dynnie.bsky.social

11.4K posts

dynnie.bsky.social banner
dynnie.bsky.social

dynnie.bsky.social

@Dynvali

➡️➡️➡️ https://t.co/mdy8sVzwKd ⬅️⬅️⬅️

dynnie.bsky.social เข้าร่วม Nisan 2013
5.1K กำลังติดตาม721 ผู้ติดตาม
ทวีตที่ปักหมุด
dynnie.bsky.social
dynnie.bsky.social@Dynvali·
finally decided to go make one of them fancy blue skies that everyone's been going on about mutuals feel free to drop your @'s or find me @ dynnie
English
0
1
23
2.6K
dynnie.bsky.social รีทวีตแล้ว
Paul Moore - Security Consultant 
Hacking the #EU #AgeVerification app in under 2 minutes. During setup, the app asks you to create a PIN. After entry, the app *encrypts* it and saves it in the shared_prefs directory. 1. It shouldn't be encrypted at all - that's a really poor design. 2. It's not cryptographically tied to the vault which contains the identity data. So, an attacker can simply remove the PinEnc/PinIV values from the shared_prefs file and restart the app. After choosing a different PIN, the app presents credentials created under the old profile and let's the attacker present them as valid. Other issues: 1. Rate limiting is an incrementing number in the same config file. Just reset it to 0 and keep trying. 2. "UseBiometricAuth" is a boolean, also in the same file. Set it to false and it just skips that step. Seriously @vonderleyen - this product will be the catalyst for an enormous breach at some point. It's just a matter of time.
Paul Moore - Security Consultant @Paul_Reviews

.@vonderleyen "The European #AgeVerification app is technically ready. It respects the highest privacy standards in the world. It's open-source, so anyone can check the code..." I did. It didn't take long to find what looks like a serious #privacy issue. The app goes to great lengths to protect the AV data AFTER collection (is_over_18: true is AES-GCM'd); it does so pretty well. But, the source image used to collect that data is written to disk without encryption and not deleted correctly. For NFC biometric data: It pulls DG2 and writes a lossless PNG to the filesystem. It's only deleted on success. If it fails for any reason (user clicks back, scan fails & retries, app crashes etc), the full biometric image remains on the device in cache. This is protected with CE keys at the Android level, but the app makes no attempt to encrypt/protect them. For selfie pictures: Different scenario. These images are written to external storage in lossless PNG format, but they're never deleted. Not a cache... long-term storage. These are protected with DE keys at the Android level, but again, the app makes no attempt to encrypt/protect them. This is akin to taking a picture of your passport/government ID using the camera app and keeping it just in case. You can encrypt data taken from it until you're blue in the face... leaving the original image on disk is crazy & unnecessary. From a #GDPR standpoint: Biometric data collected is special category data. If there's no lawful basis to retain it after processing, that's potentially a material breach. youtube.com/watch?v=4VRRri…

English
572
5.1K
20.4K
2.4M
dynnie.bsky.social รีทวีตแล้ว
Disregard67
Disregard67@disregard67·
Animation enables the funniest things
English
4
26
266
1.9K
dynnie.bsky.social รีทวีตแล้ว
Aydan
Aydan@AydanFox·
AAAAAAAAAAAAAAAAAAA
20
83
1.6K
16.2K
dynnie.bsky.social รีทวีตแล้ว
Turbine Traveller
Turbine Traveller@Turbinetraveler·
Delta and American Airlines CRJ pilots at Ronald Reagan Washington National Airport are going viral after an ATC clip caught them making "meow," "ruff," and other animal sounds over the radio, but the controller wasn't having it. In the audio, ATC quickly shuts it down, telling them to act like "professional pilots." 📹: Flight Fantasy Simulator
English
188
1.6K
14K
1.5M
dynnie.bsky.social รีทวีตแล้ว
ゴン
ゴン@tk_eckie·
思ってたのと違ったけどかわいいからオッケー👌
日本語
7
113
1.2K
17.2K
dynnie.bsky.social รีทวีตแล้ว
🥀ᏕᎥᎷᏕᎥᎷ🥀
Star Fox in the Japanese comic is so cute and adorable look at them, they’re like little chicks!
🥀ᏕᎥᎷᏕᎥᎷ🥀 tweet media
English
5
292
1.8K
41.1K
dynnie.bsky.social รีทวีตแล้ว
ちゃぼ
ちゃぼ@q135MF4MzkPHoyO·
帰ったら発芽してました
ちゃぼ tweet mediaちゃぼ tweet media
日本語
1
26
462
3.7K
dynnie.bsky.social รีทวีตแล้ว
やまこじ
やまこじ@higashiyama5555·
#突然tlに可愛いたぬきを無言で流す見た人強制
やまこじ tweet media
QME
0
426
2.9K
39.1K
dynnie.bsky.social รีทวีตแล้ว
けーすけ
けーすけ@ksk_no_suke·
麗しいジーマ✨️ 📷️2026.3/27 #いしかわ動物園 #ユキヒョウ #ジーマ
けーすけ tweet media
日本語
0
44
459
3K
dynnie.bsky.social รีทวีตแล้ว
北きつね牧場【公式】
北きつね牧場【公式】@kitakitsunefarm·
The👅うずら #うずら ♀と言えば…な1枚 #北きつね牧場 #キタキツネ #朝日が眩しい朝
北きつね牧場【公式】 tweet media
日本語
20
355
2.1K
36K
dynnie.bsky.social รีทวีตแล้ว
✦
@sharksemen·
GIF
ZXX
3
83
942
8K
dynnie.bsky.social รีทวีตแล้ว
dynnie.bsky.social รีทวีตแล้ว
Velkan 🌿
Velkan 🌿@velk4n·
comm
Velkan 🌿 tweet media
English
1
25
311
2K
dynnie.bsky.social รีทวีตแล้ว
Quillic 🇺🇸 🕯️
Quillic 🇺🇸 🕯️@WanderingAvali·
Surrender your opals.
Quillic 🇺🇸 🕯️ tweet media
English
5
28
504
4.6K
dynnie.bsky.social รีทวีตแล้ว
Dead by Daylight Info Es
La linterna del killer sí que es potente 🔦💀 [Créditos a WqrHeqd]
Español
26
377
3.3K
91.6K