junior hacker, consultant, open source and open data advocate

Joined February 2020
39 Photos and videos
ngl, i don't believe i will be able to focus on the match at this point in time
🚨🇩🇪 In Germany they're watching the World Cup in another dimension. Ultra HD broadcast, on-screen minimap and even the name of the player with the ball appears in real time. Really ahead of time! 🇩🇪
57
Well I'm not the type to support a company who would obviously take 32KB of RAM for chinese gov spyware, but for god's sake this is peak engineering if it does it work like a modern system with only this much RAM
64KB of ram minimum is here Huawei has optimized HarmonyOS like never before and is currently optimized to run with as little as 128KB of ram, with plans to soon optimize it for 64KB of ram That's 64 times less than the 4MB minimum requirement of Windows 95
15
Au nom du père, du fils, et du saint whisky, amène la bouteille d'Akashi
7
The love story between Algeria and Kansas city is the most beautiful arc of the world cup up to date
44
sinjin 🇩🇿🇵🇸 retweeted
So-called age verification for social media is spreading across the world, framed as an effort to create a safer internet for children. In reality, age verification lays the foundation for a fully controlled internet. The age verification rush must be slowed down, and politicians need to recognize the consequences of different types of legislation and systems. Age verification is the wrong approach to fix “the social media problem” The big tech social media companies are bad. Their business model is bad; it is based on mass surveillance and manipulation, and they cooperate with governments in mapping entire populations. But age verification is fundamentally the wrong approach to preventing children from using big tech social media platforms. Introducing age verification is based on coercion; the state forces social media companies to verify their users’ identities. But the big tech social media platforms already know which of their users are children. Their business model depends on knowing this. They know how old users are, and they know exactly what type of person they are. As age verification is based on coercion, politicians could instead force platforms to stop doing the things politicians consider harmful to children, or force them to block children (again, they know who they are) from using their services. But instead, politicians seek to massively invade everyone’s privacy and undermine democratic rights on a global scale. In other words, the latter is the real objective – they do not want to protect children; they want to impose control. Slippery slope of age verification It is undeniable that age verification threatens freedom of expression, risks increasing mass surveillance, and is likely to lead to censorship. It will not only shrink the online world and reduce young people’s right to privacy (for example, if VPN services were to be restricted); but also risks becoming a significant step toward a controlled internet for everyone. Most age verification is identity verification Most countries are now considering introducing age verification systems, meaning that everyone would have to identify themselves either to the service/website they want to use or to a third party capable of linking them to their activity on that service or website. This is not age verification but identity verification, and the consequence is therefore that freedom of information is restricted (you can no longer visit regulated websites anonymously) and that you can no longer post anonymously on social media. This is a major problem in countries like the UK and Germany where the police conduct raids on people’s homes for posting content on social media that the authorities dislike. Or in the United States, where authorities are trying to pressure tech companies into revealing the identities behind accounts protesting ICE. Social media identity verification removes important tools for activists in countries where criticizing those in power is dangerous. Restrictions on app store or operating system level Some countries are looking to impose identity verification at the app store level or even within the operating system itself. This is an exciting experiment, since this is possible to circumvent using open-source operating systems. Some countries are already looking to include open-source systems. Since open-source systems cannot be controlled, politicians would ultimately need to ban devices that are not controlled by the state. The end point: telescreens like those in Orwell’s 1984, devices that both monitor you and broadcast only the information approved by the state. The Zero-Knowledge Proof (ZKP) alternative and the EU The EU has presented its own age verification app as “completely anonymous”. The idea is to use Zero-Knowledge Proof (ZKP) cryptography to break the link between the age credential issuer (EU governments) and the regulated services/sites. Currently, the EU app does not have ZKP functionality, contrasting Ursula von der Leyen’s claim that the app ”is technically ready to be used”. But more importantly, the app is currently designed to always function without ZKP technology; if ZKP is unavailable, the app falls back to a non-ZKP model. Even if fully developed ZKP technology could be implemented in the future, it would remain an optional extra feature that countries may choose to disable and that the EU could remove at any time. Read more on our site. mullvad.net/blog/age-verific…
74
887
3,071
70,158
sinjin 🇩🇿🇵🇸 retweeted
One of the most brutal scenes in human history has been leaked. Footage from an Israeli aircraft shows thousands of starving Palestinians running towards an aid truck, before it bombs and kills them all. A video that the world must never forget.
2,991
27,987
94,466
8,420,241
RT @TheSaviour: 🚨🇮🇱🇵🇸BREAKING: Israel committed a massacre on Gaza beach just moments ago.
