I appreciate the dark video. It's different and easy on the eyes. Global dark mode ftw
@ggwp77453 жыл бұрын
Let the darkness rise
@michaeltorkaman68753 жыл бұрын
@@weakspirit_ hahaha
@THExRISER3 жыл бұрын
@@weakspirit_ Ok "Dawn Praiser".
@kellysmith73573 жыл бұрын
the fact that some devs dont put in dark mode pisses me off
@VaradMahashabde3 жыл бұрын
"every device is hackable" "weaponized exploits" "every person can be killed" KZbin : _you are on thin ice there mister_
@Originalimoc3 жыл бұрын
😂
@ologhai85593 жыл бұрын
also YT: "Hey, nothing wrong with that scam spamming comments you have reported. We wont delete it."
@aighti3 жыл бұрын
*on
@supe47013 жыл бұрын
Why should KZbin care what he is saying? Besides a few keywords that might automatically flag the video, there’s nothing KZbin would dislike.
@forreutubey7802 жыл бұрын
@@supe4701 you clearly have living in a cave
@danthe1st3 жыл бұрын
every human could be killed doesn't mean every human gets killed ~ LiveOverflow, 2021
@bugswriter_3 жыл бұрын
We just need a killer.
@anilkumarhansda80873 жыл бұрын
@@bugswriter_ time ??
@AgentM1243 жыл бұрын
Climate Change: Hold my fossil fuels.
@pavel96523 жыл бұрын
Yet every one dies, eventually ;)
@m1kr0kosmos3 жыл бұрын
@@bugswriter_ 👏👏👏
@Daniooo3 жыл бұрын
Liking the new little edits like the glitches and stuff, adds more personality to your videos :D
@em_ma30923 жыл бұрын
Me after watching this video: **reboots phone just in case**
@DanielandStuff73 жыл бұрын
there is no need to reboot, as china phones will reboot them self :D
@vaisakh_km3 жыл бұрын
@@DanielandStuff7 🤣🤣
@anupamjaiswal77143 жыл бұрын
There is post exploitation
@DanielandStuff73 жыл бұрын
@@nhvidn Xiaomi Mi 11 ?
@Stoney_Eagle3 жыл бұрын
General rule of thumb: If you've seen Doom running on it, it's hackable. 😁
@sunnymishra10573 жыл бұрын
I have seen Doom on pregnancy test kit
@vectoralphaSec3 жыл бұрын
@@sunnymishra1057 it's hackable.
@efeyzee3 жыл бұрын
@@sunnymishra1057 sadly it was just displaying Doom running on an RPi
@zach28303 жыл бұрын
@@sunnymishra1057 came to say that
@ThePC0073 жыл бұрын
@@efeyzee And it wasn't even the original hardware. The guy just put his own hardware into the kit and streamed doom to it, which is just boring and completely negates the entire purpose of the challenge. :(
@jfb-3 жыл бұрын
The fact that every computer could in principle be hacked is the singular thing that makes me nervous about self driving cars
@golfmc79413 жыл бұрын
So can normal cars 🙃
@theairaccumulator71443 жыл бұрын
@@golfmc7941 Cars with no computer can't be hacked.
@tresuvesdobles3 жыл бұрын
There is no such thing as cars with no computer anymore. Furthermore, for instance, plains are completely automatic too, yet there are no known cases of hacking. Idk, I feel we just have to not think too much about it
@veneering41283 жыл бұрын
@@tresuvesdobles planes have been hacked before by the CIA in order to kill people fighting against their oppression
@maxpoppe3 жыл бұрын
@@tresuvesdobles well the USA military has cars without electronics in case of an emp so yea those aren't hackable
@precipire10253 жыл бұрын
"Hey I think I have a virus" "Have you tried turning it off and on again?" "what"
@_CryptoCat3 жыл бұрын
Awesome video 😸 So lucky cts didn't get hit by the exploit targeting researchers! I'm also among the 3% that use Firefox 🔥🦊😎
@0xgodson1193 жыл бұрын
me 2 😎
@buowerc3 жыл бұрын
I’m thinking what researcher would ever use chrome
@balam3143 жыл бұрын
🔥🦊 gang
@thecaretaker66593 жыл бұрын
Use brave
@BasteG0d693 жыл бұрын
I agree
@BasteG0d693 жыл бұрын
Great video! :-)
@askplays3 жыл бұрын
:) Ayy it's the guy from the video
@daljeetbhati8353 Жыл бұрын
U r videos sure go over head but they are very good
@bopon40903 жыл бұрын
Could not thank enough for sharing these. I use to think no one can hack my phone unless they have a physical access to my device.
