mastouille.fr est l'un des nombreux serveurs Mastodon indépendants que vous pouvez utiliser pour participer au fédiverse.
Mastouille est une instance Mastodon durable, ouverte, et hébergée en France.

Administré par :

Statistiques du serveur :

596
comptes actifs

#ignorant

0 message0 participant0 message aujourd’hui
A répondu dans un fil de discussion

@ilumium @GrapheneOS @article19 When I asked #Google a follow-up question using Google's own terminology, like #PlayIntegrity #GMS etc. their team of three competition lawyers brushed it aside saying they didn't understand the acronyms. They did not let me clarify. This is a classic example of the Google lawyers being conveniently #ignorant of the key details of things the Google Play team does that nicely props up their monopoly.

Suite du fil

McKennie has previously criticised #Trump. Speaking in June 2020, in the wake of the #BlackLivesMatter #Protests during his first term, McKennie told German media outlet Bild: “I don’t think that Trump is the right one for the job as the president. I stand by these words. I believe he doesn’t understand the responsibility he has for the entire country. I think he’s #ignorant. I don’t support him a bit. I don’t think he’s a man to stand by his word. In my eyes, you can call him #racist.”

A répondu dans un fil de discussion

@pixelpusher220

the pridefully #ignorant ones will endlessly blame shift away from their own #entitled #privileged indolence

the question is do they outnumber the ones who can have their eyes opened via the suffering they bring onto us by not #voting/ voting for #bigoted #plutocrat #malice

some have the bare minimum of heart to go "i was wrong"

if they are not enough? too late?

then we are truly fucked

#maga #voters, #nonvoters: i absolutely despise you

A répondu dans un fil de discussion

@kwleslie

our world is founded on

"why it's important to #vaccinate"

"why it's important to #vote"

"why it's important to have #friends and #allies"

etc

and people not born of the #suffering that created these lessons, and proudly #ignorant of #history, don't know, don't care, and amazingly, *organize* on this willful ugliness

oh, they will learn

again

the hard way

and those of us who already know why these things are important will suffer as well, dragged along by the evil and stupid

A répondu dans un fil de discussion

@jpsachse : or when your account gets pwned and the attacker does a better job proving that they are you than you - after all, *they* have access to your account - while you do not.

🔸 ANDROID PASSKEY BLACK HOLE
*Or* when you press a button "Clear data" (at the bottom of chrome.google.com/sync) which is accompanied by the text:

« This will clear your Chrome data that has been saved in your Google Account. This might clear some data from your devices. »

For you to subsequently find out that ALL OF YOUR PASSKEYS on (all of) your Android device(s) are IRRETRIEVABLE GONE (I reported this to Google in June 2023 and published it 6 months later in
seclists.org/fulldisclosure/20). It's still unfixed.

🔸 WHY NO EXPORT AND NO BACKUP
W.r.t. being able to export and/or backup all private keys belonging to all of your passkeys: that's a big dilemma (depending on your POV).

The main (advertised, not taking into account a possibly desired vendor lock-in) reason is simple: if *you* have direct access to such private keys, *malware* running on your device does too.

The compromise is that they are automatically synced to your cloud account, and from there to other devices (of the same brand, provided they run an OS version that's not too old), including a new device if you brick or lose your old device.

However, if there's serious malware on your device, then, even if the malware authors cannot steal all of your passkeys (that is, their private keys), then you're toast anyway; a RAT such as AnyDesk may fool you into believing that you're logging in to website A while in fact it's B and they steal it's session cookie - and pwn the webaccount.

🔸 SYNCING PRIVATE KEYS
BTW it's hardly being discussed, but being able to synchronize secrets between secure hardware enclaves in such a way that *you* are denied access, is quite an achievement (considering that, if you buy a new phone, the only available secrets to the transport system are your definitely weak passcode, and your, potentially weak, cloud password that may be used to encrypt the private keys in transit).

I *know* that it's complicated because I accidentally found out around June 2023 that Android can get confused: passkeys *seem* to sync just fine, but passkeys created on phone 1 do not work on phone 2 and vice versa. Somehow the phones had started using *different* encryption keys used to securily synchronize them (I also mentioned that issue in my reports to Google in the summer of 2023, and I mention it in the FD (seclists.org) message).

I don't know how Apple syncs secrets in iCloud keychain, and neither whether a situation may exist where passkey's private keys sync but are unusable (like may happen when using Android).

🔸 APPLE'S OWN PASSKEY MISERY
However, Apple has got their own bunch of problems with passkeys being usable *without* requiring biometrics or a passcode to unlock them from iCloud Keychain, see infosec.exchange/@ErikvanStrat and follow-up (it gets worse every time I look at it) infosec.exchange/@ErikvanStrat (more details in earlier toots in that thread).

In short: if you don't use biometrics to unlock your iPhone or iPad (OR you do, but you have -unlikely- disabled a specific configuration setting), then anyone with access to your iDevice in an unlocked condition (*), can sign in to:
appleid.apple.com
and/or
icloud.com
WITHOUT entering your passcode (or using biometrics).

(*) your child, spouse, someone you don't know (well) who borrows your phone to make a call (because their's battery is dead), NOTABLY including a thief who stole it while you were using it (or saw you type your passcode and can unlock it by themselves: youtu.be/QUYODQB_2wQ).

I'm not sure yet, but this may even render Apple's anti-theft system totally moot.

@rmondello @johnbrayton
@agl

myaccount.google.comParamètres du compte : votre navigateur n'est pas compatible
A répondu dans un fil de discussion

🌊Please boost, create awareness!🌊

@webhat wrote: « passwordless works using biometrics to unlock the trusted key store »

It *may* require biometrics, or it may not.

🤳 For example: on my iPhone, if I REMOVE my stored fingerprint data, then:

🔒 I'll *always* have to enter my *passcode* (screen unlock password) when I *CREATE* a new passkey, on any website that supports passkeys;

🚨 HOWEVER: I *NEVER* have to enter my passcode (or I can bypass any request) when *USING* a passkey to *LOG IN* on to at least the following websites:
idmsa.apple.com
webauthn.io
passkeys-demo.appspot.com
passkeys.io
webauthn-conditional-ui-demo.g

🚨 Similarly, I *always* have to enter my passcode when I *add* a password-based-credentials-record to iCloud Keychain, but *never* when i ask iCloud Keychain to autofill such credentials to log in to *any* website.

💣How is this NOT a vulnerability?💣

🔧 Note that I've not found *any* configuration setting that (when *not* having configured and using biometrics at all) would force me to *always* authenticate locally to have iCloud Keychain autofill credentials in order to log in to a website.

🔓 This is 0FA if someone, who you do not fully trust (e.g. a thief), has or obtains access to your unlocked iPhone or iPad.

💥 IMO this is a huge risk, particular after a miscreant observes you entering your passcode and then steals your iDevice, such as clearly visualized by Joanna Stern (of the Wall Street Journal) in youtu.be/QUYODQB_2wQ (follow-up: youtu.be/tCfb9Wizq9Q). It is a GAPING SECURITY HOLE because most users, in particular those who do NOT use biometrics (many elderly people), are not aware of the risks.

😱 And IMO it's *unbelievable* that Apple denies that this is a vulnerability (note that more than one vulnerability may be involved).

🔑 @rmondello : see security.apple.com/reports/OE1 for details.

⁉️ What else can I do to bring this to people's attention? Please complain to Apple that they insufficiently protect unaware iDevice users!

idmsa.apple.comMy AppleID