8,637
sinjin 🇩🇿🇵🇸 retweeted
We’re cooked, guys. A new vulnerability has been discovered in sudo and you don’t even need to be in the sudo group to get root. I just tried it 👇
63
160
1,381
315,561
Pour l'amour du ciel, que quelqu'un déplume ce pauvre canard. L'anssi est sans doute l'agence doté des esprits les plus brillant qu'on puisse trouver en France. Il faut surtout l'impliquer de chaque processus de design et d'implémentation des système qui se font poutrer a chaque fois.
La multiplication des fuites de données devrait avoir raison de l’Anssi. Cette agence de l'Etat laisse des sites sensibles grands ouverts aux hackeurs en omettant de contrôler la plupart des organismes indispensables à l’Etat, alors que c'est sa mission ! lecanardenchaine.fr/technolo…
2
132
Microslop in all it's glory
I just reverse engineered the YellowKey BitLocker bypass Microsoft shipped code that checks for a flag called "FailRelock" in every Windows 11 recovery image. When it's set to 1, after recovery unlocks your BitLocker drive, it never relocks it. All you need is a USB stick. This code only exists in the recovery environment. Not in normal Windows. They left an entire debug testing framework in production.
32
Just remember : Don't be evil
🔴 Google refuse de corriger une faille critique d’Android 16 permettant à n’importe quelle application de contourner les VPN et d’exposer l’adresse IP réelle des utilisateurs, même avec les protections “Always-On VPN” et “Bloquer les connexions sans VPN” activées. 👉 Tous les VPN Android seraient potentiellement concernés : ProtonVPN, NordVPN, Surfshark, ExpressVPN, Mullvad et les autres fournisseurs utilisant le système VPN natif d’Android. Le plus inquiétant : Google aurait classé le signalement de la faille comme “non faisable”, tandis que GrapheneOS a déjà déployé un correctif de son côté. ➡️ Selon les chercheurs en cybersécurité, une application malveillante pourrait envoyer certains paquets réseau en dehors du tunnel VPN afin de révéler l’adresse IP réelle de la victime. Cette fuite pourrait permettre : • le suivi des utilisateurs ; • la géolocalisation réelle ; • la surveillance d’activité ; • le contournement de l’anonymat offert par les VPN.
23
sinjin 🇩🇿🇵🇸 retweeted
Apple and Google are gradually expanding their use of hardware-based attestation. They're convincing a growing number of services to adopt it. Google's Play Integrity API and Apple's App Attest API are very similar. Apple brought it to the web via Privacy Pass, which Google intends on doing too. Google's Play Integrity API requires hardware attestation for the strong integrity level and is gradually phasing in requiring it for the more commonly used device integrity level. Apple already has it as a requirement. Over the long term, this will increasingly lock out hardware and OS competition. The purpose of these systems is disallowing people from using hardware and software not approved by Apple or Google. This is wrongly presented as being a security feature. Banks and government services are the main ones adopting it but Apple and Google are encouraging every service to use it. Apple's Privacy Pass brought hardware attestation to the web to help with passing captchas on their own hardware. Many people saw that as harmless since few sites would be willing to lock out non-Apple-hardware users. Apple and Google are both likely to bring broader hardware attestation to the web. Google's reCAPTCHA is planning an approach where they use Privacy Pass on Apple hardware, their own approach on Google Mobile Services Android devices and a QR code scanning system to require an iOS or Google certified Android device for Windows and other systems: support.google.com/recaptcha… Banking and government services increasingly require using a mobile app where they can use attestation to force using an Apple or Google approved device and OS. Apple's privacy pass, Google's 'cancelled' Web Environment Integrity and now reCAPTCHA Mobile Verification are bringing this to the web. Current media coverage for reCAPTCHA Mobile Verification misunderstands it and the impact of it. They're bringing a hardware attestation requirement to Windows, desktop Linux, OpenBSD, etc. by requiring a QR scan from a certified smartphone to pass reCAPTCHA in some cases. They could expand it more. Control over reCAPTCHA puts Google in a position where they can require having either iOS or a certified Android device to use an enormous amount of the web. Google defines certification requirements for Android which includes forcing bundling Google Chrome, etc. It's enormously anti-competitive. Google's Play Integrity API bans using GrapheneOS despite it being far more secure than anything they permit. It also bans using any other alternative. This isn't somehow specific to an AOSP-based OS. You can't avoid this by using a mobile OS based on FreeBSD instead. You'll just be more locked out. Google's Play Integrity API permits devices with no security patches for 10 years. The device integrity level can be bypassed via spoofing but they can detect it quite well and block it once it starts being done at scale. The strong integrity level requires leaked keys from TEEs/SEs to bypass it. It doesn't provide a useful security feature, but it does lock out competition very well. Services requiring Apple App Attest or Google Play Integrity are primarily helping to lock in Apple and Google having a duopoly for mobile devices. Play Integrity is more relevant due to AOSP being open source. Governments are increasingly mandating using Apple's App Attest and Google's Play Integrity for not only their own services but also commercial services. The EU is leading the charge of making these requirements for digital payments, ID, age verification, etc. Many EU government apps require them. Instead of governments stopping Apple and Google from engaging in egregiously anti-competitive behavior, they're directly participating in locking out competition via their own services. Requiring people to have an Apple device or Google-certified Android device is anti-competition, not security. reCAPTCHA Mobile Verification will currently work with sandboxed Google Play on GrapheneOS but it clearly exists to provide a way for them to start using hardware attestation on systems without it. People without an iOS or Android device will be locked out when this is required even without that. This isn't about security or any missing functionality. GrapheneOS can be verified via hardware attestation. Google bans using GrapheneOS for Play Integrity because we don't license Google Mobile Services and conform to anti-competitive rules already found to be illegal in South Korea and elsewhere. Services shouldn't ban people from using arbitrary hardware and operating systems in the first place. Google's security excuse is clearly bogus when they permit devices with no patches for 10 years but not a much more secure OS. It's for enforcing their monopolies via GMS licensing, that's all.