@zanidd3 жыл бұрын
I really enjoyed this format. I need mooore :D
@solveigvan8083 жыл бұрын
I think a more useful question is: "Can every device be hacked remotely without your interaction or awareness." This is the type of attack that concerns me the most and fortunately there are several ways to prevent this almost completely.
@kellysmith73573 жыл бұрын
???
@NathanAsh3 жыл бұрын
yeah put your phone in the microwave lol
@mo9383 жыл бұрын
i remember when LO didn't show his face. he has come so far and it's been incredible watching. keep up the good work.
@CraneArmy3 жыл бұрын
breaking into fort knox for a gold heist, may be possible, how many armored divisions do you have? worth?
@nexovec3 жыл бұрын
Originally I read it as fart box, but that doesn't matter. Security solution for newer samsung phones is literally named knox.
@gameglitcher3 жыл бұрын
I am unsure of the processes of Fort Knox, but I am sure they have incoming and outgoing shipments of things. Access to the ledgers for these would provide a much more realistic attack vector. After all, your goal is to get the material out, why not use the systems they have to your advantage and weaken the target? I am sure much more research went into the development of the Fort than the armored transports. Physical security still has the same weaknesses of mismanaged I/O and backdoors. Plus when the physical security is controlled by electronics, an armored truck is just a mechanized safe with lethal security measures on wheels, right?
@CraneArmy3 жыл бұрын
@@gameglitcher Im sure you are right. but I'm giving this as a benchmark. This is the immediate solution, that sets a baseline for risk and cost. All other solutions are going to be higher risk and lower cost, or they are bad vectors.
@gameglitcher3 жыл бұрын
@@CraneArmy Fair XD. if it wasn't for your comment I wouldn't have had a response >.>
@Florian.Dalwigk3 жыл бұрын
The amount of proficiency in this video is pure MindOverflow 😅
@DarkyBoy3 жыл бұрын
Cool dich hier zu sehen :P
@BenjaminAster3 жыл бұрын
Ich erwarte eine Kollaboration zwischen euch! Ihr seid schließlich beide deutschsprachig.
@Florian.Dalwigk3 жыл бұрын
@@DarkyBoy 😊
@Florian.Dalwigk3 жыл бұрын
@@BenjaminAster Ich werde es mal anbringen :)
@teggolT3 жыл бұрын
Zwei deutsche sprechen Englisch miteinander --- Two Germans speaking English with each other
@b3twiise8533 жыл бұрын
Dude casually has a pwn2own award hanging behind him
@luizinhoensina3 жыл бұрын
dude, your content has to be one of the best in KZbin, love what you're doing!
@electricimpulsetoprogramming3 жыл бұрын
tambem!
@YandiBanyu3 жыл бұрын
The subtitle is golden haha. Loved your content
@mu11668B3 жыл бұрын
Expectation: _Free WiFi is dangerous it could pwn your phone and drain your wallet._ Reality: *Ahhhahaha free routers botnet goes brrrrrrr!* *Ohh this kid downloaded our fake cracks and installed malware on their parents' desktop! By disabling the antivirus as what we told them! Lmao!*
@default9393 жыл бұрын
Can you do a video about row hammer exploitation please ?
@ron461353 жыл бұрын
Thank you for this well made video. Interesting discussions and pointers raised!
@EnricoCalrissian3 жыл бұрын
I couldn't have summarized it better myself. And congrats to being published in Phrack
@asandax62 жыл бұрын
Question is the video supposed to cut off around 8:04 with a message "An error ocurred. Please try again later.(Playback ID: xxxxxxxxx)"?
