‼️🇪🇺 The EU's new Age Verification app was hacked with little to no effort.
When you set it up, the app asks you to create a PIN. But that PIN isn't actually tied to the identity data it's supposed to protect. An attacker can delete a couple of entries from a file on the phone, restart the app, pick a new PIN, and the app happily hands over the original user's verified identity credentials as if nothing happened.
It gets worse. The app's "too many attempts" lockout is just a counter in a text file. Reset it to 0 and keep guessing. The biometric check (face/fingerprint) is a simple on/off switch in the same file. Flip it to off and the app skips it entirely.
@vonderleyen We do not want age verification! The intrusion into private life is too big and the data safety is not sufficient! We can protect our children ourselves. This is not a state matter. Stop it!
@thundaga99@AngelicaOung A force for good? By fueling the war of aggression in Ukraine? By digital-jailing it's own people? By adding new coal capacity enough to completely offset EU's climate efforts?
@Bwipo I am sorry you have to apologise for speaking basic, real things. Remember, the cancel mob will never be happy.
You're a great player, keep up the grind.