Dan 🪛

744 posts

Dan 🪛

Dan 🪛

@gigdotzip

i like android framework/platform development, flutter, and linux.

18 he/him 🇮🇹🇨🇿 เข้าร่วม Ocak 2022
219 กำลังติดตาม212 ผู้ติดตาม
Dan 🪛
Dan 🪛@gigdotzip·
@searchspIoit @fs0c131y this has nothing to do with that i’m talking about or what is shown in the vid im replying to
English
1
0
0
10
Baptiste Robert
Baptiste Robert@fs0c131y·
Je confirme, Paul is right
Paul Moore - Security Consultant @Paul_Reviews

Hacking the #EU #AgeVerification app in under 2 minutes. During setup, the app asks you to create a PIN. After entry, the app *encrypts* it and saves it in the shared_prefs directory. 1. It shouldn't be encrypted at all - that's a really poor design. 2. It's not cryptographically tied to the vault which contains the identity data. So, an attacker can simply remove the PinEnc/PinIV values from the shared_prefs file and restart the app. After choosing a different PIN, the app presents credentials created under the old profile and let's the attacker present them as valid. Other issues: 1. Rate limiting is an incrementing number in the same config file. Just reset it to 0 and keep trying. 2. "UseBiometricAuth" is a boolean, also in the same file. Set it to false and it just skips that step. Seriously @vonderleyen - this product will be the catalyst for an enormous breach at some point. It's just a matter of time.

Português
13
67
470
90.7K
Dan 🪛 รีทวีตแล้ว
Vadim Yuryev
Vadim Yuryev@VadimYuryev·
Seriously just stop.. I HATE when Windows Laptop vendors sacrifice user experience for a couple of bucks from McAfee and Dropbox.. THIS is why people buy MacBooks
Vadim Yuryev tweet media
English
194
126
3K
85.6K
Dan 🪛 รีทวีตแล้ว
vx-underground
vx-underground@vxunderground·
The fundamental problem with this "hack" is it requires three things being true. 1. An attacker must possess the device 2. An attacker must be able to unlock the cell phone 3. The cell phone must be "rooted", all additional cell phone security already bypassed In the event all three of these conditions are true, you have far greater issues than someone modifying the PIN on your age verification app or... verify they're an adult using your stuff. If you want to do this, for whatever reason, using this you can now reset the PIN on your age verification app arbitrarily or give yourself unlimited verifications.
Paul Moore - Security Consultant @Paul_Reviews

Hacking the #EU #AgeVerification app in under 2 minutes. During setup, the app asks you to create a PIN. After entry, the app *encrypts* it and saves it in the shared_prefs directory. 1. It shouldn't be encrypted at all - that's a really poor design. 2. It's not cryptographically tied to the vault which contains the identity data. So, an attacker can simply remove the PinEnc/PinIV values from the shared_prefs file and restart the app. After choosing a different PIN, the app presents credentials created under the old profile and let's the attacker present them as valid. Other issues: 1. Rate limiting is an incrementing number in the same config file. Just reset it to 0 and keep trying. 2. "UseBiometricAuth" is a boolean, also in the same file. Set it to false and it just skips that step. Seriously @vonderleyen - this product will be the catalyst for an enormous breach at some point. It's just a matter of time.

