El otro día nos pasaron un desarrollo para poner en producción en un entorno que nos iban a contratar. Como no sabían bien qué tipo de VPS necesitaban, nos dieron acceso para ver la app.
Nos dijeron que estaba "listo a falta de 3 retoques".
Era un desarrollo que habían hecho los del departamento financiero de la empresa aprovechando que habían dado un curso de Antigravity.
Usa 5 lenguajes de programación distintos: PHP, Node, Apps Script, PowerShell y .bat. Cada trozo resuelto de una forma diferente. Las "bases de datos": ficheros JSON y Excels...
Datos reales de 9.000 clientes dentro del repo: NIF, IBAN, márgenes, historial de facturación. Sin anonimizar. De hecho, aunque los borres hoy, siguen en el historial de Git...
La contraseña de admin se comprueba en el navegador. Está escrita en el JavaScript que se descarga cualquiera. El servidor responde a quien pregunte, sin autenticar, por HTTP. Leer, modificar y borrar registros: gratis.
El control de acceso funcionaba perfectamente, siempre que el atacante no supiera pulsar F12.
Rutas fijas del PC del desarrollador, cero tests, 1 GB de repo con las librerías y las bases de datos dentro. Y en una herramienta, rastros de que el código se corrompió y lo reconstruyeron a partir de logs y ficheros de texto...
Los commits, una novela: "arreglado", "ahora sí", "ahora sí de verdad", "funciona no tocar", "woooo"...
Todo en GitHub. Privado, pero GitHub.
Estuvimos entre cortarnos las venas o dejárnoslas largas.
Obviamente hemos dicho: NO.
acompañadme en la autistada del día 🧵
el otro día me quejé de que Andrea Garte tiene flickering en las tiras LED de Balanzen
y me he hecho la pregunta que se haría cualquier persona normal y funcional:
¿se podría medir la frecuencia EXACTA del parpadeo desde un vídeo de YouTube?
Spoiler: sí, y con decimales y todo
ok honnêtement ? une partie de moi VEUT qu’ils votent le Chat Control 😂
Sérieux. Allez-y. Faites-le.
Parce que ces gens comprennent rien à la technologie. Zéro. Ils ont jamais codé une ligne de leur vie et ils débarquent en mode « on va scanner les messages de 450M de personnes pour protéger les enfants ». Non. C’est de la surveillance de masse. Point. Tout le monde le sait.
Voici ce qu’ils captent pas :
La privacy c’est des maths. Tu peux pas légiférer contre les maths lol. Le chiffrement de bout en bout marche ou marche pas — y’a pas de « juste un petit backdoor pour les gentils ». Ça existe pas. N’importe quel ingénieur te le dira.
Ils veulent scanner côté client, avant le chiffrement ? Bravo 👏 Vous venez de déclarer la guerre à toute une génération de cryptographes qui vont bosser 24/7 pour vous rendre obsolètes. Le talent va PARTOUT sauf là où on l’écrase.
C’est ça le truc que les régulateurs pigent jamais : chaque loi débile contre la privacy = accélérateur pour la privacy. Toujours. Historiquement, à chaque fois. Tu fermes une porte, il s’ouvre 10 fenêtres. Décentralisation, protocoles chiffrés, tout explose.
Donc franchement — qu’ils le fassent. Qu’ils transforment leur mépris en carburant. Ce qui va sortir de là c’est pas un troupeau surveillé bien sage. C’est une infrastructure de résistance tellement solide et tellement banale que tout le monde l’utilisera sans même y penser.
Le Chat Control tuera pas la privacy.
Ce sera le meilleur truc qui lui soit jamais arrivé.
Et le plus drôle 😂 c’est qu’ils l’auront voté eux-mêmes.
Phishing and social engineering are getting more sophisticated at an exponential rate due to AI.
Proton just let a phishing email go through to my inbox that I think will compromise tens of thousands of folks.
How it seems to work: someone added my email to a real Google Group. They then sent out a message to all members of the group with subject line "Your Google data has been exported."
Obviously this will cause many people to panic. The email went through to my inbox because it came from a legit google group from a legit Google URL.
All links in the email look totally normal – unless you look at the link for "Cancel request" button. But amazingly this one also seems to come from a genuine Google URL – a URL shortener from Google! goo[dot]gl/XXXXX (not putting the real URL here).
Then it takes you to (1) a Recaptcha screen and then (2) a genuine looking Google account login screen. It's hosted on a Google site (sites[dot]google[dot]com) so everything looks legit.
Because all links are technically hosted by Google, this is very very bad.
Saldırı değil. Gerçekten uzak, mükemmel koşullarda test edilen zımbırtılardan biri daha.
Uçuş süresi 22 saniye, RSSI -66 yani kalkış yerine çok yakın, batarya ortalama hücre voltajı 3.9V, faydalı yük yok. Uçuş hızı saldırı hızından çok uzak.
