Hacking the #EU#AgeVerification app in under 2 minutes.
During setup, the app asks you to create a PIN. After entry, the app *encrypts* it and saves it in the shared_prefs directory.
1. It shouldn't be encrypted at all - that's a really poor design.
2. It's not cryptographically tied to the vault which contains the identity data.
So, an attacker can simply remove the PinEnc/PinIV values from the shared_prefs file and restart the app.
After choosing a different PIN, the app presents credentials created under the old profile and let's the attacker present them as valid.
Other issues:
1. Rate limiting is an incrementing number in the same config file. Just reset it to 0 and keep trying.
2. "UseBiometricAuth" is a boolean, also in the same file. Set it to false and it just skips that step.
Seriously @vonderleyen - this product will be the catalyst for an enormous breach at some point. It's just a matter of time.
The best backtest @TraderMayne has ever reviewed.
A member submitted their backtest and got a full breakdown of:
•What they did right
•What could've been avoided
•How they took Mayne's system and made it their own
Take an analyst system, put in the work and this is what happens.
The founder of OpenClaw (Originally known as ClawdBot) Peter Steinberger, has agreed to join Sam Altman and OpenAI
OpenClaw will “live in a foundation as an open source project that OpenAI will continue to support.”
@LSDinmycoffee Trump took office and introduced uncertainty.
Unless that uncertainty comes roaring back then the same themes won’t cause the same outcomes.