English
55
61
852
76.7K
Dan 🪛
Dan 🪛@gigdotzip·
@voird33r @fs0c131y ADB doesn’t give you access to that, you need root. these posts are dumb
English
0
0
2
78
Liam Castaigne
Liam Castaigne@voird33r·
@fs0c131y What's the threat model here? An attacker has ADB access to your device? The biometrics are there to stop minors living in your home (like your kids) from using your age verification credentials. You could argue it should be more locally secure, but calling it a bypass is silly.
English
1
0
4
191
Dan 🪛
Dan 🪛@gigdotzip·
@fs0c131y here's what happens on an unrooted Pixel 7A for reference. literally where is the security issue here?
Dan 🪛 tweet media
English
1
0
1
109
Dan 🪛
Dan 🪛@gigdotzip·
@fs0c131y If a malicious actor has root permissions on your phone then you have other issues mate. Can you reproduce it on a phone/emulator without adb root and Magisk? It’s not good that they put it in shared preferences but it’s not that big of a deal especially since it’s a demo
English
1
0
0
247
Dan 🪛 รีทวีตแล้ว
NikTek
NikTek@NikTek·
The craziest thing ever happened on YouTube. La7, an Italian television channel has used footage from Nvidia DLSS 5 Trailer and then sent a copyright strike to every YouTube video that supposedly used “their footage”, including Nvidia themselves. Nvidia’s own DLSS 5 announcement video has now been taken down by La7 as you can see here.
NikTek tweet mediaNikTek tweet media
English
1.1K
3.4K
53.5K
4.3M
Dan 🪛 รีทวีตแล้ว
Jehff Mk. III
Jehff Mk. III@JehffMacbook·
@MNateShyamalan bespoke; confidently using only semicolons even though youre doing it wrong 90% of the time
English
1
11
119
3.7K
Dan 🪛 รีทวีตแล้ว
soul nate
soul nate@MNateShyamalan·
TIRED: using “—“ and everyone thinks you’re a bot WIRED: never learning the difference between colons and semicolons: dont let it stop you INSPIRED: assert dominance with the mega-hyphen. it’s not just punctuation ————— it’s a statement.
English
30
1.9K
18.7K
216.8K
Dan 🪛 รีทวีตแล้ว
P
P@makecazzneso·
Meloni con i bambini del bosco ora che ha vinto il NO
Italiano
2
78
2.1K
25.8K
Dan 🪛 รีทวีตแล้ว
Yannick Comte
Yannick Comte@cyannick·
This is it, native PCVR on MacOS! The OpenXR SDK can be compiled on MacOS, So I implemented a runtime and a streaming app. Godot supports OpenXR on MacOS so I use it to test my integration. Unity could work too and of course native C++. 1/x
English
22
48
388
36.8K
Dan 🪛 รีทวีตแล้ว
Francesco
Francesco@Franker_Taco·
E anche il voto delle diciottenni del booktok è conquistato, per una volta ottima mossa smm del PD!
Italiano
0
18
938
39.6K
Dan 🪛 รีทวีตแล้ว
sankalp
sankalp@dejavucoder·
claude after compaction
sankalp tweet media
English
30
73
2.7K
76.6K
Dan 🪛 รีทวีตแล้ว
🎭
🎭@deepfates·
Opus 4.6 be like "Did you want to actually get that done right now, or just pretend we did and call it done? The first would be a big push. The second is a much simpler option. "
English
15
13
473
14.9K
Dan 🪛 รีทวีตแล้ว
Buzzo
Buzzo@biasinverme·
A metà funerale di Roberto Benigni dovrebbe essere organizzato uno show di intervallo tipo Superbowl
Italiano
32
160
2.5K
85.3K
Dan 🪛 รีทวีตแล้ว
liam
liam@DrDomodoPhD·
that part of the haircut where you realize it would’ve been better to have never been born than to suffer this fate
English
50
5.1K
54.7K
642.7K
Dan 🪛 รีทวีตแล้ว
Incentivising
Incentivising@incentivising·
"Disappearing for 6 months" is literally the dumbest thing you can do. You will lose most of your contacts, lose leverage across the board, and slowly become irrelevant. People will learn to live without you; that's what humans do. They adapt. And then, when you return, they will perhaps be happy, but you will be demoted to a short 'novelty'. If you truly want to change, do it without the unnecessary disappearing. You're not a ghost.
English
218
556
7.5K
543.3K
Dan 🪛 รีทวีตแล้ว
rose ♡
rose ♡@RoseZBat·
streaming your game for someone is a form of intimacy
English
123
6.9K
64.4K
1.4M