@GBlunted3 жыл бұрын
I feel like this is awesome content! Love the input from the other experts sprinkled throughout the video, each in their own style. So cool! 😎
@kkon5ti3 жыл бұрын
my phone fucks itself up so often, it gets rebooted sometimes even twice daily
@danthe1st3 жыл бұрын
depends on how you define "every device"
@kritikusi-6663 жыл бұрын
@ 14min...you stay away from my cookies. This was a very great piece.
@vectoralphaSec3 жыл бұрын
Would be great to hear what the researchers think is the best or more secure browser? is it Google Chrome? Microsoft Edge? Firefox? Opera? Brave Browser? Safari? or any other browser. Which one do they think is better?
@Jujo13 жыл бұрын
Yeah even I would love to know this, glad the guy was using Firefox but considering how Firefox is one of the most used browsers out there wouldn't there be people trying to make 0day exploits that can work on both chromium and Firefox too? Should I really rely on Firefox so much?
@binarycat12373 жыл бұрын
lynx (¾ joke)
@marz33083 жыл бұрын
no one safe, it's just less targeted than others
@TheGrimravager3 жыл бұрын
running debian unstable with a cron that runs every 6 hours: sudo apt-get update -yqq && sudo apt-get upgrade -yqq so basically, I'm super vulnerable when the debian repository gets hacked xd
@schwingedeshaehers3 жыл бұрын
Reboot or live patch?
@_xpl0it_3 жыл бұрын
thanks for this video brother, got to learn a lot from this video. I too definitely disabled jit and webassembly for no obvious reason, but since the experts do and it's good to do so then why not
@Avg-internet-warrior2 жыл бұрын
sometime big software firms leave vulnerabilities unpatched just because they accept risk and put blidfold
@valshaped3 жыл бұрын
Step 1: Define "device" in a meaningful way Step 2: check if your target is a device
@fjb18543 жыл бұрын
7:45 Full chain. I've clicked on Google ads using a Google browser and gotten malware, so I can confirm this.
@AgentM1243 жыл бұрын
I wonder if you buy a phone that's 4 years old, if it's vulnerable to attacks because the factory software is out of date and still has to perform a system update to the latest security version. So there might be a time frame in which you could get trojaned or something.
@krlst.59773 жыл бұрын
Excellent video, thanks!
@kipchickensout Жыл бұрын
"phishing or a company mishandling your data" kinda reminded me of the new (at least german) IDs requiring you to let them store your finger prints and even though I don't know why that could be a problem, I do not even remotely trust them with those... it feels like telling them my password which they then probably just store in plain text
@l3yce5833 жыл бұрын
If for example a journalist uses a second machine (and maby a second network) for projects which is not connected to global network (or to anything else outside his control) anny way of access should be eliminated right?
@steven94923 жыл бұрын
i think the production value of this channel is going up, and I love it! however I think the shadows on your face were too dramatic
@comradepeter873 жыл бұрын
Seeing how so many of these vulnerabilities are memory-related, it would be interesting to see how the solutions that tackle it at the programming language level pan out. If you would make a video on that it'd be really cool.
@j3r3miasmg3 жыл бұрын
Nice to see some of the legends talking about vulnerabilities.
@matasarlauskas31653 жыл бұрын
Thank you, this video was really interesting and helpful :)
@gunner90373 жыл бұрын
it's incredible that buying and selling these exploits to third parties isn't illegal even though it definitely should be
@LiveOverflow3 жыл бұрын
it's heavily regulated
@YandiBanyu3 жыл бұрын
@@LiveOverflow May I ask why? I mean, what is the purpose? If it's government, I could see it, but a third party?
@TheElexec3 жыл бұрын
It's just information. Regulating this gets really close to regulating free speech. A lot of third party buyers are also governments and tech companies themselves. Making a market illegal just moves the buyers into the black market. Also, security researchers are smart enough to hide their traces anyway.
@YandiBanyu3 жыл бұрын
@@TheElexec you've got a point. Moving the market to the black market just make things worse.
