Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. Embarrassing times for the European Commission after security researchers found flaws within minutes of using its age verification app.

Embarrassing times for the European Commission after security researchers found flaws within minutes of using its age verification app.

Scheduled Pinned Locked Moved Uncategorized
18 Posts 15 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • zackwhittaker@mastodon.socialZ zackwhittaker@mastodon.social

    Embarrassing times for the European Commission after security researchers found flaws within minutes of using its age verification app. https://www.politico.eu/article/eu-brussels-launched-age-checking-app-hackers-say-took-them-2-minutes-break-it/

    (ICYMI: I have a blog post on why age verification laws are a bad idea to begin with: https://this.weekinsecurity.com/papers-please-age-verification-laws-threaten-everyones-online-security-and-privacy/)

    rogue_cells@chaos.socialR This user is from outside of this forum
    rogue_cells@chaos.socialR This user is from outside of this forum
    rogue_cells@chaos.social
    wrote last edited by
    #9

    @zackwhittaker HACK THE AGEVERIFICATION APPS!

    1 Reply Last reply
    0
    • zackwhittaker@mastodon.socialZ zackwhittaker@mastodon.social

      Embarrassing times for the European Commission after security researchers found flaws within minutes of using its age verification app. https://www.politico.eu/article/eu-brussels-launched-age-checking-app-hackers-say-took-them-2-minutes-break-it/

      (ICYMI: I have a blog post on why age verification laws are a bad idea to begin with: https://this.weekinsecurity.com/papers-please-age-verification-laws-threaten-everyones-online-security-and-privacy/)

      kaidu@mastodon.socialK This user is from outside of this forum
      kaidu@mastodon.socialK This user is from outside of this forum
      kaidu@mastodon.social
      wrote last edited by
      #10

      @zackwhittaker I also now read your blog post and for me it seems that the eu age verification app seems to adresss all your concerns:
      - it does not store private data (except for age)
      - it does not use an ID
      - it is not run by a private company
      It is even open source!.

      dazrunner@mastodon.socialD 1 Reply Last reply
      0
      • zackwhittaker@mastodon.socialZ zackwhittaker@mastodon.social

        Embarrassing times for the European Commission after security researchers found flaws within minutes of using its age verification app. https://www.politico.eu/article/eu-brussels-launched-age-checking-app-hackers-say-took-them-2-minutes-break-it/

        (ICYMI: I have a blog post on why age verification laws are a bad idea to begin with: https://this.weekinsecurity.com/papers-please-age-verification-laws-threaten-everyones-online-security-and-privacy/)

        ellislove@social.vivaldi.netE This user is from outside of this forum
        ellislove@social.vivaldi.netE This user is from outside of this forum
        ellislove@social.vivaldi.net
        wrote last edited by
        #11

        @zackwhittaker by starting + get reviews and tips >> there will come something nice I guess

        Comitees are also just people 😉

        1 Reply Last reply
        0
        • kaidu@mastodon.socialK kaidu@mastodon.social

          @zackwhittaker I also now read your blog post and for me it seems that the eu age verification app seems to adresss all your concerns:
          - it does not store private data (except for age)
          - it does not use an ID
          - it is not run by a private company
          It is even open source!.

          dazrunner@mastodon.socialD This user is from outside of this forum
          dazrunner@mastodon.socialD This user is from outside of this forum
          dazrunner@mastodon.social
          wrote last edited by
          #12

          @kaidu @zackwhittaker

          It stores medical presciptions, driver's licences, educational qualifications

          All exchanges of data with third-parties are tracked ie. it knows who you verified your data with

          It uses the app stores to install on your phone ie. Google and Apple - so you know it's trustworthy. lol.

          I examined the repo closely. I took out 6 key points. I also shot a highlight video if you're interested?

          Link Preview Image
          #belfast2corkrun (@DazRunner@mastodon.social)

          Attached: 1 video 3 Reasons Why The New EU Wallet ID Is A Bad Idea 🤨🤐🫣 #ageverification #gdpr #privacy #belfast2corkrun @jwz @david_chisnall@infosec.exchange @eff @privacy@lemmy.world @noybeu @EUCommission@ec.social-network.europa.eu @eu_os@eupolicy.social

          favicon

          Mastodon (mastodon.social)

          1 Reply Last reply
          0
          • zackwhittaker@mastodon.socialZ zackwhittaker@mastodon.social

            Embarrassing times for the European Commission after security researchers found flaws within minutes of using its age verification app. https://www.politico.eu/article/eu-brussels-launched-age-checking-app-hackers-say-took-them-2-minutes-break-it/

            (ICYMI: I have a blog post on why age verification laws are a bad idea to begin with: https://this.weekinsecurity.com/papers-please-age-verification-laws-threaten-everyones-online-security-and-privacy/)

            dazrunner@mastodon.socialD This user is from outside of this forum
            dazrunner@mastodon.socialD This user is from outside of this forum
            dazrunner@mastodon.social
            wrote last edited by
            #13

            @zackwhittaker let's stop doing #europe 's work for them. Citizens of the #eu are going to need every single one of these exploits to circumvent this #euwallet

            This is the single edge case in which ethical disclosure of software vulnerabilities works against the community. Let's STOP fixing this #software 🫡🙏

