Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. Scan your passport to join our social network.

Scan your passport to join our social network.

Scheduled Pinned Locked Moved Uncategorized
europesocialnetworkidentityverific
85 Posts 44 Posters 78 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • causeofbsod@wetdry.worldC causeofbsod@wetdry.world

    @EregLoch @aral @lain@lain.com if the verification is entirely on-device then it is likely trivial to spoof with some work in ghidra.

    rule 1 of computer security: the client is untrustworthy

    causeofbsod@wetdry.worldC This user is from outside of this forum
    causeofbsod@wetdry.worldC This user is from outside of this forum
    causeofbsod@wetdry.world
    wrote last edited by
    #50

    @EregLoch @aral this is of course assuming they arent just lying and doing the verification remotely anyway

    1 Reply Last reply
    0
    • hsza@social.tudbut.deH hsza@social.tudbut.de

      @vonKordke @lain @aral you know who this response paints you as? A geniune Nazi

      Only fascists whine “oh you call everyone a fascist” when called out as what they are

      vonkordke@social.vivaldi.netV This user is from outside of this forum
      vonkordke@social.vivaldi.netV This user is from outside of this forum
      vonkordke@social.vivaldi.net
      wrote last edited by
      #51

      @hsza @lain @aral
      Do you care what monkeys screams when you go near their cage in the zoo? Me neither

      hsza@social.tudbut.deH 1 Reply Last reply
      0
      • goog@gabboman.xyzG goog@gabboman.xyz

        @aral@mastodon.ar.al @mynameistillian@plush.city

        to any dumbass reporting this post, a simple google search would have spared you the effort of reporting what's a known meme on the polish side of internet

        Link Preview Image
        Kamil Tumulec – Wikipedia, wolna encyklopedia

        favicon

        (pl.wikipedia.org)

        go care about actual doxxing that happens on your very own cesspool instead of getting mad over a photo of an ID that might as well never really exist

        crv@akkoma.kruhlovo.xyzC This user is from outside of this forum
        crv@akkoma.kruhlovo.xyzC This user is from outside of this forum
        crv@akkoma.kruhlovo.xyz
        wrote last edited by
        #52
        @goog @aral @mynameistillian report za tumulca 🥀
        goog@gabboman.xyzG 1 Reply Last reply
        0
        • eregloch@mastodon.coffeeE eregloch@mastodon.coffee

          @aral

          @lain
          Since I read the info on the verification process, supposedly fully on device, and user name options (real or something else) for now I tend to give it the benefit of doubt. It might even reduce malicious fake accounts.

          frawst@fedi.fraw.stF This user is from outside of this forum
          frawst@fedi.fraw.stF This user is from outside of this forum
          frawst@fedi.fraw.st
          wrote last edited by
          #53

          @EregLoch@mastodon.coffee @aral@mastodon.ar.al @lain@lain.com if the verification is truly fully on device, then in theory someone can just spoof the results that get sent back to the server and pretend theyre a real person, which completely defeats the point

          the only way ID verification truly works is when there is some external server doing the verification, which of course has its own even worse problems

          there is no way to make ID verification both private and trustworthy, the two are fundamentally interlinked, so theres no point even entertaining the idea either way

          1 Reply Last reply
          0
          • vonkordke@social.vivaldi.netV vonkordke@social.vivaldi.net

            @hsza @lain @aral
            Do you care what monkeys screams when you go near their cage in the zoo? Me neither

            hsza@social.tudbut.deH This user is from outside of this forum
            hsza@social.tudbut.deH This user is from outside of this forum
            hsza@social.tudbut.de
            wrote last edited by
            #54

            @vonKordke @lain @aral pspspspspspsps monkey

            hsza@social.tudbut.deH 1 Reply Last reply
            0
            • hsza@social.tudbut.deH hsza@social.tudbut.de

              @vonKordke @lain @aral pspspspspspsps monkey

              hsza@social.tudbut.deH This user is from outside of this forum
              hsza@social.tudbut.deH This user is from outside of this forum
              hsza@social.tudbut.de
              wrote last edited by
              #55

