t

36 posts

t banner
t

t

@blau

⋆˚˖。꩜⭒˚.⋆

Katılım Haziran 2007
56 Takip Edilen3.4K Takipçiler
t
t@blau·
🗣️ #WirVerlassenX - Aber X Premium darf man ja wohl noch haben dürfen...
t tweet mediat tweet media
Deutsch
0
1
3
300
t retweetledi
Stefan Thumann
Stefan Thumann@StefanThumann·
Unter #WirVerlassenX verlassen Grüne, Linke und SPD das Schlachtfeld. Ein Zeichen für "Wir geben auf, wenn es unangenehm wird". Und ein Geschenk an die Gegner. Denn es bleibt hängen: "Man kann die Linksgrünen besiegen, schaut her!" Gratis-Motivation und Siegestaumel inklusive.
Deutsch
44
74
877
12.8K
t retweetledi
Proton Drive
Proton Drive@ProtonDrive·
︎ ︎ ︎ ︎ ︎ ︎ ︎ Privacy is not negotiable. ︎ ︎ ︎ ︎ ︎ ︎ ︎ ︎
English
79
626
4.4K
90.5K
t retweetledi
Paul Moore - Security Consultant 
Hacking the #EU #AgeVerification app in under 2 minutes. During setup, the app asks you to create a PIN. After entry, the app *encrypts* it and saves it in the shared_prefs directory. 1. It shouldn't be encrypted at all - that's a really poor design. 2. It's not cryptographically tied to the vault which contains the identity data. So, an attacker can simply remove the PinEnc/PinIV values from the shared_prefs file and restart the app. After choosing a different PIN, the app presents credentials created under the old profile and let's the attacker present them as valid. Other issues: 1. Rate limiting is an incrementing number in the same config file. Just reset it to 0 and keep trying. 2. "UseBiometricAuth" is a boolean, also in the same file. Set it to false and it just skips that step. Seriously @vonderleyen - this product will be the catalyst for an enormous breach at some point. It's just a matter of time.
Paul Moore - Security Consultant @Paul_Reviews

.@vonderleyen "The European #AgeVerification app is technically ready. It respects the highest privacy standards in the world. It's open-source, so anyone can check the code..." I did. It didn't take long to find what looks like a serious #privacy issue. The app goes to great lengths to protect the AV data AFTER collection (is_over_18: true is AES-GCM'd); it does so pretty well. But, the source image used to collect that data is written to disk without encryption and not deleted correctly. For NFC biometric data: It pulls DG2 and writes a lossless PNG to the filesystem. It's only deleted on success. If it fails for any reason (user clicks back, scan fails & retries, app crashes etc), the full biometric image remains on the device in cache. This is protected with CE keys at the Android level, but the app makes no attempt to encrypt/protect them. For selfie pictures: Different scenario. These images are written to external storage in lossless PNG format, but they're never deleted. Not a cache... long-term storage. These are protected with DE keys at the Android level, but again, the app makes no attempt to encrypt/protect them. This is akin to taking a picture of your passport/government ID using the camera app and keeping it just in case. You can encrypt data taken from it until you're blue in the face... leaving the original image on disk is crazy & unnecessary. From a #GDPR standpoint: Biometric data collected is special category data. If there's no lawful basis to retain it after processing, that's potentially a material breach. youtube.com/watch?v=4VRRri…

English
665
6.2K
24.7K
3.4M
t
t@blau·
@ApoRed_ federball digga
English
0
0
0
40
ApoRed
ApoRed@ApoRed_·
Der Mainy is back on Twitti (X)
ApoRed tweet media
English
463
88
2.7K
363.5K
t retweetledi
Punch Cat
Punch Cat@PunchingCat·
ZXX
11
497
5.8K
93.3K
t retweetledi
Blendi
Blendi@BlendiByl·
Minecraft 3D generation now at the highest quality ever, built using @fal ⛏️ Text → Image (nano-banana-pro) → 3D mesh (Hunyuan 3D v3.1) → Voxelize → Texture mapping → Minecraft structure!
English
102
109
2.6K
462.8K
t retweetledi
KuchenTV
KuchenTV@Kuchngeschmack·
Der Krieg muss jetzt enden
KuchenTV tweet media
Deutsch
9
12
699
17.3K
t retweetledi
Julian Adrat
Julian Adrat@JulianAdrat·
Habe ich das richtig verstanden, für „Misgendern“ linker Politiker: 10.000 Euro Strafe – aber ein linker Politiker mit 4.000 Kinderpornodateien auf dem Laptop kommt mit 1.000 Euro davon?
Deutsch
104
877
6K
65.9K
t retweetledi
Punch Cat
Punch Cat@PunchingCat·
ZXX
11
575
5.4K
76K
t retweetledi
Não Intendo
Não Intendo@blognaointendo·
aaaaaaaaaaaaaaaaaaaaahhhhhhhhhhh
94
2.9K
22.6K
1.7M
t retweetledi
Dr KALU, OON
Dr KALU, OON@DrKalu_·
Thank God Kamala Harris didn't win that election
English
167
1.5K
21.7K
252.1K
t retweetledi
Punch Cat
Punch Cat@PunchingCat·
ZXX
7
346
2.5K
57.8K