C'est le cœur lourd que j'ai quitté hier la rédaction de https://t.co/2aGXBIFtZ3. Big up à @ZonGO, @adrianbranco et @downhill911, ainsi qu'à toute la rédac. Vous allez me manquer !
Hacking the #EU#AgeVerification app in under 2 minutes.
During setup, the app asks you to create a PIN. After entry, the app *encrypts* it and saves it in the shared_prefs directory.
1. It shouldn't be encrypted at all - that's a really poor design.
2. It's not cryptographically tied to the vault which contains the identity data.
So, an attacker can simply remove the PinEnc/PinIV values from the shared_prefs file and restart the app.
After choosing a different PIN, the app presents credentials created under the old profile and let's the attacker present them as valid.
Other issues:
1. Rate limiting is an incrementing number in the same config file. Just reset it to 0 and keep trying.
2. "UseBiometricAuth" is a boolean, also in the same file. Set it to false and it just skips that step.
Seriously @vonderleyen - this product will be the catalyst for an enormous breach at some point. It's just a matter of time.
Sans 60 Millions de Consommateurs, on n’aurait peut-être jamais su que Shein vendait des poupées sexuelles de fillettes.
Le gouvernement, lui, veut supprimer ce journal et l'INC.
https://t.co/dy7ZQBUe8Y
Réaction assez symptomatique du "petit monde de la tech" qui ne tolère que celle-ci ne soit commentée (par des influenceurs ou des journalistes) qu'à travers le prisme de l'optimisme absolu. Et on ne peut pas dire que MKBHD soit un apôtre du technoscepticisme...
Petit tuto pour celles et ceux qui, comme moi, n'arrivent pas à passer l'arène des Grandes Galeries de Silksong. En fait, c'est tout simple, regardez ! 🫠😭
https://t.co/FFe1SLpwuO
DDR5 is unstable garbage.
Max out your memory channels? Flaky.
Temperature a bit too hot? Silent Throttle with no logs.
Too “Dense” of a stick? Good luck training.
Last gen was rock solid by comparison. Here's what happened.
Just a friendly reminder that the majority of new Apple products released today will be destroyed years before their time due to Apple's Activation Lock, remote management lock, and parts pairing.
These faulty systems cause perfectly legitimate Apple products to be bricked when users and institutions inevitably pass them on without removing credentials. Although in perfect working condition, these tens of millions of devices a year cannot be reused, refurbished, or even salvaged for their parts.
But don't mind me -- keep celebrating! Hooray Apple!
#righttoreuse #righttorefurbish #righttorepair
Découvrez les nouveaux iPhone Air et iPhone 17 Pro. L’iPhone Air, une résistance remarquable pour le plus fin des iPhone. L’iPhone 17 Pro, le plus puissant des iPhone et son autonomie prodigieuse. Quel que soit votre choix, c’est gagnant-gagnant.
Apple est en grande partie responsable de ce qui arrive à toute sa presse dédiée… Plus d’affiliation, jamais aucun budget pub, et surtout, aucune exclusivité/preview, réservées à quelques médias/influenceurs. Alors qu’elle n’a jamais fait autant de bénéfices ! Courage les gars.
Amazon requires new sellers to have a company name of at least 7
some letters to avoid manual checks. Hence Chinese white label resellers just check some alphabetti spaghetti and come up with CUKTECH and NICGIGA or KPKKQUE or FUXK etc