              @vonKordke @aral @lain thats right i dont actually care youve proven you’re not worth listening to heh

              just trolling for the entertainment value now

              vonkordke@social.vivaldi.netV khaleer@mastodon.gamedev.placeK 2 Replies Last reply
              0
              • hsza@social.tudbut.deH hsza@social.tudbut.de

                @vonKordke @aral @lain thats right i dont actually care youve proven you’re not worth listening to heh

                just trolling for the entertainment value now

                vonkordke@social.vivaldi.netV This user is from outside of this forum
                vonkordke@social.vivaldi.netV This user is from outside of this forum
                vonkordke@social.vivaldi.net
                wrote last edited by
                #56

                @hsza @lain @aral

                Not "not worth listening". You just can't understand nor accept different opinions. But that's fine. Not everybody can be open minded.

                1 Reply Last reply
                0
                • aral@mastodon.ar.alA aral@mastodon.ar.al

                  Scan your passport to join our social network.

                  Don’t worry, it’s European.

                  Needless to say, unless you’re a complete and utter fool, do not join W and warn your friends not to join W either.

                  #EU #europe #W #socialNetwork #identityVerification #surveillance #privacy #humanRights #democracy #data @lain https://lain.com/objects/aaa7d9d6-331b-4a59-aeda-b2badafc15c3

                  kierkegaanks@beige.partyK This user is from outside of this forum
                  kierkegaanks@beige.partyK This user is from outside of this forum
                  kierkegaanks@beige.party
                  wrote last edited by
                  #57

                  @aral @lain@lain.com as it was said: mr gorbachev, tear that bullshit down

                  1 Reply Last reply
                  0
                  • aral@mastodon.ar.alA aral@mastodon.ar.al

                    Scan your passport to join our social network.

                    Don’t worry, it’s European.

                    Needless to say, unless you’re a complete and utter fool, do not join W and warn your friends not to join W either.

                    #EU #europe #W #socialNetwork #identityVerification #surveillance #privacy #humanRights #democracy #data @lain https://lain.com/objects/aaa7d9d6-331b-4a59-aeda-b2badafc15c3

                    daliarezk@mastodon.socialD This user is from outside of this forum
                    daliarezk@mastodon.socialD This user is from outside of this forum
                    daliarezk@mastodon.social
                    wrote last edited by
                    #58

                    @aral @lain 😂😂I don't have a passport

                    1 Reply Last reply
                    0
                    • crv@akkoma.kruhlovo.xyzC crv@akkoma.kruhlovo.xyz
                      @goog @aral @mynameistillian report za tumulca 🥀
                      goog@gabboman.xyzG This user is from outside of this forum
                      goog@gabboman.xyzG This user is from outside of this forum
                      goog@gabboman.xyz
                      wrote last edited by
                      #59

                      @crv@akkoma.kruhlovo.xyz @aral@mastodon.ar.al @mynameistillian@plush.city

                      tylko na fedi takie kwiatki

                      crv@akkoma.kruhlovo.xyzC 1 Reply Last reply
                      0
                      • goog@gabboman.xyzG goog@gabboman.xyz

                        @crv@akkoma.kruhlovo.xyz @aral@mastodon.ar.al @mynameistillian@plush.city

                        tylko na fedi takie kwiatki

                        crv@akkoma.kruhlovo.xyzC This user is from outside of this forum
                        crv@akkoma.kruhlovo.xyzC This user is from outside of this forum
                        crv@akkoma.kruhlovo.xyz
                        wrote last edited by
                        #60
                        @goog @aral @mynameistillian tumuLec fedi meta
                        1 Reply Last reply
                        0
                        • aral@mastodon.ar.alA aral@mastodon.ar.al

                          Scan your passport to join our social network.

                          Don’t worry, it’s European.

                          Needless to say, unless you’re a complete and utter fool, do not join W and warn your friends not to join W either.

