8 in 10 Banks in Belgium HATE This One Weird eID RCE
▲ 445 r/europrivacy+6 crossposts

8 in 10 Banks in Belgium HATE This One Weird eID RCE

hey everyone, I just presented this at the DEF CON security conference.

If you had the connective signing extension installed previously then you were likely vulnerable to this, although I don’t know if it was being exploited.

amibeingpwned.com
u/acorn222 — 11 days ago

Every CERT wants PGP, every PGP tool feels like it was made in 2003, so I built a free extension to manage PGP keys and encryption

I genuinely got annoyed at the poor UX with existing tools which let me use my PGP keys. CLI tools are great for some things but they're not great for making encrypted messaging.

I've done a bunch of vulnerability reports using PGP for encryption and having my contacts and keys in my browser made my life so much easier. Contacts can be dragged & dropped in, same with files.

It uses passkeys for encryption instead of passwords (if you don't want to use passwords) and only decrypts the keys at use, unless specified otherwise.

The extension requires no sensitive permissions and there's tests to check whether or not the keys are retained in memory when they're not meant to be.

CSP is locked down to disable external communication, no analytics or external servers are used, as it doesn't need them.

No other extension has comparible security to PGP tools from what I've seen.

https://github.com/Am-I-Being-Pwned/PGP-Tools

chromewebstore.google.com
u/acorn222 — 1 month ago

How to use Verified CRX uploads with PGP tools

I wasn't a fan of the suggested way to do verified CRX uploads, so I decided to add in an easy and secure way to sign extensions with PGP Tools.
All keys are encrypted at rest and only decrypted when they're being used.
You can use passwords or passkeys to encrypt the key at rest too.

Link is here: https://chromewebstore.google.com/detail/pgp-tools-encrypt-decrypt/pgpcdgggohpbombhkffjoiiafdlfcpgp

youtu.be
u/acorn222 — 2 months ago
▲ 19 r/Defcon

First time at DEF CON and I'm speaking - What should I know?

Hey everyone, it's going to be my first time at DEF CON and first time speaking at a conference in person, has anyone got any advice for me?

I've watched a bunch of the talks on youtube and IMO I've got some interesting content for mine.
Making the slides right now for the deadline too, making sure I tell the story properly.

Are there any common mistakes people make, is there anything that most people do poorly?

In terms of specifics too, has anyone else heard back after acceptance?
I've also not heard anything yet aside from the main "DEF CON 34: Your submission has been accepted!" email, and I'm assuming this is normal, but I might follow up with them as I'd like to do a live demo.

reddit.com
u/acorn222 — 2 months ago
▲ 335 r/VPN+2 crossposts

The Word 'Toad' Gave Any Website Full Control of Chrome's Most Popular VPN

I am OP here, feel free to ask questions!

amibeingpwned.com
u/acorn222 — 3 months ago