Bram Kanstein / @bramk:
RT by @bramk: Hacking the #EU #AgeVerification app in under 2 minutes.
During setup, the app asks you to create a PIN. After entry, the app *encrypts* it and saves it in the shared_prefs directory.
1. It shouldn't be encrypted at all - that's a really poor design.
2. It's not cryptographically tied to the vault which contains the identity data.
So, an attacker can simply remove the PinEnc/PinIV values from the shared_prefs file and restart the app.
After choosing a different PIN, the ap...
RT by @bramk: Hacking the #EU #AgeVerification app in under 2 minutes.
During setup, the app asks you to create a PIN. After entry, the app *encrypts* it and saves it in the shared_prefs directory.
1. It shouldn't be encrypted at all - that's a really poor design.
2. It's not cryptographically tied to the vault which contains the identity data.
So, an attacker can simply remove the PinEnc/PinIV values from the shared_prefs file and restart the app.
After choosing a different PIN, the ap...
Nitter
Paul Moore - Security Consultant (@Paul_Reviews)
Hacking the #EU #AgeVerification app in under 2 minutes.
During setup, the app asks you to create a PIN. After entry, the app *encrypts* it and saves it in the shared_prefs directory.
1. It shouldn't be encrypted at all - that's a really poor design.…
During setup, the app asks you to create a PIN. After entry, the app *encrypts* it and saves it in the shared_prefs directory.
1. It shouldn't be encrypted at all - that's a really poor design.…
Bram Kanstein / @bramk:
RT by @bramk: We went from watching the stars to watching seconds, then we wonder why everyone’s anxious.
@LanternBitcoin connects mechanical time keeping, fiat money, and attention spans, and loss of meaning in a way that felt uncomfortably accurate.
Deep 🔥 episode live @ 12PM EST 👇
RT by @bramk: We went from watching the stars to watching seconds, then we wonder why everyone’s anxious.
@LanternBitcoin connects mechanical time keeping, fiat money, and attention spans, and loss of meaning in a way that felt uncomfortably accurate.
Deep 🔥 episode live @ 12PM EST 👇
stacker news ~bitcoin:
Bitcoin Math Puzzle #002: Selfish Mining Pt. 2
Bitcoin Math Puzzle #002: Selfish Mining Pt. 2
Stacker News
Bitcoin Math Puzzle #002: Selfish Mining Pt. 2 \ stacker news
There are two miners, Alice and Bob. Bob is an honest miner and always mines on the public (longest) chain. Alice is a potentially honest, potentially selfish miner who can decide to mine on the public chain, or to secretly work on a private chain, only to…
stacker news ~bitcoin:
ZEUS v13.0.0 Highlights
ZEUS v13.0.0 Highlights