porbem
75.2K posts

porbem
@porbem
#FaceTheClimateEmergency "I can't believe what you say because I see what you do." James Baldwin

J Treek looks at the normalisation of Digitised ID in Britain. A government may, with ease, use such a system to ostracise, de-bank and deny you services & entry to public life. All things the state already does. Read it in @ReinersProject: reiners.org.uk/digital-id-the…









Ikväll är Kristdemokraternas @alicemedce gäst i 30 minuter. 📺 SVT Play 19.30. SVT2 22.00







Hacking the #EU #AgeVerification app in under 2 minutes. During setup, the app asks you to create a PIN. After entry, the app *encrypts* it and saves it in the shared_prefs directory. 1. It shouldn't be encrypted at all - that's a really poor design. 2. It's not cryptographically tied to the vault which contains the identity data. So, an attacker can simply remove the PinEnc/PinIV values from the shared_prefs file and restart the app. After choosing a different PIN, the app presents credentials created under the old profile and let's the attacker present them as valid. Other issues: 1. Rate limiting is an incrementing number in the same config file. Just reset it to 0 and keep trying. 2. "UseBiometricAuth" is a boolean, also in the same file. Set it to false and it just skips that step. Seriously @vonderleyen - this product will be the catalyst for an enormous breach at some point. It's just a matter of time.