168
2,348
9,147
367,560
sinjin 🇩🇿🇵🇸 retweeted
Finito les VPN sur de plus en plus de sites du quotidien... Banques, organismes privés, sites institutionnels, etc... assistance.phm.education.gou…
14
93
141
37,572
This is some china level right infringement. In europe, the news talk about censure from Dictatures like Iran, but look like they're trying to do the same and worse
The European Union is pushing for rules to check people's ages on the internet so children cannot easily access porn and certain social media sites. A big rise in VPN use, such as an 1,800 % increase in downloads in the UK after its Online Safety Act. EU experts now describe VPNs as a loophole that needs closing. They are discussing whether VPN providers should check users' ages before allowing sign-ups or connections, and a top EU official has said that stopping these bypasses is one of the next steps. If approved, this change would force VPN services to collect personal data like ID cards or face scans, which would destroy the privacy and no-logs features that make good VPNs useful for many people.
46
6500$ in deductible?! The american tax payer could have (with just the money of the iran war) free healthcare for all if money wasn't this badly managed.
I called to cancel my health insurance because I couldn't afford the premium. The rep asked why. I said $480 a month for a plan with a $6,500 deductible isn't insurance. It's a monthly fee I pay to still go bankrupt if anything actually happens. She didn't have an answer.
Community note
The account owner is from South Asia, which can be seen on their profile, but is presenting themselves as an American. This is engagement bait. x.com/i/status/20533…
48
this kind of news the day before a public holiday in France might let some security team dying of rage
🚨 BREAKING: New Linux zero-day "Dirty Frag" lets ANY local user become root on most major distros. The PoC is already public, half of it isn't patched yet. Discovered by researcher Hyunwoo Kim, the exploit chains two kernel bugs and sits in the same family as Dirty Pipe and Copy Fail. ▪️ CVE-2026-43284 (xfrm-ESP Page-Cache Write): patched in mainline Linux. ▪️ CVE-2026-43500 (RxRPC Page-Cache Write): NO PATCH yet. The exploit is reliable by design. Attackers don't have to win a timing race, the system won't crash and alert anyone if it fails, and it succeeds nearly every run. The embargo got broken before distros could ship fixes, so the working code is now sitting on GitHub. Confirmed working on: Ubuntu 24.04.4, RHEL 10.1, openSUSE Tumbleweed, CentOS Stream 10, AlmaLinux 10, Fedora 44.
1
13
Where is the world going ? we need to pay for software feature on cars already paid. And we should applause for a security update that is free ?!!
Tesla AI Vision deploys airbags before impact, which greatly reduces risk of injury or death. This comes for free on all new cars.
4
je reconnais une 86 sous covering quand j'en vois une
En gros il dit que RedBull peaufine la voiture de Max mais pas la sienne 🤣
105
sinjin 🇩🇿🇵🇸 retweeted
On est le 29 septembre 2025 La situation au Congo 🇨🇩 n’a jamais changé. Regardez comment Félix Tshisekedi laisse mourir son peuple ? Par contre pour donner l’accès aux américains 🇺🇸 aux mines pour que l’Amérique puisse nourrir et protéger sa jeunesse, ça le dérange pas du tout.
64
2,110
3,856
118,219
sinjin 🇩🇿🇵🇸 retweeted
16 Sep 2025
- Israel has actually begun a ground operation, and I'm here in northern Gaza, threatened with death at any moment. If you're browsing, please leave a dot. It's just a dot.
10,164
16,068
96,489
1,660,320