• 0 Posts
  • 8 Comments
Joined 1 year ago
cake
Cake day: June 10th, 2023

help-circle




  • Orvanis@lemm.eetoTechnology@beehaw.orgLemmy user list
    link
    fedilink
    English
    arrow-up
    11
    ·
    1 year ago

    I was able to confirm that the database includes email address and password hash.

    Uhhhh not loving that if true… Why would password hashes need to be sent all over the planet…? That’s a security bomb just ticking.

    Shouldn’t each instance only need to be tracking user Metadata, with only the original users instance handling authentication…? After all my personal interaction is happening on my instance.



  • From a tech perspective, insanely clever to use modern phones rolling shutter mode to sample significantly more data points.

    From a “is this going to cause problems for the average person” perspective - not even close. Requires 65 minutes of recorded, stable footage. The camera must be < 6 feet away if the lights are on, and the cryptography algorithm must be running during that magic hour of recording…

    It does enable remote attacks, but only if all very specific requirements are met, and it requires you have access to a camera for a long period of time that is perfectly positioned.