Rafał Fitt
12K posts

Rafał Fitt
@rafal_fitt
There is always a bigger fish. Check the compass, not the clock. Knowledge Is Power. #NAFO











As a European, I hang my head in shame. The US has shown that if you blockade an oil exporter, they fold quickly. Europe can do this to Russia and shut down oil tanker traffic out of the Baltic. But it doesn't. Innocent Ukrainians pay the price every day. robinjbrooks.substack.com/p/the-baltic-c…








Hacking the #EU #AgeVerification app in under 2 minutes. During setup, the app asks you to create a PIN. After entry, the app *encrypts* it and saves it in the shared_prefs directory. 1. It shouldn't be encrypted at all - that's a really poor design. 2. It's not cryptographically tied to the vault which contains the identity data. So, an attacker can simply remove the PinEnc/PinIV values from the shared_prefs file and restart the app. After choosing a different PIN, the app presents credentials created under the old profile and let's the attacker present them as valid. Other issues: 1. Rate limiting is an incrementing number in the same config file. Just reset it to 0 and keep trying. 2. "UseBiometricAuth" is a boolean, also in the same file. Set it to false and it just skips that step. Seriously @vonderleyen - this product will be the catalyst for an enormous breach at some point. It's just a matter of time.