@georgehammond8673 жыл бұрын
pagacus is made by israel and very advances in real life.
@ARitzCracker3 жыл бұрын
I got a question for you. What's the risk when Android phone manufactures stop pushing updates to their devices after the devices are 3 years old? When my Phone started getting kernel updates from the manufacturer, I started using LineageOS. I know someone could theoretically edit my system partition to put their nasty stuff instead if they have physical access, but wouldn't being unable to receive system updates for your phone make you more vulnerable to drive-by's?
@ActualAshCam Жыл бұрын
If your kernel has release-keys builds (which I believe Lineage does), you should be able to re-lock your bootloader and still receive OTA updates.
@ARitzCracker Жыл бұрын
@@ActualAshCam ah, the issue is that I use magisk so I can bypass the non-manufacturer-approved OS checks so I can still use my banking app on my phone. Re-locking the bootloader in that state still bricks the phone.
@ActualAshCam Жыл бұрын
@@ARitzCracker Ah, I see. You still probably could, it would just take a lot more work, including creating your own signing keys, and signing patched boot images.
@codegeek983 жыл бұрын
The subtitles go haywire starting at 10:35 and 13:13
@AgentM1243 жыл бұрын
Even with an infinite amount of ways to hack a computer, there can still be unhackable computers.
@Maxjoker983 жыл бұрын
> Always remember, always reboot your phone Yeah right, like I have any other choice with my PinePhone. That thing is a little unstable ;)
@hpsmash773 жыл бұрын
You should also, in the general guidelines, include that its better physically disable stuff that using some software, like how you should detach your webcam and mic when not in use. great video
@Opcode3 жыл бұрын
make video in row hammer exploitation please :)
@Swixo3 жыл бұрын
I’m also very interested 👍
@default9393 жыл бұрын
good idea !
@antoinehanako31933 жыл бұрын
Ok, but what about intentional backdoors either in software, or hardware?
@erwor3 жыл бұрын
Is it dangerous to use an old android phone that does not get updates for more than 3 years now?
@eqwadordivoo37923 жыл бұрын
but what is the most common method to discover 0days ? fuzzing, code audit(only for open source) or reverse engineering?
@elliot_yoyo3 жыл бұрын
Subtitles have problem at 10:50
@denisrosas2 жыл бұрын
One question I always had. Is copying and pasting my password from a password manager is a really stupid way to get pwned?
@LiveOverflow2 жыл бұрын
No
@rachitmukherjee57253 жыл бұрын
The subtitles from 10:35 to 10:57 say something elsee 🤔🤔🤔🤔
@Rerbun3 жыл бұрын
I'm guessing using the Lynx browser in termimal also reduces the attack surface quite a bit?
@4.0.43 жыл бұрын
No, you need to hide in the woods and communicate only by pigeon. Make sure to inspect every pigeon packet to be double safe.
@clippy36563 жыл бұрын
I am so curious if he really rebooted his phone in that video or if he just slid his finger over the screen
@grim.heart82713 жыл бұрын
16:49 umatrix shouldn't be used as a mitigation of javascript-related threats. Development is ended and the github repository is archived. Use alternative solutions for js blacklisting.
@adamblomberg3 жыл бұрын
Outdated stuff. The developer has just said to use unlock origin since it has similar features from same developer. Also what she mean with iphone? There's only safari on iphone, that's the only engine used for all of them. It's very outdated as well apple not supporting web standards to keep monopoly on app store. Also exploits for Android has been more expensive than iOS because iOS had so many they had to disable the security firm couldn't take any more and closed reporting for a time don't know the situation now. Also pretty curious how famous people like Elon musk with extreme confidential information deal with this it's pretty known he uses an iPhone.
@sajjadhossanshimanto86223 жыл бұрын
You're lying. You can't hack my Broken PC
@Gabriel-xq5es3 жыл бұрын
haha Axe go brr
@ludfde3 жыл бұрын
If somebody hacks my pc thats literally the only person, that has access to it.
@SproutyPottedPlant3 жыл бұрын
What about my Sega Mega Drive?
