• FauxPseudo @lemmy.world
    link
    fedilink
    English
    arrow-up
    1
    ·
    1 month ago

    That app just became a national security threat. It gives out information to a non-government server. It can be exploited by foreign agents.

    Just a reminder to the president, this would include his own secret service detail and their location.

  • BoofStroke@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    1
    ·
    edit-2
    1 month ago

    This white house app?

    https://thereallo.dev/blog/decompiling-the-white-house-app

    The official White House Android app:

    Injects JavaScript into every website you open through its in-app browser to hide cookie consent dialogs, GDPR banners, login walls, signup walls, upsell prompts, and paywalls.

    Has a full GPS tracking pipeline compiled in that polls every 4.5 minutes in the foreground and 9.5 minutes in the background, syncing lat/lng/accuracy/timestamp to OneSignal’s servers.

    Loads JavaScript from a random person’s GitHub Pages site (lonelycpp.github.io) for YouTube embeds. If that account is compromised, arbitrary code runs in the app’s WebView.

    Loads third-party JavaScript from Elfsight (elfsightcdn.com/platform.js) for social media widgets, with no sandboxing.

    Sends email addresses to Mailchimp, images are served from Uploadcare, and a Truth Social embed is hardcoded with static CDN URLs. None of this is government infrastructure.

    Has no certificate pinning. Standard Android trust management.

    Ships with dev artifacts in production. A localhost URL, a developer IP (10.4.4.109), the Expo dev client, and an exported Compose PreviewActivity.

    Profiles users extensively through OneSignal - tags, SMS numbers, cross-device aliases, outcome tracking, notification interaction logging, in-app message click tracking, and full user state observation.

  • baggachipz@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    1
    ·
    1 month ago

    HELLO EMPLOYEE, TODAY WE FIGHT THR WOKE LIBRULS. MAKE SURE YOU GET TO THE KID ROCK CONCERT AND MMA MATCH ON TIME. THANK YOU FOR YOUR ATTENTION TO THIS MATTER!!!