• FauxPseudo @lemmy.world
    link
    fedilink
    English
    arrow-up
    25
    ·
    3 hours ago

    That app just became a national security threat. It gives out information to a non-government server. It can be exploited by foreign agents.

    Just a reminder to the president, this would include his own secret service detail and their location.

  • BoofStroke@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    44
    ·
    edit-2
    6 hours ago

    This white house app?

    https://thereallo.dev/blog/decompiling-the-white-house-app

    The official White House Android app:

    Injects JavaScript into every website you open through its in-app browser to hide cookie consent dialogs, GDPR banners, login walls, signup walls, upsell prompts, and paywalls.

    Has a full GPS tracking pipeline compiled in that polls every 4.5 minutes in the foreground and 9.5 minutes in the background, syncing lat/lng/accuracy/timestamp to OneSignal’s servers.

    Loads JavaScript from a random person’s GitHub Pages site (lonelycpp.github.io) for YouTube embeds. If that account is compromised, arbitrary code runs in the app’s WebView.

    Loads third-party JavaScript from Elfsight (elfsightcdn.com/platform.js) for social media widgets, with no sandboxing.

    Sends email addresses to Mailchimp, images are served from Uploadcare, and a Truth Social embed is hardcoded with static CDN URLs. None of this is government infrastructure.

    Has no certificate pinning. Standard Android trust management.

    Ships with dev artifacts in production. A localhost URL, a developer IP (10.4.4.109), the Expo dev client, and an exported Compose PreviewActivity.

    Profiles users extensively through OneSignal - tags, SMS numbers, cross-device aliases, outcome tracking, notification interaction logging, in-app message click tracking, and full user state observation.

  • baggachipz@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    39
    ·
    7 hours ago

    HELLO EMPLOYEE, TODAY WE FIGHT THR WOKE LIBRULS. MAKE SURE YOU GET TO THE KID ROCK CONCERT AND MMA MATCH ON TIME. THANK YOU FOR YOUR ATTENTION TO THIS MATTER!!!

  • LastYearsIrritant@sopuli.xyz
    link
    fedilink
    English
    arrow-up
    27
    ·
    7 hours ago

    Eventually everyone is going to have to own two phones, one for “official” work and government stuff, and one for actual privacy.

    • darkdemize@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      37
      ·
      7 hours ago

      This is strictly for government-issued devices. So everyone that is subject to this is already carrying two phones.

      • scarabic@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        edit-2
        2 hours ago

        As I have one for work which is not my personal phone. And it is totally enterprise-managed so they put whatever apps they want on it and block anything they want. It’s their phone essentially. This headline seems like a nothingburger to me.

      • FauxPseudo @lemmy.world
        link
        fedilink
        English
        arrow-up
        3
        ·
        3 hours ago

        So like the phones of his secret service detail? I’m waiting for it to be announced that it’ll be bundled into the Trump phone.

        • darkdemize@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          2
          ·
          3 hours ago

          For what it’s worth, I saw that it had been installed on my government issued phone this morning and was able to simply uninstall it.

          • FauxPseudo @lemmy.world
            link
            fedilink
            English
            arrow-up
            1
            ·
            2 hours ago

            Some people won’t have admin control rights to do that. And by uninstalling it you are in violation of an executive order.

                • darkdemize@sh.itjust.works
                  link
                  fedilink
                  English
                  arrow-up
                  2
                  ·
                  1 hour ago

                  Respectfully, I’ve been working in government for nearly 20 years. I know what my limits are and what I can get away with. I never signed any acknowledgement that I would keep the app on the phone. Worst case scenario and extremely unlikely to happen, they somehow notice it’s missing from my phone and ask me about it. “Oh, my bad. Didn’t know I wasn’t supposed to remove it.”

    • sunbeam60@feddit.uk
      link
      fedilink
      English
      arrow-up
      13
      ·
      7 hours ago

      Of course! Employees shouldn’t be conducting business on their private phones anyway!

    • ZapBeebz_@lemmy.world
      link
      fedilink
      English
      arrow-up
      2
      ·
      6 hours ago

      I’ve got my personal phone and a government-issued iPhone. The iPhone gets turned off as soon as I leave work in the evening and I turn it back on when I get to work. I only give out my work phone number, so I don’t get bothered when I’m off the clock. It’s pretty convenient tbh.

  • lol_idk@piefed.social
    link
    fedilink
    English
    arrow-up
    5
    ·
    6 hours ago

    As someone with a work phone, it’s easy for me to absolutely never use the thing. It stays in the office and I remote into my work machine and log into Google messages if I need to check for text. The rest is either accessible from other means or can wait until I’m in the office

    • scarabic@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      2 hours ago

      This is a rage bait headline for the masses who don’t understand what it means to have a work-issued phone.