10AM PDT | 7PM CEST | 8PM EET METRO2039.com
English
353
2.3K
15.4K
939.6K
AFCM retweetledi
trish
trish@TrisH0x2A·
it's honestly embarrassing that Chrome accidentally became the best PDF viewer while Adobe spent decades making Acrobat slower and more bloated
English
765
5.7K
117.5K
2.4M
AFCM retweetledi
Pavel Durov
Pavel Durov@durov·
The EU deep state is telling us (via state-owned media and Soros-funded NGOs) that Telegram is a PROBLEM because people can discuss content from OTHER social media in PRIVATE telegram groups. This nonsense is used to justify surveillance (Chat Control) and censorship (DSA).
Pavel Durov tweet media
English
581
3.9K
15.3K
916.8K
AFCM retweetledi
FFmpeg
FFmpeg@FFmpeg·
FFmpeg is moving to Rust 🦀 Our use of C and Assembly in FFmpeg has been an unacceptable violation of safety. FFmpeg will be running 10x slower - but we're doing it for your safety. All your videos will appear green - safety first, working software later.
English
1.5K
3.7K
44.2K
2M
AFCM retweetledi
Feross
Feross@feross·
🚨 CRITICAL: Active supply chain attack on axios -- one of npm's most depended-on packages. The latest axios@1.14.1 now pulls in plain-crypto-js@4.2.1, a package that did not exist before today. This is a live compromise. This is textbook supply chain installer malware. axios has 100M+ weekly downloads. Every npm install pulling the latest version is potentially compromised right now. Socket AI analysis confirms this is malware. plain-crypto-js is an obfuscated dropper/loader that: • Deobfuscates embedded payloads and operational strings at runtime • Dynamically loads fs, os, and execSync to evade static analysis • Executes decoded shell commands • Stages and copies payload files into OS temp and Windows ProgramData directories • Deletes and renames artifacts post-execution to destroy forensic evidence If you use axios, pin your version immediately and audit your lockfiles. Do not upgrade.
English
542
4K
16.2K
12.4M
AFCM retweetledi
Mullvad.net
Mullvad.net@mullvadnet·
This is Senate House in London. When George Orwell wrote 1984, the building served as the model for the headquarters of the Ministry of Truth (the propaganda ministry). The Ministry of Truth decided what was true, for example that 2+2=5. It was responsible for censorship and rewriting history, and it banned the word “free” in the sense of freedom. When we projected our banned TV ads onto buildings in London, we thought this would be a fitting location. Nineteen Eighty-Four was supposed to be a warning, not an instruction manual.
Mullvad.net tweet media
English
38
509
4K
91.4K
AFCM retweetledi
Pirat_Nation 🔴
Pirat_Nation 🔴@Pirat_Nation·
Capcom just revealed the Resident Evil 4 merchant is now broke Over the past three years, players sold items worth 43.25 trillion pesetas but only bought 39.91 trillion back. He's now down 3.34 trillion pesetas and facing foreclosure.
Pirat_Nation 🔴 tweet mediaPirat_Nation 🔴 tweet media
English
221
2.6K
58.4K
1.1M
AFCM retweetledi
Andy Nguyen
Andy Nguyen@theflow0·
I ported Linux to the PS5 and turned it into a Steam Machine. Running GTA 5 Enhanced with Ray Tracing. 🤯
English
501
1.7K
18.6K
2.3M