Binlerce takipçisi olan "bu" sayfaların paylaşımları yine şaşırtmıyor. Araştırma 0, kopyala yapıştır...
Hacking the #EU#AgeVerification app in under 2 minutes.
During setup, the app asks you to create a PIN. After entry, the app *encrypts* it and saves it in the shared_prefs directory.
1. It shouldn't be encrypted at all - that's a really poor design.
2. It's not cryptographically tied to the vault which contains the identity data.
So, an attacker can simply remove the PinEnc/PinIV values from the shared_prefs file and restart the app.
After choosing a different PIN, the app presents credentials created under the old profile and let's the attacker present them as valid.
Other issues:
1. Rate limiting is an incrementing number in the same config file. Just reset it to 0 and keep trying.
2. "UseBiometricAuth" is a boolean, also in the same file. Set it to false and it just skips that step.
Seriously @vonderleyen - this product will be the catalyst for an enormous breach at some point. It's just a matter of time.
.@vonderleyen "The European #AgeVerification app is technically ready. It respects the highest privacy standards in the world. It's open-source, so anyone can check the code..."
I did. It didn't take long to find what looks like a serious #privacy issue.
The app goes to great lengths to protect the AV data AFTER collection (is_over_18: true is AES-GCM'd); it does so pretty well.
But, the source image used to collect that data is written to disk without encryption and not deleted correctly.
For NFC biometric data:
It pulls DG2 and writes a lossless PNG to the filesystem. It's only deleted on success. If it fails for any reason (user clicks back, scan fails & retries, app crashes etc), the full biometric image remains on the device in cache. This is protected with CE keys at the Android level, but the app makes no attempt to encrypt/protect them.
For selfie pictures:
Different scenario. These images are written to external storage in lossless PNG format, but they're never deleted. Not a cache... long-term storage. These are protected with DE keys at the Android level, but again, the app makes no attempt to encrypt/protect them.
This is akin to taking a picture of your passport/government ID using the camera app and keeping it just in case. You can encrypt data taken from it until you're blue in the face... leaving the original image on disk is crazy & unnecessary.
From a #GDPR standpoint:
Biometric data collected is special category data. If there's no lawful basis to retain it after processing, that's potentially a material breach.
https://t.co/PKQ0DWSYzL
chinese antivirus companies are shipping kernel drivers that let any local user take over your entire system
i reversed two drivers from Qihoo 360 and Kingsoft. one has a heap overflow that corrupts 512 bytes of kernel pool. the other lets you kill any process and read/write kernel memory with a static AES key embedded in the binary
these are "security" products. thread
That tiny red nub sitting between the G, H, and B keys on keyboards has been quietly dividing the tech world for over 30 years. Half the people who encounter it have no idea what it does. The other half refuse to use anything else.
It’s called the TrackPoint. And it was born out of a single frustrating observation.
In 1984, a researcher named Ted Selker conducted a study showing that it takes a typist 0.75 seconds to shift their hand from the keyboard to the mouse and a comparable amount of time to shift back. That 1.5 seconds of lost time, multiplied across an entire workday, felt like a solvable problem. So he built something that would eliminate it entirely; a pressure-sensitive nub planted right in the middle of the keyboard, so your hands never had to leave the keys at all. IBM introduced it commercially in 1992 on the ThinkPad 700 series.
The way it works is not what most people expect. It doesn’t move like a joystick. It responds to pressure. Beneath the rubber cap sit strain gauges that measure the force applied in different directions and translate it into cursor movement. The harder you press, the faster the cursor moves. There is no repositioning, no lifting your finger, no running out of space. Infinite cursor movement from a single fingertip that never moves more than a millimeter.
The red color almost didn’t happen. IBM’s product safety division had reserved red exclusively for emergency power-off switches on mainframe computers.
ThinkPad designer Richard Sapper got around this by calling the color IBM Magenta and when the first batch shipped, the engineers made it decidedly more crimson. A loophole dressed in plain sight.
Power users programmers, analysts, executives who live on their keyboards swear by it. The reason, according to Lenovo’s chief design officer, is that your hands never leave the home row. You type and navigate simultaneously, without the constant interruption of reaching for a trackpad. Once mastered, people say it feels less like using a tool and more like an extension of thought.
Most laptops abandoned it. Lenovo never did. And the people who know, know.
Una vez, en China, fui a un súper a comprar patatas.
Patata en chino se dice 土豆 (Tǔdòu). El súper era de barrio y lo llevaba una parejita mayor. Fui a donde las verduras y tal, pero no las veía. Le dije al abuelo: «你们有土豆吗?» (¿Tenéis patatas?). El señor, un poco malhumorado, se me quedó mirando como si le hablase en chino, je je. No, es que el yayo no me entendía. Como buen gallego, me puse terco y me dije: «Me va a entender por mis cojon*s».