                          #EU #europe #W #socialNetwork #identityVerification #surveillance #privacy #humanRights #democracy #data @lain https://lain.com/objects/aaa7d9d6-331b-4a59-aeda-b2badafc15c3

                          freci@piaille.frF This user is from outside of this forum
                          freci@piaille.frF This user is from outside of this forum
                          freci@piaille.fr
                          wrote last edited by
                          #61

                          @aral on a somewhat related note LinkedIn wants me to upload my ID to be able to close my account because I do not agree with uploading my ID to continue to use it… and you need an unblocked account to contact the DPO to exercise your rights which implies… uploading the ID. Kind of a catch-22

                          timwardcam@c.imT blogdiva@mastodon.socialB holdenweb@freeradical.zoneH bard@asphodel.ripB freci@piaille.frF 5 Replies Last reply
                          0
                          • causeofbsod@wetdry.worldC causeofbsod@wetdry.world

                            @EregLoch @aral @lain@lain.com if the verification is entirely on-device then it is likely trivial to spoof with some work in ghidra.

                            rule 1 of computer security: the client is untrustworthy

                            eregloch@mastodon.coffeeE This user is from outside of this forum
                            eregloch@mastodon.coffeeE This user is from outside of this forum
                            eregloch@mastodon.coffee
                            wrote last edited by
                            #62

                            @CauseOfBSOD

                            @aral
                            You are missing rule 2: the server is untrustworthy. In networking any system can be malignant or hacked and become malignant. Assuming otherwise is failure in the waiting.

                            (Rule 3: use open source and invite the world to find vulnerabilities)

                            causeofbsod@wetdry.worldC 1 Reply Last reply
                            0
                            • aral@mastodon.ar.alA aral@mastodon.ar.al

                              Scan your passport to join our social network.

                              Don’t worry, it’s European.

                              Needless to say, unless you’re a complete and utter fool, do not join W and warn your friends not to join W either.

                              #EU #europe #W #socialNetwork #identityVerification #surveillance #privacy #humanRights #democracy #data @lain https://lain.com/objects/aaa7d9d6-331b-4a59-aeda-b2badafc15c3

                              loremipsum@fedia.socialL This user is from outside of this forum
                              loremipsum@fedia.socialL This user is from outside of this forum
                              loremipsum@fedia.social
                              wrote last edited by
                              #63

                              @aral @lain Lsocial lol

                              1 Reply Last reply
                              0
                              • aral@mastodon.ar.alA aral@mastodon.ar.al

                                Scan your passport to join our social network.

                                Don’t worry, it’s European.

                                Needless to say, unless you’re a complete and utter fool, do not join W and warn your friends not to join W either.

                                #EU #europe #W #socialNetwork #identityVerification #surveillance #privacy #humanRights #democracy #data @lain https://lain.com/objects/aaa7d9d6-331b-4a59-aeda-b2badafc15c3

                                H This user is from outside of this forum
                                H This user is from outside of this forum
                                hannes99@mastodon.social
                                wrote last edited by
                                #64

                                @aral thank you for speaking up! Also see @_elena's post: https://mastodon.social/@_elena/116537351402947996

                                @lain

                                1 Reply Last reply
                                0
                                • eregloch@mastodon.coffeeE eregloch@mastodon.coffee

                                  @CauseOfBSOD

                                  @aral
                                  You are missing rule 2: the server is untrustworthy. In networking any system can be malignant or hacked and become malignant. Assuming otherwise is failure in the waiting.

                                  (Rule 3: use open source and invite the world to find vulnerabilities)

                                  causeofbsod@wetdry.worldC This user is from outside of this forum
                                  causeofbsod@wetdry.worldC This user is from outside of this forum
                                  causeofbsod@wetdry.world
                                  wrote last edited by
                                  #65

                                  @EregLoch @aral seems i need to make my argument explicit as youve clearly misunderstood

                                  We know that the client is not guaranteed to be trustworthy from the perspective of the server. We assume that the identity verification is done on the client only as stated. Per this assumption that means that the result of the verification is sent back as some form of yes/no (coupled with a name to be matched on the server, in case of success) or similar, without any other data that would allow the verification to be repeated on the server being sent back. As the client may be untrustworthy, it may manipulate the verification process or just send back modified data from a recorded successful verification with the attackers preferred values. Therefore, we can conclude that it is trivially possible to create fake accounts unless the assumption is false.

