Video wird geladen...

Video konnte nicht geladen werden

Zur Startseite

Bypassing #EU #AgeVerification using their own infrastructure. I've ported the Android app logic to a Chrome extension - stripping out the pesky step of handing over biometric data which they can leak... and pass verification instantly. Step 1: Install the extension Step 2: Register an identity (just once) Step...

1,182,258 Aufrufe • vor 5 Monaten •via X (Twitter)

46 Kommentare

Profilbild von beep boop
beep boopvor 5 Monaten

this is the core problem with ALL age verification bullshit its either trackable or its easily spoofable with no way of knowing

Profilbild von Paul Moore - Security Consultant 
Paul Moore - Security Consultant vor 5 Monaten

Bingo.

Profilbild von artur
arturvor 5 Monaten

i just found out about you, and i really love this rabbit hole lmao. appreciate your work a lot

Profilbild von Paul Moore - Security Consultant 
Paul Moore - Security Consultant vor 5 Monaten

Appreciate that, thank you!

Profilbild von Lilith Wittmann
Lilith Wittmannvor 5 Monaten

Yeah thats the issue I documented 5 months ago. The annoying thing will be that you need to find an implementation to extract the private keys from every 3 months.

Profilbild von Vi iD
Vi iDvor 5 Monaten

So this is essentially less effective than simple "Are you over 18" popup.

Profilbild von Louis Thibault
Louis Thibaultvor 5 Monaten

I don't think we should be helping the EU harden this system. I wish security researchers would just refuse to touch it.

Profilbild von Paul Moore - Security Consultant 
Paul Moore - Security Consultant vor 5 Monaten

Double-edged sword Louis. I'm with you; I don't want to help build a surveillance state. But, it's coming regardless... and issues like these expose users to real-world risk. Better to expose them while there's minimal risk. I can tackle the bugs; the legislation is way beyond me.

Profilbild von Louis Thibault
Louis Thibaultvor 5 Monaten

>But, it's coming regardless Well yeah, if you help build it, it certainly is. >and issues like these expose users to real-world risk Yeah, which might get the EU to back down. >Better to expose them while there's minimal risk. You've just swapped out one risk for another.

Profilbild von Louis Thibault
Louis Thibaultvor 5 Monaten

Let me be clear: people getting hurt by this system *visibly and immediately* is the best possible outcome.

Profilbild von Gingembre
Gingembrevor 5 Monaten

@Paul_Reviews Thank you

Profilbild von Louis Thibault
Louis Thibaultvor 5 Monaten

@Paul_Reviews I'm too autistic to let it slide🫡

Profilbild von LE COLLECTIF 🅻🅴 🅲🅾🅻🅻🅴🅲🆃🅸🅵 🇫🇷
LE COLLECTIF 🅻🅴 🅲🅾🅻🅻🅴🅲🆃🅸🅵 🇫🇷vor 5 Monaten

It’s worse than amateurish – it’s a scam that must have cost the EU a fortune, and therefore us!!!!!

Profilbild von Y4ss
Y4ssvor 5 Monaten

We get the point the app is not secure. But let's not offer them more free pentesting. Strategically I would argue that it's better to let them believe their own lies (it's secure, interoperable, etc) and fail miserably when confronted with reality (bypass, black market, etc).

Profilbild von Anton Balakirev
Anton Balakirevvor 5 Monaten

curious how many millions and months did they spent on this app

Profilbild von FactIndie 🔍
FactIndie 🔍vor 5 Monaten

This is not me bookmarking this post, move along.... As an EU citizen, all I can say is: "everything is ok"

Profilbild von Rob
Robvor 5 Monaten

Why are we iron manning the government plan? Let them fail - act like it’s perfect - stop helping them see where they can tighten the noose

Profilbild von Aerendir Mobile
Aerendir Mobilevor 5 Monaten

Broken in under 2 minutes. The only fix is tying the key to your identity, which turns an age check into a surveillance system. This isn't a fixable bug. IT'S THE INEVITABLE OUTCOME OF CENTRALIZED VERIFICATION. The architecture was the decision. The flaw was guaranteed.

Profilbild von eliothaise ✝️ ܝܫܘܥ
eliothaise ✝️ ܝܫܘܥvor 5 Monaten

I'm starting to think that the obvious flaws are there by design in order to enforce worse dystopic controls down the line

Profilbild von ivan@@
ivan@@vor 5 Monaten

Keep doing this please. If u stop, people forget, and nothing changes

Profilbild von AyC
AyCvor 5 Monaten

If this shit gets leaked it will be a nuclear meltdown of privacy information.

