2 days ago I reported about a #security patch having been applied to the IzzyOnDroid F-Droid repo aka #IzzySoftRepo – but I didn't give much details. After it was tested now at the IoD test & staging area, and running smoothly for two days for the public one, I reported back to its author @obfusk that all seems smooth, and she decided to make POC & patch public. You can find the full details at github.com/obfusk/fdroid-fakes… & openwall.com/lists/oss-securit… now. @fdroidorg @eighthave be welcome using it!
1/2
GitHub - obfusk/fdroid-fakesigner-poc: F-Droid Fake Signer PoC
F-Droid Fake Signer PoC. Contribute to obfusk/fdroid-fakesigner-poc development by creating an account on GitHub.GitHub
Potential security hazard: `apk_signer_fingerprint()` looks at certs in reverse order that Android checks them (#1128) · Issues · F-Droid / fdroidserver · GitLab
Take a look at apk_signer_fingerprint(): def get_first_signer_certificate(apkpath):...GitLab
APK Signing Block considerations (#1056) · Issues · F-Droid / fdroidserver · GitLab
Some considerations regarding the APK Signing Block and how F-Droid handles Reproducible Builds. Block typesGitLab
Part of the bug was known 11 months ago. The new proof-of-concept shows key details that were not previously known nor reported in the issue. Those were just dumped to the public. We asked for that yesterday, and you didn't send it to us, but withheld it to now publicly dump it. That code was posted to GitHub yesterday: github.com/obfusk/fdroid-fakes…
You could have just sent us that link yesterday before tooting it, that would have been better.
Commits · obfusk/fdroid-fakesigner-poc
F-Droid Fake Signer PoC. Contribute to obfusk/fdroid-fakesigner-poc development by creating an account on GitHub.GitHub
I see this was reported to #androguard yesterday github.com/androguard/androgua…
Did you give them any advanced warning?
handles duplicate block IDs in APK Signing Block differently from Android/apksigner · Issue #1030 · androguard/androguard
If you manipulate an APK's Signing Block to have e.g. duplicate v2 Signature Blocks, Android and apksigner will only see the first, but androguard will only see the last (since it uses the ID as a ...GitHub
All I'm asking is for #ResponsibleDisclosure. The tone you sense was my panic as I scrambled to figure out the proof-of-concept to ensure that #FDroid users are kept safe. Signature verification is a key part of that. I cleared my schedule this morning to deal with this.
Thanks to @obfusk to doing the hard work of the proof-of-concept and the patch. I posted my preliminary analysis of the issue on gitlab.com/fdroid/fdroidserver…
1/2
Potential security hazard: `apk_signer_fingerprint()` looks at certs in reverse order that Android checks them (#1128) · Issues · F-Droid / fdroidserver · GitLab
Take a look at apk_signer_fingerprint(): def get_first_signer_certificate(apkpath):...GitLab
They key takeaway is:
If a binary repo maintainer is not careful about where they get their APKs and relies completely on AllowedAPKSigningKeys to verify the APKs, then this is an important issue.
2/2
Zusätzliche APK-Checks im IzzyOnDroid Repo
Nachdem der Library-Scanner nun seit mehreren Jahren im IzzyOnDroid Repo im Einsatz ist war es an der Zeit, einige zusätzliche APK-Prüfungen zu etablieren.IzzyOnDroid
Obligatory #SolarEclipse2024 #eclipse photos, dog and colander edition.
to sólo na gitare...
Dire Straits - Sultans Of Swing (Alchemy Live)
Official Live Video for Sultans Of Swing. Taken from Dire Straits – Alchemy: Dire Straits Live.Dire Straits – Live 1978-1992' is out now (UK/ROW). Out Januar...YouTube
#AndroidAppRain at apt.izzysoft.de/fdroid today with 9 updated and 1 added apps:
* Bubble2: Comic Book Reader/Image Archive Viewer
Enjoy your #free #Android #apps with the #IzzySoftRepo 
IzzyOnDroid F-Droid Repository
This is a repository of apps to be used with F-Droid. Applications in this repository are official binaries built by the original application developers, taken from their resp. repositories (mostly Github, GitLab, Codeberg).IzzyOnDroid App Repo
Samsung Galaxy Tab S9 FE Review - Accessible Android
The tablet has corners instead of a curved display, with the USB Type-C port and speaker positioned at the bottom center and right, respectively. On the topSalih Kunduz (Accessible Android)
Kenny Rogers - The Gambler
REMASTERED IN HD!Official Music Video for The Gambler performed by Kenny Rogers.Follow Kenny Twitter: https://twitter.com/_kennyrogersFacebook: https://www.f...YouTube
Tlačim to #kolo i očima, chčije ze mě na všechny strany, vychlastal jsem skoro všechnu vodu a dosáhl závratný rychlosti 22 km/h.
