aronman

1.2K posts

aronman

aronman

@aronman36366359

Common sense is not so common.

Katılım Ocak 2020
280 Takip Edilen26 Takipçiler
Sabitlenmiş Tweet
aronman
aronman@aronman36366359·
“I have a foreboding of an America in my children's or grandchildren's time -- when the United States is a service and information economy; when nearly all the manufacturing industries have slipped away to other countries;
English
1
0
1
153
aronman retweetledi
Libertario 🟨⬛
Libertario 🟨⬛@QuotesforGoal·
"La diferencia entre un Estado Benefactor y un Estado Totalitario es sólo cuestión de tiempo" Ayn Rand
Libertario 🟨⬛ tweet media
Español
40
1.2K
4K
55.8K
aronman retweetledi
SpaceX
SpaceX@SpaceX·
Falcon lands for the 600th time!
English
1K
3.4K
27.2K
1.7M
aronman
aronman@aronman36366359·
@PetterS_Jensen @MlleMalin Jeg snakket om obligatoriske fag. De fleste fagene du nevner her kan velges bort, i motsetning til språk- og kulturfagene
Norsk
1
0
1
106
Navigi
Navigi@_navigi·
@MlleMalin @aronman36366359 Du kan vel få en i matematikk og en i naturfag, i tillegg til to til i matematikk (R1 + R2), to i fysikk og to i kjemi? Altså kan du få åtte realfagskarakterer om du går den veien.
Norsk
1
0
0
130
Malin
Malin@MlleMalin·
Dessverre skjønner jeg kidsa godt. Ingeniørlønningene i Norge er rett og slett ikke konkurransedyktige. Hvorfor streve seg gjennom vanskelige studier når man får bedre betalt ved å ta enkle?
Malin tweet media
Norsk
31
9
204
12.7K
aronman
aronman@aronman36366359·
@MlleMalin Det hadde vært en stor forbedring! Det hadde nok skapt et kulturskifte også, hvor det ble høystatus å være realist, igjen
Norsk
0
0
1
26
Malin
Malin@MlleMalin·
@aronman36366359 Og se på antall karakterer (som betyr mye for snittet). Én i matematikk og 4-5 i språkfag. Man kunne gjort som i øst-asiatiske land og gitt mye mer karaktermessig penalty ved å være lagger i realfag (en karakter i algebra, en i kalkulus, en i geometri osv)
Norsk
2
0
17
694
aronman
aronman@aronman36366359·
@TheRabbitHole Obedience is the biggest virtue in female groups
English
0
0
3
236
The Rabbit Hole
The Rabbit Hole@TheRabbitHole·
Male students are more tolerant of political rivals than female students are of political allies.
The Rabbit Hole tweet media
English
192
1.5K
10.1K
681.6K
Arild Hystad
Arild Hystad@arild_hystad·
EU vil altså innføra krav om å lasta opp pass eller id-kort for å kunna bruka Internet. Norske myndigheter jobbar som vanleg for å vera blant dei første til å innføra EU-reglane. Konklusjonen? La oss forlata EØS. La oss erstatta dei som styrer landet. nrk.no/urix/slik-vil-…
Arild Hystad tweet media
Norsk
34
79
392
8.1K
aronman
aronman@aronman36366359·
#EU sin app for #aldersverifikasjon lagrer bilder av deg som den ikke trenger – ukryptert, lossless, langsiktig lagring. Sikkert bare en tabbe😌
Paul Moore - Security Consultant @Paul_Reviews

.@vonderleyen "The European #AgeVerification app is technically ready. It respects the highest privacy standards in the world. It's open-source, so anyone can check the code..." I did. It didn't take long to find what looks like a serious #privacy issue. The app goes to great lengths to protect the AV data AFTER collection (is_over_18: true is AES-GCM'd); it does so pretty well. But, the source image used to collect that data is written to disk without encryption and not deleted correctly. For NFC biometric data: It pulls DG2 and writes a lossless PNG to the filesystem. It's only deleted on success. If it fails for any reason (user clicks back, scan fails & retries, app crashes etc), the full biometric image remains on the device in cache. This is protected with CE keys at the Android level, but the app makes no attempt to encrypt/protect them. For selfie pictures: Different scenario. These images are written to external storage in lossless PNG format, but they're never deleted. Not a cache... long-term storage. These are protected with DE keys at the Android level, but again, the app makes no attempt to encrypt/protect them. This is akin to taking a picture of your passport/government ID using the camera app and keeping it just in case. You can encrypt data taken from it until you're blue in the face... leaving the original image on disk is crazy & unnecessary. From a #GDPR standpoint: Biometric data collected is special category data. If there's no lawful basis to retain it after processing, that's potentially a material breach. youtube.com/watch?v=4VRRri…

Norsk
0
0
0
34
aronman
aronman@aronman36366359·
- PIN-koden din kan bare bypasses i #EU sin app for #aldersverifikasjon 🤠 - Du får uendelig antall forsøk på å logge deg inn, uten tidsbegrensning
Paul Moore - Security Consultant @Paul_Reviews

Hacking the #EU #AgeVerification app in under 2 minutes. During setup, the app asks you to create a PIN. After entry, the app *encrypts* it and saves it in the shared_prefs directory. 1. It shouldn't be encrypted at all - that's a really poor design. 2. It's not cryptographically tied to the vault which contains the identity data. So, an attacker can simply remove the PinEnc/PinIV values from the shared_prefs file and restart the app. After choosing a different PIN, the app presents credentials created under the old profile and let's the attacker present them as valid. Other issues: 1. Rate limiting is an incrementing number in the same config file. Just reset it to 0 and keep trying. 2. "UseBiometricAuth" is a boolean, also in the same file. Set it to false and it just skips that step. Seriously @vonderleyen - this product will be the catalyst for an enormous breach at some point. It's just a matter of time.

Norsk
0
0
0
8
aronman
aronman@aronman36366359·
EU sin alderskontroll bypassed på 2 min 🤠
Paul Moore - Security Consultant @Paul_Reviews

Bypassing #EU #AgeVerification using their own infrastructure. I've ported the Android app logic to a Chrome extension - stripping out the pesky step of handing over biometric data which they can leak... and pass verification instantly. Step 1: Install the extension Step 2: Register an identity (just once) Step 3: Continue using the web as normal The extension detects the QR code, generates a cryptographically identical payload and tells the verifier I'm over 18, which it "fully trusts". This isn't a bug... it's a fundamental design flaw they can't solve without irrevocably tying a key to you personally; which then allows tracking/monitoring. Of course, I could skip the enrolment process entirely and hard-code the credentials into the extension... and the verifier would never know.

Norsk
0
0
0
18
aronman retweetledi
Chris Freiman
Chris Freiman@cafreiman·
It’s amazing that this even needs to be said in 2026, but the collapse of communism was a good thing:
Chris Freiman tweet media
English
281
3.1K
14.3K
487.1K
Mads Johannesen
Mads Johannesen@ClaironMads·
«Fei for din egen dør» er det et godt ordtak som sier. Når du tjener godt over gjennomsnittet ift arbeidere som skaper (mye) mer verdi enn hva denne byråkraten gjør så innehar man frekkhetens nådegave med å gå så høyt ut. Dette er da Rødt politiker Sofie Marhaugs inntekt. Kart og terreng?
Mads Johannesen tweet mediaMads Johannesen tweet media
Norsk
30
10
258
41.1K