                                  Whether or not the server is trustworthy is irrelevant to this attack.

                                  causeofbsod@wetdry.worldC 1 Reply Last reply
                                  0
                                  • causeofbsod@wetdry.worldC causeofbsod@wetdry.world

                                    @EregLoch @aral seems i need to make my argument explicit as youve clearly misunderstood

                                    We know that the client is not guaranteed to be trustworthy from the perspective of the server. We assume that the identity verification is done on the client only as stated. Per this assumption that means that the result of the verification is sent back as some form of yes/no (coupled with a name to be matched on the server, in case of success) or similar, without any other data that would allow the verification to be repeated on the server being sent back. As the client may be untrustworthy, it may manipulate the verification process or just send back modified data from a recorded successful verification with the attackers preferred values. Therefore, we can conclude that it is trivially possible to create fake accounts unless the assumption is false.

                                    Whether or not the server is trustworthy is irrelevant to this attack.

                                    causeofbsod@wetdry.worldC This user is from outside of this forum
                                    causeofbsod@wetdry.worldC This user is from outside of this forum
                                    causeofbsod@wetdry.world
                                    wrote last edited by
                                    #66

                                    @EregLoch If you have an actual counterargument (i.e. not another non sequitur) then now is the time to present it

                                    1 Reply Last reply
                                    0
                                    • aral@mastodon.ar.alA aral@mastodon.ar.al

                                      Scan your passport to join our social network.

                                      Don’t worry, it’s European.

                                      Needless to say, unless you’re a complete and utter fool, do not join W and warn your friends not to join W either.

                                      #EU #europe #W #socialNetwork #identityVerification #surveillance #privacy #humanRights #democracy #data @lain https://lain.com/objects/aaa7d9d6-331b-4a59-aeda-b2badafc15c3

                                      shadowdancer@mstdn.socialS This user is from outside of this forum
                                      shadowdancer@mstdn.socialS This user is from outside of this forum
                                      shadowdancer@mstdn.social
                                      wrote last edited by
                                      #67

                                      @aral
                                      Look. No matter who's running it, or where it's hosted, if it's run for profit, you're the product. It's as simple as that.
                                      Just stay the fuck away from it.
                                      @lain

                                      1 Reply Last reply
                                      0
                                      • freci@piaille.frF freci@piaille.fr

                                        @aral on a somewhat related note LinkedIn wants me to upload my ID to be able to close my account because I do not agree with uploading my ID to continue to use it… and you need an unblocked account to contact the DPO to exercise your rights which implies… uploading the ID. Kind of a catch-22

                                        timwardcam@c.imT This user is from outside of this forum
                                        timwardcam@c.imT This user is from outside of this forum
                                        timwardcam@c.im
                                        wrote last edited by
                                        #68

                                        @freci @aral Same with Twitter. So my account there still exists but has been abandoned for some years.

                                        aral@mastodon.ar.alA 1 Reply Last reply
                                        0
                                        • freci@piaille.frF freci@piaille.fr

                                          @aral on a somewhat related note LinkedIn wants me to upload my ID to be able to close my account because I do not agree with uploading my ID to continue to use it… and you need an unblocked account to contact the DPO to exercise your rights which implies… uploading the ID. Kind of a catch-22

                                          blogdiva@mastodon.socialB This user is from outside of this forum
                                          blogdiva@mastodon.socialB This user is from outside of this forum
                                          blogdiva@mastodon.social
                                          wrote last edited by
                                          #69

                                          @freci @aral class action lawsuit. they do it on purpose because they know individuals won't sue them.

                                          1 Reply Last reply
                                          0
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Login or register to search.
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • World
                                          • Users
                                          • Groups