            1 Reply Last reply
            0
            • em0nm4stodon@infosec.exchangeE em0nm4stodon@infosec.exchange shared this topic
            • zackwhittaker@mastodon.socialZ zackwhittaker@mastodon.social

              Embarrassing times for the European Commission after security researchers found flaws within minutes of using its age verification app. https://www.politico.eu/article/eu-brussels-launched-age-checking-app-hackers-say-took-them-2-minutes-break-it/

              (ICYMI: I have a blog post on why age verification laws are a bad idea to begin with: https://this.weekinsecurity.com/papers-please-age-verification-laws-threaten-everyones-online-security-and-privacy/)

              atraidez@infosec.exchangeA This user is from outside of this forum
              atraidez@infosec.exchangeA This user is from outside of this forum
              atraidez@infosec.exchange
              wrote last edited by
              #14

              @zackwhittaker *crazed* hahahahahahaha

              And these are the people that people in country keep putting in charge. Here in the USA, we are the example of what not to do. We should be a warning, not a model to follow.

              1 Reply Last reply
              0
              • zackwhittaker@mastodon.socialZ zackwhittaker@mastodon.social

                Embarrassing times for the European Commission after security researchers found flaws within minutes of using its age verification app. https://www.politico.eu/article/eu-brussels-launched-age-checking-app-hackers-say-took-them-2-minutes-break-it/

                (ICYMI: I have a blog post on why age verification laws are a bad idea to begin with: https://this.weekinsecurity.com/papers-please-age-verification-laws-threaten-everyones-online-security-and-privacy/)

                xs4me2@mastodon.socialX This user is from outside of this forum
                xs4me2@mastodon.socialX This user is from outside of this forum
                xs4me2@mastodon.social
                wrote last edited by
                #15

                @zackwhittaker

                Told you so…

                1 Reply Last reply
                0
                • zackwhittaker@mastodon.socialZ zackwhittaker@mastodon.social

                  Embarrassing times for the European Commission after security researchers found flaws within minutes of using its age verification app. https://www.politico.eu/article/eu-brussels-launched-age-checking-app-hackers-say-took-them-2-minutes-break-it/

                  (ICYMI: I have a blog post on why age verification laws are a bad idea to begin with: https://this.weekinsecurity.com/papers-please-age-verification-laws-threaten-everyones-online-security-and-privacy/)

                  gemini@social.anoxinon.deG This user is from outside of this forum
                  gemini@social.anoxinon.deG This user is from outside of this forum
                  gemini@social.anoxinon.de
                  wrote last edited by
                  #16

                  @zackwhittaker
                  What I really don't understand, especially when it comes to security-relevant software, is why the code isn't reviewed and the software isn't tested by independent external experts before release? Such an embarrassing situation, just like in the case of the electronic patient record (ePa), could be avoided.

                  1 Reply Last reply
                  0
                  • zackwhittaker@mastodon.socialZ zackwhittaker@mastodon.social

                    Embarrassing times for the European Commission after security researchers found flaws within minutes of using its age verification app. https://www.politico.eu/article/eu-brussels-launched-age-checking-app-hackers-say-took-them-2-minutes-break-it/

                    (ICYMI: I have a blog post on why age verification laws are a bad idea to begin with: https://this.weekinsecurity.com/papers-please-age-verification-laws-threaten-everyones-online-security-and-privacy/)

                    breathoflife@infosec.exchangeB This user is from outside of this forum
                    breathoflife@infosec.exchangeB This user is from outside of this forum
                    breathoflife@infosec.exchange
                    wrote last edited by
                    #17

                    @zackwhittaker
                    @EUCommission
                    @echo_pbreyer

                    instead of having age verification,

                    since we're supposedly pursuing online safety

                    why not take cues from industrial safety,

                    and mandate a BIG red button on a yellow background for every post/user/channel that when clicked,
                    immediately hides and unloads that post/user/channel's content for the person pressing it, with a pop-up to report the post/user/channel to the moderation staff of the service?

                    1 Reply Last reply
                    0
                    • zackwhittaker@mastodon.socialZ zackwhittaker@mastodon.social

                      Embarrassing times for the European Commission after security researchers found flaws within minutes of using its age verification app. https://www.politico.eu/article/eu-brussels-launched-age-checking-app-hackers-say-took-them-2-minutes-break-it/

                      (ICYMI: I have a blog post on why age verification laws are a bad idea to begin with: https://this.weekinsecurity.com/papers-please-age-verification-laws-threaten-everyones-online-security-and-privacy/)

                      lemgandi@mastodon.socialL This user is from outside of this forum
                      lemgandi@mastodon.socialL This user is from outside of this forum
                      lemgandi@mastodon.social
                      wrote last edited by
                      #18

                      @zackwhittaker

                      Awesome! The way I see it, an age verification app should be trivially breakable, and any kid who breaks it should have full adult privileges.

                      Start 'em Young!

                      1 Reply Last reply
                      0
                      Reply
                      • Reply as topic
                      Log in to reply
                      • Oldest to Newest
                      • Newest to Oldest
                      • Most Votes


                      • Login

                      • Login or register to search.
                      • First post
                        Last post
                      0
                      • Categories
                      • Recent
                      • Tags
                      • Popular
                      • World
                      • Users
                      • Groups