Jako nedělejte si ze mě prdel, víc ty kola prostě jet nemůžou! :D
Tohle je můj top, jinak jezdim #MTB +- 18 na tomhle profilu - v podstatě rovina.
Asi bych byl spokojenej, kdyby se mi povedlo tenhle průměr jezdit normálně bez toho, abych se pak v cíli musel vybrečet a nebyla za mnou spocená čára, ale z toho asi nic nekouká - byť by těch 35 minut do práce / z práce namísto 45 bylo fakt milý :D
I'm on an unrestricted variable electricity tarrif.
My price per kwh is about to go negative for 3 hours*
I can get my oven and air con unit to fight each other, and be paid for it!
*it's so windy that there's nowhere to put all the energy the turbines are generating, so they pay (mostly industry) to use it up. The price shoots up in the evening when everyone starts putting their heating on and cooking dinner. People on a fixed price tarriff are paying ~25p/kWh all day in the UK right now.
reshared this
I updated my AutoHotkey Doom Launcher Script. It adds co-op as an option. Unfortunately I didn't get to actually test it with co-op, but it does run.
The zip file ccontains both the executable, .exe and the source code, .ahk.
All of the other components have been tested and they do work. The only thing I'm not quite sure about is the co-op option, but I know the hosting part of it actually opens things so that someone can join.
If you want to use the script, place it in your TobyAccessibilityMod_Version7-0 folder and run the .exe. It will spawn a menu which you can navigate with the arrow keys to select an option.
All of a sudden it starts raining handmaids in handcuffs:
erosblog.com/2024/04/06/its-ra…
#Facism #Handmaids #HandmaidsTale #Privacy #ReproductiveRights #BurnThePatriarchy #Technology #Patriarchy #Christofacism #Christianity #Ovulation #OvulationTracker #Ovia #Tech #Danger #ReproductiveFreedom
It's Raining Handmaids In Handcuffs - ErosBlog: The Sex Blog
You've all heard the "joke" about the programmer/engineer who keeps a loaded gun by his printer in case it makes an unexpected noise and he needs to shoot... Tagged: sex blogging, handmaids, ovulation tracker, patriarchyBacchus (ErosBlog: The Sex Blog)
drip. menstrual cycle and fertility tracking | F-Droid - Free and Open Source Android App Repository
Open-source, non-commercial and leaves your data on your phone.f-droid.org
The trouble with ‘gender ideology’
Can we learn to see gender in its real complexity?America Magazine
@Tzipporah with their Eighth Generation "Two Spirit" wool blanket by Two Spirit artist Ryan Young (Lac du Flambeau Band of Lake Superior Chippewa) that calls out to their community's traditional story about crows.
eighthgeneration.com/collectio…
#Mvskoke #Chippewa #Crows #Native #Indigenous #TwoSpirit #2SLGBTQ
Two Spirit Wool Blanket
Native American designed Wool Blankets by Eighth Generation. Wool Blanket design features contemporary Ojibwe crow art by Native American two spirit artist Ryan Young. Native American & Indian Wool Blankets for Men, Women & Home.Eighth Generation
Community Member Monday: Adam Seskunas - The Document Foundation Blog
Tell us a bit about yourself! My name is Adam Seskunas and I currently live in San Diego, California. In my free time I enjoy outdoor activities, hiking, backpacking in the Sierra, rock climbing and surfing with my daughter Sofia.Mike Saunders (The Document Foundation)
appleinsider.com/articles/24/0…
Best Buy hops on $849 M2 MacBook Air bandwagon with latest deal
After B&H initially offered the M2 MacBook Air for $849, Best Buy is now offering the same deal, matching the lowest price on record.Christine McKee (AppleInsider)
Speaking of #overlays, there is yet another one: #WebAbility
I have already made a PR to add it to the Overlay Fact Sheet:
github.com/karlgroves/overlayf…
As with other overlays, it makes WCAG/ADA promises, fails to fix stuff, replicates platform features (poorly) in CSS, and introduces WCAG violations just by adding it to a site.
