Hacking the #EU#AgeVerification app in under 2 minutes.
During setup, the app asks you to create a PIN. After entry, the app *encrypts* it and saves it in the shared_prefs directory.
1. It shouldn't be encrypted at all - that's a really poor design.
2. It's not cryptographically tied to the vault which contains the identity data.
So, an attacker can simply remove the PinEnc/PinIV values from the shared_prefs file and restart the app.
After choosing a different PIN, the app presents credentials created under the old profile and let's the attacker present them as valid.
Other issues:
1. Rate limiting is an incrementing number in the same config file. Just reset it to 0 and keep trying.
2. "UseBiometricAuth" is a boolean, also in the same file. Set it to false and it just skips that step.
Seriously @vonderleyen - this product will be the catalyst for an enormous breach at some point. It's just a matter of time.
🥚Here’s an Easter egg the Government doesn’t want us to find in the digital ID plans…
Our digital ID photos could be subverted into police facial recognition mugshots.
It's clear - a sprawling digital ID system will cost us our rights & freedoms | https://t.co/Y6P1zIiUsf
@UK_Daniel_Card@Alph4betSoup I mean no one with money lobbies for a bill to audit and finning social media and other services for using shady dark patterns and other solution. That would be bad for the businesses. That can not stand.
@UK_Daniel_Card@Alph4betSoup I did the one meant for parents.
one question really stand out. multi-choice : what feature should be restricted by age verification:
- share n. de image, video
that word really had to be in there.
there was one section mentioning dark patterns , but only mentioning
Darren Jones says “none of that is true” when asked whether police could access digital ID photographs for facial recognition searches.
Yet the consultation published yesterday explicitly says this is a possibility.
@darrenpjones is the consultation wrong, or are you?
think of the children;
give up your freedom, give up your privacy, give up your right to peacefully and anonymously disagree.....
but think of the children, but don't dare disagree!
think of the children, unless you disagree with me!
think of the children, or suffer the consequences, no more online freedom for thee!
#UK #Online #Safety #Distopia #Privacy
@primusmagestri@UK_Daniel_Card Most case is that some people prefer and trust f-droid versions of some apps more, Especially with lineageOS or similar non-official image. Play store is not installed by default and some app installed from play store via third party store app and only used when necessary.
@UK_Daniel_Card Oh these devices are just gorgeous. I have a very minimalist EE product which basically a white labeled product based on modified alcatel onetouch . Had a really interesting factory debug method over usb ( reboot with adb because the kernel is an old android kernel)
HMRC also suffered an outage this morning by the looks of it… as far as I know the AWS was specific to us-east-1.
Surely this should have had a limited impact (unless they were using some US 3rd party somewhere)?