Profilbild von O4T1S
O4T1Svor 5 Monaten

🤯🤣🤣

Profilbild von Zaphod Beebelbox
Zaphod Beebelboxvor 5 Monaten

And so the arms race begins. They will weaponize this to no end to prevent you from bypassing it, starting with arresting anyone saying or doing anything as you suggest, more technology, more integration into operating systems, force of law compliance for your ISP, your bank, your social networks... The amounts of money the EU is going to request and spend on enforcing this is going to be astronomically large and ever growing, which is exactly what they want. They are going to use your money to silence you, punish you and remove you from online civilization unless you comply with everything they tell you to do.

Profilbild von de augurkenkoning
de augurkenkoningvor 5 Monaten

is this extension opensource?

Profilbild von Paul Moore - Security Consultant 
Paul Moore - Security Consultant vor 5 Monaten

Depends if I publish it. Unlikely at the moment... but hopefully those in charge will realise this is doomed to fail.

Profilbild von de augurkenkoning
de augurkenkoningvor 5 Monaten

you should, no matter what. "the light of day is the best disinfectant"

Profilbild von IshayuG
IshayuGvor 5 Monaten

The app is a proof of concept. The whole idea is that it is tied to your personal government data. However the idea is also that it generates a zero-knowledge proof, which means that once it's signed by the authorities based on government data, you don't need to verify it with them and it doesn't contain anything except "over 18". You're using a proof of concept that isn't cryptically tied to any particular government and going "omg look I can pretend to be a government!" with it. Well duh, of course you can.

Profilbild von Strawman
Strawmanvor 5 Monaten

Maybe i'm grossly overestimating our EU overlords, but couldn't this be a way to get 'the public' to 'demand' more security and move the discussion from 'yes' or 'no' to 'how secure should it be' (talking past the sale)?

Profilbild von castform5
castform5vor 5 Monaten

Flaws in an early development demo? Unheard of! Preposterous! Has never happened on any other project's development.

Profilbild von Paul Moore - Security Consultant 
Paul Moore - Security Consultant vor 5 Monaten

President says "technically ready, check the code"... but it's a early prototype? Sorry, doesn't wash.

Profilbild von castform5
castform5vor 5 Monaten

Too bad the president is just a spokesperson and not actually involved in the project. Any CEO will say their product is technically ready the moment they get it running on a single system too.

Profilbild von Jarvis
Jarvisvor 5 Monaten

“Jarvis, activate the goyim control protocol. Make no mistakes”

Profilbild von Smarkie
Smarkievor 5 Monaten

Tbqh the extension with a non real id would be the best approach to mess with the cockroaches fascimoves

Profilbild von Lou Greenwood
Lou Greenwoodvor 5 Monaten

As long as you promise to always be over 18, the system is working very well 🫣

Profilbild von Jan 🌍🍣🍵😎🖖🦌🌲🍃🍍🏝️
Jan 🌍🍣🍵😎🖖🦌🌲🍃🍍🏝️vor 5 Monaten

Do you have the source code somewhere? Happy to create an Open Source port for Safari on iPhone, iPad and macOS.

Profilbild von Tim the Libertarian
Tim the Libertarianvor 5 Monaten

Not all heroes wear capes!

Profilbild von Thomas
Thomasvor 5 Monaten

“Hackers & p*dos have found an unpatchable flaw in the system, we must PROTECT THE KIDS” –> tracking and monitoring.

Profilbild von Merlin M
Merlin Mvor 5 Monaten

extremely disturbing "This isn't a bug... it's a fundamental design flaw they can't solve without irrevocably tying a key to you personally; which then allows tracking/monitoring"

Profilbild von Detlef C.
Detlef C.vor 5 Monaten

That's 4 million euro and half a year of bureaucratic software development down the drain in less than 48 hours. They might want to learn from this, next time they overstep their role.

Profilbild von Maanvis 🇳🇱 🍅
Maanvis 🇳🇱 🍅vor 5 Monaten

Hahaha Von der Leyen and the EU look like complete fools. Good job Paul

Profilbild von Quentin
Quentinvor 5 Monaten

So you manage to hack and bypass a thing made by EU chosen "expert" (i suppose) in less than a week... at this point the whole thing is an absolute joke in every regard.

Profilbild von Smarkie
Smarkievor 5 Monaten

Paul by any chance do you know who did the app for the stasi, i mean CE?

Profilbild von Secrets of Privacy | Make Yourself a Harder Target
Secrets of Privacy | Make Yourself a Harder Targetvor 5 Monaten

Where there's a will there's a way.

Profilbild von British Adventure News 🇬🇧
British Adventure News 🇬🇧vor 5 Monaten

Great work! Does your extension work in Brave?

Profilbild von o/
o/vor 5 Monaten

Side note: is it possible to port that to, let's say a DNS server like pi-hole and then let it handle all requests automatically? Asking for a friend of course...

Profilbild von arbadacarba 🐈‍⬛🏴‍☠️
arbadacarba 🐈‍⬛🏴‍☠️vor 5 Monaten

Zeit, euch die Verantwortliche dafür mal vorzustellen

Ähnliche Videos