@tacokoneko3 жыл бұрын
15:50 the firefox master race wins again. obviously this isn't saying there aren't firefox exploits, but it is saying that chromium exploits are much more sought-after, popular and common than firefox, because of market share. all the more reason to use pale moon - present-day pale moon is hard forked from no newer than firefox 52, making upstream firefox 0-days incredibly unlikely to work on it. and no matter what browser you use, turning off javascript completely except for a small whitelist makes it exponentially more difficult to target your attack surface.
@isse67903 жыл бұрын
Using old software doesn't make you more secure, it makes you much more unsecure. Furthermore Pale moon is maintained by a retarded furry and should not be used by anyone. Palemoon has already been attacked once when one of their servers got hacked and every executable was bundled with malware. Don't give security advice when you don't know what you're talking about.
@tacokoneko3 жыл бұрын
@@isse6790 the fact you think pale moon is old software automatically makes your entire opinion invalid and discarded
@safwanljd3 жыл бұрын
Your content is gold, you just need more appealing thumbnails
@georgehammond8673 жыл бұрын
you are a lot better then alot of others people around on KZbin. can you give that SUDO exploit, this will make you very famous.
@OthmanAlikhan3 жыл бұрын
Thanks for the video =)
@iamNATFAN3 жыл бұрын
My issue with one point in this video is that a software "weapon" is very different from real weapons, like you said. However in my opinion the key difference here isn't the level of damage that can be caused (quality), it's the amount of people that can be affected (quantity). We know that exploits like Pegasus do exist in the real world, and they are relatively hard to detect. Because a zero click exploit could be effectively deployed on any device, it can therefore be deployed on every device. Without trying to sound too much like a conspiracy theorist, we know that historically nation states are usually 10-20 years ahead of consumer technology. I don't see why we should consider the Digital Age any different in that regard. If you were a dictator, and you wanted to have near omnipotence of anything that happens in your country (or abroad, the Internet doesn't abide by physical borders), why wouldn't you pay a few million (or billion, you have country-level money) and get a nice new zero click zero day that you can deploy on any number in the phone book? Sorry for the ramble, happy to chat with people further about this. I'd love to be proved wrong, because right now I can't really see a fault in my logic here, apart from speculating on potential technology, which I am willing to admit debases the premise a little.
@xerotoninz3 жыл бұрын
just restarted my phone... and ill update later
@OrangeSan3 жыл бұрын
"every device is hackable" *turns on on incognito mode* You can't touch me now buckaroo :)
@glorytoarstotzka3303 жыл бұрын
10:36 the subtitles break here, probably because of an exploit...
@SergiuszOlszewski3 жыл бұрын
I use Windows 10 Mobile. 0.01% market share. No chance there is an exploit for my phone one would be able to sell.
@unskeptable3 жыл бұрын
Hi , Can someone hack into a Bank to increase their balance or into a Broadband Operator to get unlimited data for example ?
@Desperado0703 жыл бұрын
We all get killed by the grim reaper in the end... Time to put me computer in a safe.
@nathanellis78193 жыл бұрын
Thank you for the dark mode. My eyes are grateful. Wish more ppl would do this.
@yugiohsc3 жыл бұрын
I also hadn’t updated my phone! Thanks
@ag0ny3 жыл бұрын
Nice. Thanks 👍
@anthonymarquez25423 жыл бұрын
Have you covered anti-cheat and drm system exploits in games?
@veneering41283 жыл бұрын
He has a series on Guild Wars 2 botting
@Zedoy3 жыл бұрын
Nee Video!!! Yaaay ❤️
@igorgiuseppe18623 жыл бұрын
wait... is that company (zerodium) business model even legal?
@_specialneeds3 жыл бұрын
I know you can run separate systems on Android in a VM which I do from time to time for browsing the web. I really don't bother with Apple products because of their unethical opposition to the right to repair movement but VMs are a good way to isolate your activity.
@LiEnby3 жыл бұрын
Man it would be so cool to be able to do this .
