⚠️👀🐸👀⚠️
DAS FROSCH-SIEGEL
Eine gut gemachte und verständliche Erklärung zum Frosch-Siegel!
Damit sollte jeder verstehen, dass es besser ist, die Hände davon zu lassen!
✨Mehr auf✨
https://t.co/81jZKEALow
Anmerkung:
Denkt an den hochgiftigen Pfeilfrosch!
Das Kabinett hat heute beschlossen: Internetprovider müssen künftig alle IP-Adressen ihrer Kunden drei Monate lang speichern. Anlasslos.
Endlich wissen sie, wer wann welche Katzenvideos geguckt hat. Der Überwachungsstaat dankt – und nennt es ‚Sicherheit‘.“
Wer findet das noch „verhältnismäßig“? 👇
‼️🇪🇺 The EU's new Age Verification app was hacked with little to no effort.
When you set it up, the app asks you to create a PIN. But that PIN isn't actually tied to the identity data it's supposed to protect. An attacker can delete a couple of entries from a file on the phone, restart the app, pick a new PIN, and the app happily hands over the original user's verified identity credentials as if nothing happened.
It gets worse. The app's "too many attempts" lockout is just a counter in a text file. Reset it to 0 and keep guessing. The biometric check (face/fingerprint) is a simple on/off switch in the same file. Flip it to off and the app skips it entirely.
Bypassing #EU#AgeVerification using their own infrastructure.
I've ported the Android app logic to a Chrome extension - stripping out the pesky step of handing over biometric data which they can leak... and pass verification instantly.
Step 1: Install the extension
Step 2: Register an identity (just once)
Step 3: Continue using the web as normal
The extension detects the QR code, generates a cryptographically identical payload and tells the verifier I'm over 18, which it "fully trusts".
This isn't a bug... it's a fundamental design flaw they can't solve without irrevocably tying a key to you personally; which then allows tracking/monitoring.
Of course, I could skip the enrolment process entirely and hard-code the credentials into the extension... and the verifier would never know.