Cool business model.
Adding WebAbility as an overlay by aardrian · Pull Request #1189 · karlgroves/overlayfactsheet
From Introducing WebAbility.io: Ultimate Web Accessibility Widget for ADA & WCAG Compliance, a press release from Techyweb Solutions INC.: WebAbility.io offers easy, comprehensive solutions for we...GitHub
🚨 PRIVACY WIN 🚨
#Google must destroy $5 billion worth of user data illegally collected in Incognito Mode 💪
Because #privacy matters.
Read more on the court ruling:
👉 tuta.com/blog/google-incognito…
Google must destroy $5 billion worth of user data illegally collected in Incognito Mode
If you thought Google’s Incognito Mode was private, you’re one of the billions around the world blinded by big tech’s privacy illusion.Tutanota
"I don’t take it. I don’t want it." Speaking to an INN Boston member yesterday, Rep. Jim McGovern said he rejects AIPAC and its toxic influence in Congress, as it prolongs the massacre in Gaza.
Help us #RejectAIPAC by joining a virtual phone bank on Thursday! mobilize.us/ifnotnow/event/615…
Reject AIPAC Phone Bank
We need your help to get every Democratic candidate on record whether they will stand with humanity or reject AIPAC’s dangerous agenda of endless war and apartheid.Mobilize
Twice in the past week I've read scholars who should know better repeat the urban legend that the QWERTY keyboard was designed to slow down typing, and thus, jamming, on early typewriters.
That'd be cool if it were true, but it's not, and the the truth is even cooler. The QWERTY keyboard evolved over time, shaped by two forces: (1) since the early machines were used by telegraph operators, the keys were arranged to avoid common transcription errors; and (2) competing patents of the typewriter slightly arranged the keyboard layout in order to qualify as new (and therefore patentable) designs.
Check out this research for more: repository.kulib.kyoto-u.ac.jp…
cmake: check fseeko after detecting HAVE_FILE_OFFSET_BITS by SirLynix · Pull Request #13264 · curl/curl
On Android, fseeko is defined as is (I omitted other functions for clarity): /* See https://android.googlesource.com/platform/bionic/+/master/docs/32-bit-abi.md */ #if defined(__USE_FILE_OFFSET64) ...GitHub
Who needs operating systems when you can IRC from the UEFI?
tomshardware.com/software/some…
Modder made an IRC client that runs entirely inside the motherboard's BIOS chip
"I told a friend I was making a joke project, then explained. She said she wasn't sure when to laugh. I'm not sure either."Christopher Harper (Tom's Hardware)
10 ways to prepare for Global Accessibility Awareness Day (GAAD) 2024
Global Accessibility Awareness Day 2024 is the perfect excuse for you to shape up your organisation's digital accessibility skills. We have some ideas for you!abilitynet.org.uk
A quick look back at Windows 3.1 which hit the RTM stage 32 years ago this week
On April 6, 1992, Windows 3.1 was released to manufacturing. 32 years later, it has been recognized as a major addition to Microsoft's Windows operating system lineup and paved the way for Windows 95.John Callaham (Neowin)
GitHub - curl/curl: A command line tool and library for transferring data with URL syntax, supporting DICT, FILE, FTP, FTPS, GOPHER, GOPHERS, HTTP, HTTPS, IMAP, IMAPS, LDAP, LDAPS, MQTT, POP3, POP3S, RTMP, RTMPS, RTSP, SCP, SFTP, SMB, SMBS, SMTP, SMTPS, T
A command line tool and library for transferring data with URL syntax, supporting DICT, FILE, FTP, FTPS, GOPHER, GOPHERS, HTTP, HTTPS, IMAP, IMAPS, LDAP, LDAPS, MQTT, POP3, POP3S, RTMP, RTMPS, RTSP...GitHub
Congrats!
I’m suddenly wondering whether anything interesting can be gleaned by comparing commit / fork / star ratios across projects.



Sonny
in reply to kcxt @ 39c3 • • •