infosec.pub

EU’s official age verification app found exposing sensitive user data; also EU Age Verification can be bypassed using their own infrastructure (opens in new tab)

> Hacking the EU Age Verification app in under 2 minutes. > > During setup, the app asks you to create a PIN. After entry, the app encrypts it and saves it in the shared_prefs directory. > > 1. It shouldn’t be encrypted at all - that’s a really poor design. > 2. It’s not cryptographically tied to the vault which contains the identity data. > > So, an attacker can simply remove the PinEnc/PinIV values from the shared_prefs file and restart the app. > > After choosing a different PIN, the app p...

Read the original article
Sign in to keep reading the full article.

Keyboard Shortcuts

Navigation

Next / previous post
j/k
Open post
oorEnter
Preview post
v

Post Actions

Love post
a
Like post
l
Dislike post
d
Undo reaction
u
Save / unsave
s

Recommendations

Add interest / feed
Enter
Not interested
x

Go to

Home
gh
Interests
gi
Feeds
gf
Likes
gl
History
gy
Changelog
gc
Settings
gs
Discover
gb
Search
/

General

Show this help
?
Submit feedback
!
Close modal / unfocus
Esc

Press ? anytime to show this help