Σdu₳rdo Chile

1.1K posts

Σdu₳rdo Chile banner
Σdu₳rdo Chile

Σdu₳rdo Chile

@dypraxnp

Privacy & FOSS advocate | Shilling OG cypherpunk chains like $ERG $SC $XMR | Opinionated, but blue check algorithm says no | Found Waldo ages ago

On-chain Katılım Temmuz 2021
514 Takip Edilen114 Takipçiler
Σdu₳rdo Chile retweetledi
Paul Moore - Security Consultant 
Hacking the #EU #AgeVerification app in under 2 minutes. During setup, the app asks you to create a PIN. After entry, the app *encrypts* it and saves it in the shared_prefs directory. 1. It shouldn't be encrypted at all - that's a really poor design. 2. It's not cryptographically tied to the vault which contains the identity data. So, an attacker can simply remove the PinEnc/PinIV values from the shared_prefs file and restart the app. After choosing a different PIN, the app presents credentials created under the old profile and let's the attacker present them as valid. Other issues: 1. Rate limiting is an incrementing number in the same config file. Just reset it to 0 and keep trying. 2. "UseBiometricAuth" is a boolean, also in the same file. Set it to false and it just skips that step. Seriously @vonderleyen - this product will be the catalyst for an enormous breach at some point. It's just a matter of time.
Paul Moore - Security Consultant @Paul_Reviews

.@vonderleyen "The European #AgeVerification app is technically ready. It respects the highest privacy standards in the world. It's open-source, so anyone can check the code..." I did. It didn't take long to find what looks like a serious #privacy issue. The app goes to great lengths to protect the AV data AFTER collection (is_over_18: true is AES-GCM'd); it does so pretty well. But, the source image used to collect that data is written to disk without encryption and not deleted correctly. For NFC biometric data: It pulls DG2 and writes a lossless PNG to the filesystem. It's only deleted on success. If it fails for any reason (user clicks back, scan fails & retries, app crashes etc), the full biometric image remains on the device in cache. This is protected with CE keys at the Android level, but the app makes no attempt to encrypt/protect them. For selfie pictures: Different scenario. These images are written to external storage in lossless PNG format, but they're never deleted. Not a cache... long-term storage. These are protected with DE keys at the Android level, but again, the app makes no attempt to encrypt/protect them. This is akin to taking a picture of your passport/government ID using the camera app and keeping it just in case. You can encrypt data taken from it until you're blue in the face... leaving the original image on disk is crazy & unnecessary. From a #GDPR standpoint: Biometric data collected is special category data. If there's no lawful basis to retain it after processing, that's potentially a material breach. youtube.com/watch?v=4VRRri…

English
668
6.2K
24.7K
3.3M
Σdu₳rdo Chile retweetledi
Alex Chepurnoy
Alex Chepurnoy@chepurnoy·
While "crypto" is depressively calm, it is good time to act further in rebellion against monetary and financial status quo. Renamed Ergo Book draft to "Ergo Book: A Roadmap For Trust-Minimized Monetary Stack And Digital Free Banking" , it is mdbook based now, finalizing structure
English
6
49
178
3.2K
Σdu₳rdo Chile retweetledi
Alex Chepurnoy
Alex Chepurnoy@chepurnoy·
We are extremely short on time as a lot of hyperinflation etc events are coming around the globe. Next step is mesh network based trading on credit and with on chain reserves and then getting first communities to test it
Alex Chepurnoy@chepurnoy

First Basis redemption transaction for offchain note explorer.ergoplatform.com/transactions/1…, with Bob redeeming a note signed by Alice (& also witnessed by tracker). Next, demos for trading over mesh, and agent to agent debt creation & clearing