Como sabéis, el chino es un idioma tonal, por lo que, si no pronuncias bien el tono, no te entienden. Probé de todo. Tǔdòu. Tùdōu. Tǔdóu. Tudou. Tudela. El señor tenía la misma cara que al principio y tenía pinta de que iba a llamar a la policía. Vino su mujer. Ella parecía risueña, más relajada. Poli bueno. Repito el proceso de pronunciación. Se me queda mirando con la misma cara, pero sonriendo.
Es decir: vale, soy gallego. No pronuncio bien. Lo entiendo. Pero, vamos a ver, TUDOU. TU-DOU. Contexto: supermercado, zona de verduras y hortalizas. ¿Qué te estoy pidiendo,amic, una rebarbadora? ¿Un subfusil de asalto? Será algo de esa sección del súper, maldita pareja de ancianos mandarines.
Me rindo. Voy a la aplicación del chino y escribo «POTATO» (es inglés-chino, por desgracia). Aparecen los caracteres chinos en grande: «土豆». Ah caralho, agora sim entendo.jpg.
―没有了!
Que no había. Por eso no las veía. Se habían agotado. Un súper sin patatas, como un jardín sin flores.
Juré en arameo. Y en gallego. Maldecí a la civilización que me acogía desde la Dinastía Song. Sin embargo, al segundo, entendí: el Destino no tenía preparadas patatas para mí. El Mandato del Cielo me negó al tubérculo sagrado.
Confucio sostenía que el éxito final de nuestras acciones puede depender del destino, pero la intención (buena o mala) y la voluntad que ponemos en ellas dependen exclusivamente de nosotros.
Aprendí una lección. Me despedí diciéndoles 再见 (Zàijiàn): «Adiós». Tampoco me entendieron.
Me fui sin ser visto, sin ser oído, pero habiendo aprendido que, a veces, el Mandato del Cielo consiste simplemente en aceptar que no va a haber patatas, y que el verdadero viaje no era conseguirlas, sino descubrir hasta dónde estaba dispuesto a llegar para que te entendiera un hombre que solo quería cerrar la tienda porque había ido un poco tarde.
i kept wasting my weekends doing nothing so i built a button that kidnaps me. whenever im bored, i press it and it books an uber to a random interesting place in my city🚘
it has a physical digital push button connected to my raspi, and some python script.
ive pressed it 11 times so far and never had a bad trip. ok bye, going to a 110-year-old wrestling pit in shivajinagar, blr. i don't know what to expect but i'm excited
"yeah i use a password manager, i don't even know my passwords they're so secure"
reality:
movie night is just me typing a 64-character password with a TV remote
‼️A security researcher from Australia built a mass surveillance tool by scraping Waze reports and tracking the users behind them
He successfully linked usernames to real-world identities, allowing him to pinpoint where individuals live and work.
Waze has since responded by removing the feature that exposed usernames.
A raíz de este magistral tuit de @XMihura, os cuento una experiencia personal de verdad verdadera.
Yo mismo, hace muchos años. Trabajando en empresa informática multinacional con sucursal en Madrid. Proyecto de desarrollo de software para gestión de sistemas de tierra en aeropuertos españoles. Yo soy programador junior. Me ponen a currar con una tipa senior que, por lo que fui viendo, no tenía mucha más idea que yo.
Objetivo: desarrollar un sistema de gestión de equipajes para siete aeropuertos españoles. Es el software que se encarga de saber dónde está tu equipaje facturado en cada momento. Plataforma: máquinas Unix suministradas por la propia empresa (fabricaba hardware además de software), colección de más de 80 scripts en bash que operan sobre unos archivos de texto plano en un formato malamente documentado.
Trabajamos un par de meses y llega el día de la prueba piloto. Me mandan al aeropuerto de El Prat un sábado por la tarde. La idea es bajar los sistemas actuales de madrugada, desplegar los nuevos, y arrancarlos para empezar el domingo ya con ellos.
A las dos de la mañana bajamos todo. Instalamos y aquello no tira. Depuración en sistemas de producción a las tres de la mañana sabiendo que tienes el aeropuerto parado, y que a las seis tiene que arrancar sea como sea. No tira. El supervisor suda más que yo.
A las cinco de la mañana me rindo. Reinstalamos el sistema viejo y arrancamos. Pero tampoco va. Nervios máximos. Infarto. Terror.
Conseguí arrancar el sistema viejo a las ocho de la mañana, produciendo una incidencia brutal en el transporte de equipajes. Pienso “nunca más”. Cojo vuelo de vuelta a Madrid, duermo todo el domingo, aparezco en la oficina el lunes y presento mi carta de renuncia.
Aquel día me propuse aprender a hacer software bien. Creo que lo he conseguido, pero la lección de El Prat y los 80 scripts en bash no se me olvidará jamás.