@samuelsamuel40993 жыл бұрын
I use TempleOS btw
@vectoralphaSec3 жыл бұрын
what's that?
@migueltucabron3 жыл бұрын
No, you're not. TempleOS can't even connect to the internet.
@samuelsamuel40993 жыл бұрын
@@migueltucabron that was my point
@migueltucabron3 жыл бұрын
@@samuelsamuel4099 No, your point doesn't make an sense because you're writing a comment on KZbin.
@v380riMz3 жыл бұрын
I use AmongOS
@jeanpierre59413 жыл бұрын
The question isn’t can you be hit by a 0-day of course you can, the question is instead are you worth it, are you in possession of have access to something that would justify using the work of 5-10 highly skilled engineers? 90% of the time the answer is no.
@xoro1633 жыл бұрын
Reboot means restart or reset?
@programorprogrammed3 жыл бұрын
restart, to boot, to start again
@xoro1633 жыл бұрын
@@adidragomir7469 ok👍
@SergieXD3 жыл бұрын
short answer?
@snowstar35602 жыл бұрын
"Every computer can be hacked" well good luck trying to hack an offline computer lol
@VISION-IT3 жыл бұрын
THX for the info Beginner question - does the low Zero Day risk for a normal user mean browsers without plugins or plugins included ? In other word - does the risk rise for normal user, if plugins are installed?
@愛3 жыл бұрын
16:30 good info
@Kynatosh3 жыл бұрын
They can't hack my mechanical turing machine without having physical access :D
@monolofiminimal3 жыл бұрын
The true answers is yes & no xd, depending on the phase of the moon
@zyansheep3 жыл бұрын
The answer for every question is "it depends"
@gl3nda963 жыл бұрын
@@zyansheep is this reply a reply?
@du42bz3 жыл бұрын
@@gl3nda96 It depends
@gl3nda963 жыл бұрын
@@du42bz Thank you, I was in an existential crisis over that
@prevostclement3 жыл бұрын
Any advice for crypto users? Especially with DeFi stuff, disabling js is definitely not possible. Do you have recommendations?
@Whitbug682 жыл бұрын
I actually need a phone tracked. No number and address and name.
@MrKristian2523 жыл бұрын
Ok, so Apple is paying millions to prevent jailbreaking?
@NameGoesHere2853 жыл бұрын
Oh no, that is a buyer and reseller of zero-day exploits, their final buyer is probably governments/intelligence agencies, nothing to do with Apple.
@ozgur51173 жыл бұрын
5:54 lol Microsoft exchange anyone surprised
@rizkymazwarpratama58863 жыл бұрын
Michael Cera explain about hacking
@myname-mz3lo Жыл бұрын
with a quantum computer yes. everything can be decrypted . no need for it to even be hacked
@kobenbawest3 жыл бұрын
“Amy” scares me
@Fatih9837 Жыл бұрын
Great Video
@Originalimoc3 жыл бұрын
Wait, do you run your browser with Admin account/UAC(Windows)? If no, and control system by using browser bug doesn't it mean Windows has a problem?
@GrzesiekJedenastka3 жыл бұрын
Just think about this for a moment... Where do you keep all your important data? On your administrator account?
@Originalimoc3 жыл бұрын
@@GrzesiekJedenastka not on browser, I think 🤔
@GrzesiekJedenastka3 жыл бұрын
@@Originalimoc OK, I should have been more direct. You have your data on your user account, not your admin account. Every program running as your user can access all your data. You don't need your process to run as administrator to be dangerous.
@Originalimoc3 жыл бұрын
@@GrzesiekJedenastka 🤔🤔🤔🤔🤔🤔🤔
@tibofordeyn15293 жыл бұрын
Ok but that’s quite scary
@LittleRainGames3 жыл бұрын
I think the government has to worry, not the average citizen.
@lis65023 жыл бұрын
this autoupdate crap is double sided edge and i feel sheer lack of UAT/ DTAP model of delivering updates. consider that updated browser doesn't support password saving "for security reasons". or what's worse, stuff their annoying ad banners to menu, because they can. no,thank you, i'll decide by myself if its worth of applying certain update.