English
0
25
94
1.7K
Σdu₳rdo Chile retweetledi
Rosen.Tech
Rosen.Tech@RosenBridge_erg·
@wolf31o2 The 2025 Cardano chain split showed what can happen when consensus logic lives in one dominant codebase. Node diversity helps prevent that. 
Independent clients could have contained or avoided such events entirely. This is common sense to support independent clients. Vote yes.
English
1
2
24
593
Σdu₳rdo Chile retweetledi
Ergo
Ergo@ergo_platform·
We provide implementation of reserve contract as well as offchain clients (tracker server and example clients). We show an example of group trading over mesh network with occasional Internet connection. Another example shows AI agent economies where autonomous agents create credit relationships for services.
English
0
4
22
1.1K
Lyudmyla Kozlovska 🇪🇺🇺🇦
European Parliament has just rejected the Chat Control proposal again! 🫶🚀 Your voice always matters! Stay ready and keep standing up for your rights!🫶 As a follow-up, ask your MEP to investigate: •Why are EPP MEPs following the agenda and timelines set by Google, Meta, TikTok, and other big platforms, instead of defending the fundamental rights of EU citizens? •On what legal and political basis was this vote reopened, and who requested it — was it driven by the public interest or corporate lobbying? •If this vote can be reopened once, does that mean it can be reopened again whenever the outcome pleases powerful actors — but not when citizens and civil society are dissatisfied with the result?
Lyudmyla Kozlovska 🇪🇺🇺🇦 tweet media
English
63
334
2.3K
43.2K
Σdu₳rdo Chile
Σdu₳rdo Chile@dypraxnp·
@LyudaKozlovska The question is, who is paying how much for them retrying in courts over and over to establish something that I couldn't even vote on? And in this democracy, can we now vote on Chatcontrol for people in power, @EUCouncil, instead Chatcontrol for the few unbiased journalists left?
English
1
0
6
306
Σdu₳rdo Chile retweetledi
Patrick Breyer #JoinMastodon
Patrick Breyer #JoinMastodon@echo_pbreyer·
🇩🇪 🏆✨ Tränen der Freude: EU-Parlament beerdigt die #Chatkontrolle - am 4. April müssen Techkonzerne aufhören! Historischer Tag für Demokratie und Privatsphäre! DANKE für euren unfassbaren Widerstand! ❤️ 🔥 Aber Achtung: Sie werden es wieder versuchen... ⚔️
Deutsch
48
369
1.9K
42.7K
Σdu₳rdo Chile retweetledi
Ergo
Ergo@ergo_platform·
Weekly Update on Matrix (sub-blocks): * fixed more todos , mostly in p2p layer, like DoS prevention, ever growing caches etc * more tests done * a non-mining peer now run (locally) in the public testnet. Its version set to 6.5.0 * updated 213 devnet seed node with a fresh build, will provide it after testing a bit
GIF
English
0
24
76
1.5K
Σdu₳rdo Chile
Σdu₳rdo Chile@dypraxnp·
@ThourCS2 Counter strike was peak gaming experience with 1.6 and CS:S. Self-hosted servers, "fuck it i'll mod it"-spirit, ranking via external rank trackers that were totally sufficient and supported local competition and even anti cheat by democratic vote + server admin.
English
0
0
0
139
Thour
Thour@ThourCS2·
CS2 just added map guides to Competitive & Retakes ‼️ For the first 5 rounds of each half, you can use annotations even in Competitive mode starting today.
English
61
77
3.7K
631.7K
Σdu₳rdo Chile retweetledi
NXT EU
NXT EU@NXT4EU·
BREAKING: The EU Parliament has adopted a stance that prohibits mass surveillance in the EU. Going against the EU countries which have been lobbying within the EU council to implement Chat-Control, the Democratic part of the EU has decided to stand up for European citizens. 🇪🇺
NXT EU tweet media
English
145
1.5K
10.1K
371.7K
Σdu₳rdo Chile retweetledi
ZachXBT
ZachXBT@zachxbt·
@Ledger day 62 since the last Ledger customer data breach 🤝
English
282
307
10.8K
281.8K
Σdu₳rdo Chile retweetledi
Tim Hinchliffe
Tim Hinchliffe@TimHinchliffe·
"We have to stop the spread of Digital ID & introduction of CBDC.. We are sovereign individuals; we don't need to prove our identity.. We need to oppose digital asset registers & tokenization of our assets & of nature" economist Richard Werner europarl.europa.eu/streaming/?eve…
English
20
499
1.1K
12.3K
Σdu₳rdo Chile
Σdu₳rdo Chile@dypraxnp·
Why panic? Opt out of windows, donate & grow the community. Linux is open-source so it's the way it's written until you re-write. California Law is not global Law. Law is not enforcement. This is your weekly, miserably thought through approach to establish mass crowd control.
English
0
0
0
12
Σdu₳rdo Chile retweetledi
Pirat_Nation 🔴
Pirat_Nation 🔴@Pirat_Nation·
Over 1.5 million people have reportedly left ChatGPT.
Pirat_Nation 🔴 tweet mediaPirat_Nation 🔴 tweet media
English
1.1K
2.8K
41.3K
2.9M
Σdu₳rdo Chile retweetledi
Sia Foundation
Sia Foundation@SiaFoundation·
Today, surveillance looks different than it did during the Cold War. It looks like checking a box to agree to ToS, silent pings, and location tracking. Your data is Big Tech’s most valuable asset. But now, we can take back our data. Sia is the safest cloud storage, by design.
English
3
7
26
649
Σdu₳rdo Chile retweetledi
Patrick Breyer #JoinMastodon
Patrick Breyer #JoinMastodon@echo_pbreyer·
🇪🇺🎉🔥 BREAKING VICTORY! LIBE just REJECTED the extension of warrantless #ChatControl 1.0 – no majority! 🛡️💪 Digital privacy of correspondence saved! Million thanks to everyone who raised their voices! ❤️🙏 Final battle ahead: Plenary vote! 🚀 #StopScanningMe
Patrick Breyer #JoinMastodon tweet media
English
5
87
232
9.2K
Σdu₳rdo Chile retweetledi
Patrick Breyer #JoinMastodon
Patrick Breyer #JoinMastodon@echo_pbreyer·
🇩🇪🎉🔥 SENSATIONELLER ETAPPENSIEG: LIBE-Ausschuss lehnt heute die Verlängerung der anlasslosen #Chatkontrolle 1.0 ab – keine Mehrheit! 🛡️💪 Das digitale Briefgeheimnis lebt! Tausend Dank an alle, die Druck gemacht haben! ❤️🙏 Finale Schlacht folgt: Plenarabstimmung! 🚀🔥
Patrick Breyer #JoinMastodon tweet media
Deutsch
25
359
1.3K
26.4K