Defeat 2FA token because of bad randomness - rhme2 Twistword (Misc 400)
Generating random numbers on computers is not easy. And while the intended solution was really hard, the challenge had a problem with the random number generation, which allowed me to solve it. Clarification from Andres Moreno (riscure) on the challenge: "The "official" challenge solution involved reading the tiny Mersenne twister (tinyMT) paper, writing some equations, and using a solver. The tinyMT is tricky to initialize. Giving a proper seed is not enough. You need to provide initial state matrices with certain properties (there is a generator for this). The challenge used improper initialized matrices (zeros) that reduced the PRNG period. During tests, we found that ~12hr were needed to solve the challenge (solver time only), but we did not test the amount of entropy reduction by improper state initialization. Fortunately, the problem was not in the PRNG." =[ đ´ Stuff I use ]= â Microphone:* https://geni.us/ntg3b â Graphics tablet:* https://geni.us/wacom-intuos â Camera#1 for streaming:* https://geni.us/sony-camera â Lens for streaming:* https://geni.us/sony-lense â Connect Camera#1 to PC:* https://geni.us/cam-link â Keyboard:* https://geni.us/mech-keyboard â Old Microphone:* https://geni.us/mic-at2020usb US Store Front:* https://www.amazon.com/shop/liveoverflow =[ â¤ď¸ Support ]= â per Video:   / liveoverflow  â per Month:    / @liveoverflow  =[ đ Social ]= â Twitter:   / liveoverflow  â Website: https://liveoverflow.com/ â Subreddit:   / liveoverflow  â Facebook:   / liveoverflow  =[ đ P.S. ]= All links with "*" are affiliate links. LiveOverflow / Security Flag GmbH is part of the Amazon Affiliate Partner Programm. #CTF #Cryptography

Hardware Power Glitch Attack (Fault Injection) - rhme2 Fiesta (FI 100)

Breaking AES with ChipWhisperer - Piece of scake (Side Channel Analysis 100)

I Hacked This Temu Router. What I Found Should Be Illegal.

RNG on the NES

How to Crack any Software

Something is jamming GPS over Europe. Here's what we found

The Circle of Unfixable Security Issues

I Gave ChatGPT a Body

Zig 2026: No-AI Policy, $670K Foundation, Left GitHub & Why Zig Isnât 1.0 - Andrew Kelley Explains

The AI Take Over Has Completely Backfired and I Can't Be Happier

Solving a JavaScript crackme: JS SAFE 2.0 (web) - Google CTF 2018

Creator of C++: Bell Labs, Negative Overhead Abstraction, Mistakes | Bjarne Stroustrup

Recover RSA private key from public keys - rhme2 Key Server (crypto 200)

"Clean" Code, Horrible Performance

15 Hacking Gadgets in 2026 That Feel Illegal to Own

I turned an old van into a 2-STORY tiny house

Basic Windows Reversing and Attacking Weak Crypto - FLARE-On 2018

1,000+ Tokens/Sec: Google Just Shattered the AI Speed Limit (DiffusionGemma)

The Biggest Hacking Mystery of Our Time: Shadow Brokers

