Actionable Truth Media

16.7K posts

Actionable Truth Media banner
Actionable Truth Media

Actionable Truth Media

@actionabletruth

The Truth and nothing but the Truth but also what you can DO about it. Subscribe to the newsletter: https://t.co/Gxcy0hWN5H

Prisoner Island شامل ہوئے Aralık 2008
1.4K فالونگ2.1K فالوورز
Actionable Truth Media ری ٹویٹ کیا
Paul Moore - Security Consultant 
Hacking the #EU #AgeVerification app in under 2 minutes. During setup, the app asks you to create a PIN. After entry, the app *encrypts* it and saves it in the shared_prefs directory. 1. It shouldn't be encrypted at all - that's a really poor design. 2. It's not cryptographically tied to the vault which contains the identity data. So, an attacker can simply remove the PinEnc/PinIV values from the shared_prefs file and restart the app. After choosing a different PIN, the app presents credentials created under the old profile and let's the attacker present them as valid. Other issues: 1. Rate limiting is an incrementing number in the same config file. Just reset it to 0 and keep trying. 2. "UseBiometricAuth" is a boolean, also in the same file. Set it to false and it just skips that step. Seriously @vonderleyen - this product will be the catalyst for an enormous breach at some point. It's just a matter of time.
Paul Moore - Security Consultant @Paul_Reviews

.@vonderleyen "The European #AgeVerification app is technically ready. It respects the highest privacy standards in the world. It's open-source, so anyone can check the code..." I did. It didn't take long to find what looks like a serious #privacy issue. The app goes to great lengths to protect the AV data AFTER collection (is_over_18: true is AES-GCM'd); it does so pretty well. But, the source image used to collect that data is written to disk without encryption and not deleted correctly. For NFC biometric data: It pulls DG2 and writes a lossless PNG to the filesystem. It's only deleted on success. If it fails for any reason (user clicks back, scan fails & retries, app crashes etc), the full biometric image remains on the device in cache. This is protected with CE keys at the Android level, but the app makes no attempt to encrypt/protect them. For selfie pictures: Different scenario. These images are written to external storage in lossless PNG format, but they're never deleted. Not a cache... long-term storage. These are protected with DE keys at the Android level, but again, the app makes no attempt to encrypt/protect them. This is akin to taking a picture of your passport/government ID using the camera app and keeping it just in case. You can encrypt data taken from it until you're blue in the face... leaving the original image on disk is crazy & unnecessary. From a #GDPR standpoint: Biometric data collected is special category data. If there's no lawful basis to retain it after processing, that's potentially a material breach. youtube.com/watch?v=4VRRri…

English
376
3.1K
12.5K
839.6K
Actionable Truth Media
Actionable Truth Media@actionabletruth·
@cogsecbrian @Geopolitics_Emp Are you sure you read my piece... because UK column was not the focus. Anyways, this is going nowhere. I thought you can provide some actual facts that I missed. Let's move on.
English
1
0
1
14
Brian
Brian@cogsecbrian·
@actionabletruth @Geopolitics_Emp I could say the same of your research because all you have done is pointed out that a man (who researches crypto) and has links to China owns 20% of UK Columns parent company. I think your focus is misplaced.
English
1
0
0
15
Actionable Truth Media
Actionable Truth Media@actionabletruth·
@cogsecbrian @Geopolitics_Emp All very interesting but what additional FACTUAL information can you add to the conversation? I didn't see any in the thread. Maybe I missed it so can you help me out please?
English
1
0
2
14
Brian
Brian@cogsecbrian·
@actionabletruth @Geopolitics_Emp Attempted character assassination and undermining me will not help your cause or promote this story. If you wish to go into detail as to why I believe Marcel is not important I am happy to do so.
English
1
0
0
18
Brian
Brian@cogsecbrian·
@actionabletruth @Geopolitics_Emp I think Marcel is the antithesis to the "left-wing" philanthro-capitalists network (OSF/Omidyar). His money is clearly obscured but once explained I think your campaign against UK Column and other will be exposed for what it is. An attempt to divide the alt media.
English
1
0
0
22
Actionable Truth Media ری ٹویٹ کیا
6 News Australia
6 News Australia@6NewsAU·
#BREAKING: 'Equipment failure' is being blamed for giant fire at Geelong oil refinery The refinery provides around 10% of the nation’s fuel More to come. @AustinPollock_9
English
20
18
81
7.4K
Actionable Truth Media ری ٹویٹ کیا
RYAN SΞAN ADAMS - rsa.eth 🦄
AI KYC is here. New claude subscribers asked for gov ID & photo. Not even a regulatory requirement - Anthropic just doing it because they want to. But regulatory is coming Next up will be laws: No AI without gov-issued ID All AI use tracked to individual - no private AI
RYAN SΞAN ADAMS - rsa.eth 🦄 tweet mediaRYAN SΞAN ADAMS - rsa.eth 🦄 tweet media
English
188
166
959
121.3K
Kai
Kai@hqmank·
Claude now requires government ID verification (via Persona) before subscription. ChatGPT doesn't. Gemini doesn't. Anthropic just handed their competitors a gift.
Kai tweet media
English
545
471
5K
749.6K
Actionable Truth Media ری ٹویٹ کیا
Kateryna Lisunova
Kateryna Lisunova@KaterynaLis·
‼️ ZELENSKYY: For the first time in the war, an enemy position was captured entirely by ground robotic systems and drones - without any infantry. A robot entered the most dangerous zones instead of a soldier and took the positions. «The future is here, on the battlefield, and Ukraine is creating it. These are our ground robotic systems. For the first time in this war's history, an enemy position was taken exclusively by unmanned GRS platforms and drones. The occupiers surrendered, and this operation was completed without infantry involvement and without losses on our side. Ratel, Termite, Ardal, Lynx, Zmiy, Protector, Volya and other GRS completed over 22 000 missions at the front in just 3 months. In other words, over 22 000 times lives were saved. A robot went into the most dangerous zones instead of a soldier» - Zelenskyy’s address to the workers of Ukraine’s defense-industrial complex. April 13th, 2026.
English
1.3K
10.7K
53.8K
5M
Actionable Truth Media ری ٹویٹ کیا
Kurt Metzger
Kurt Metzger@kurtmetzger·
ZXX
140
694
4K
158.9K