EU-DILETTANTISMUS❗️
Gestern kündigt vdL großspurig die „sichere“ EU-Altersverifizierungs-App an, heute hat sie der Sicherheitsforscher Paul Moore in weniger als 2 Minuten geknackt.
@Paul_Reviews hat eine Schritt-für-Schritt-Methode veröffentlicht, die zeigt, wie sie in weniger als 2 Minuten direkt innerhalb der App umgangen werden kann.
WAS FÜR EIN SAFTLADEN!
Hacking the #EU#AgeVerification app in under 2 minutes.
During setup, the app asks you to create a PIN. After entry, the app *encrypts* it and saves it in the shared_prefs directory.
1. It shouldn't be encrypted at all - that's a really poor design.
2. It's not cryptographically tied to the vault which contains the identity data.
So, an attacker can simply remove the PinEnc/PinIV values from the shared_prefs file and restart the app.
After choosing a different PIN, the app presents credentials created under the old profile and let's the attacker present them as valid.
Other issues:
1. Rate limiting is an incrementing number in the same config file. Just reset it to 0 and keep trying.
2. "UseBiometricAuth" is a boolean, also in the same file. Set it to false and it just skips that step.
Seriously @vonderleyen - this product will be the catalyst for an enormous breach at some point. It's just a matter of time.
Bereit für ⚡️blitzschnelle Verbindungen?
Prêt pour des connexions ultra-rapides ⚡️ ?
Unsere neuen #PoPs sind live!
- 680BNX #bernex
- 680PLA #vessy
- 650LYS #lyss
Alle geplanten und aktiven PoPs findet ihr unter https://t.co/Kq14Al5A32.
#OTD 33 years ago, Linus Torvalds sent a short announcement to the Minix newsgroup. The subject? An OS he was building - "just a hobby, won't be big and professional like gnu", Torvalds said. That OS? #Linux - the most important OS, ever - Happy Birthday!
The first reviews are in… and David’s new album, Luck and Strange, is going down a storm with the critics!
Pre-order the album - out in less than two weeks, on Sept 6th - at https://t.co/GmRmAMjL0x now.
Im Juli erklärte Google https://t.co/5pPLks7vWv zum Spammer und verweigerte die E-Mail-Annahme. Die Probleme der stark zentralisierten Mail-Infrastruktur werden dadurch deutlich. #Google#EMail https://t.co/VV4eCurlkS
@kdecommunity is developed by a #community of passionate people. KDE #develops for everyone, from kids to grandparents and from professionals to hobbyists. Is it difficult to get involved? Not at all!
Read more: https://t.co/IWTHdih267
In den Untiefen seiner Allgemeinen Geschäftsbedingungen klärt der Videotelefoniedienst Zoom darüber auf, dass er umfangreich Daten seiner Nutzer:innen sammelt. Die Daten sollen als Trainingsmaterial für "Künstliche Intelligenz" dienen, so das Unternehmen.
https://t.co/jbVRfK7nVe