iamak

joined 1 year ago
[–] iamak@infosec.pub 2 points 1 year ago (2 children)

Running de-googled Lineage OS (Android 10 equivalent version). Biggest drawback for me is maps. I make do with OSMAnd+ but I have to search on Google Maps, get the coordinates and paste into OSMAnd+. Other than that no issues

[–] iamak@infosec.pub 15 points 1 year ago

You should read about EU's proposed law DMA. It aims to solve this problem of not being able to contact friends if you uninstall WhatsApp (or any other app). The link explains it better lol

[–] iamak@infosec.pub 1 points 1 year ago

I checked network logs. Apparently my bank encrypts both uid and password before sending. I put 8 chars and it gave error so I'm assuming no

[–] iamak@infosec.pub 9 points 1 year ago

Banks make the worst possible UI and justify it by saying "security" xD

[–] iamak@infosec.pub 1 points 1 year ago (4 children)

Wtf lmao. How to I check if mine does it💀

[–] iamak@infosec.pub 80 points 1 year ago (18 children)

This is one of the dumbest shit ngl. My bank also does this. However they go one step further. They force a maximum 12 letter password and 1 character of each type (capital, small, number, symbol) is necessary. This actively reduces password security smh

[–] iamak@infosec.pub 2 points 1 year ago

Yeah now that you put it this way I realised my mistake. Thanks

[–] iamak@infosec.pub 2 points 1 year ago

Okay. I am pretty new to this stuff so I'll go and check out SSL/TLS. Thanks :)

[–] iamak@infosec.pub 2 points 1 year ago

Oh. Okay. I'll check it out once. I'm pretty new to all this so I didn't know this is how SSL works.

[–] iamak@infosec.pub 1 points 1 year ago (2 children)

First of all thanks for the very detailed response. I have a few questions.

  1. Like you said, why not use public key cryptography? Why is it not well supported for web-apps?

  2. Why not use something like Diffie-Hellman algorithm to share the password? Signal protocol uses ECDHE so I am assuming that it's safe against mitm which the base Diffie-Hellman is vulnerable to (I might be wrong. I couldn't find if it waa vulnerable or not).

[–] iamak@infosec.pub 1 points 1 year ago* (last edited 1 year ago) (5 children)

this measure of security would have been completely void...

Why not hash it server side too? I'm asking because I'm curious

[–] iamak@infosec.pub 1 points 1 year ago

Now that would be interesting :p

view more: ‹ prev next ›