Live data from Hacker News

I decompiled the White House's new app

thereallo.dev

61–70 of 291 posts

Re: I decompiled the White House's new app

#61
post #32

Earlier quoted context omitted.

Aren't the banners for EU page visitors. I don't think there is a US law about this, is there?

And when the app links off to an EU site? Nothing prevents an EU user from using this app. There are a variety of Trump enthusiasts, though I suspect less than there are here in the US.

They conduct a pervasive, hidden, persistent user tracking not only without consent, looking at the analysis, but also stripping the user from a chance of declining tracking on other sites.

I'm quite sure that's illegal.

Re: I decompiled the White House's new app

#62
post #48

Earlier quoted context omitted.

It can request with a JS call. It can't passively collect it without you approving first. The article is written like calling that JS function will turn on location tracking without consent.

He explicitly says he can't determine it, but that the location tracking as configured will turn on once the user grants consent. All true statements. How would you have written it differently

"If the user chooses to opt-in and grants location-tracking permission, the app is then, and only then, able to track the user's location?"

Re: I decompiled the White House's new app

#63

The argument regarding no certificate pinning seems to miss that just because I might be on a network that MITM's TLS traffic doesn't mean my device trusts the random CA used by the proxy. I'd just get a TLS error, right?

Not if someone can issue the certificate signed by the CA your phone trust.

Imagine being in a cafe nearby, say, embassy of the certain north African country known for pervasive and wide espionage actions, which decides to hijack traffic in this cafe.

Or imagine living in the country where almost all of the cabinet is literally (officially) being paid by the propaganda/lobbying body of such country.

Or living int he country where lawful surveillance can happen without the jury signoff, but at a while of any police officer.

Maybe its not common but frequent enough.

Re: I decompiled the White House's new app

#64
post #32

Earlier quoted context omitted.

Aren't the banners for EU page visitors. I don't think there is a US law about this, is there?

And when the app links off to an EU site? Nothing prevents an EU user from using this app. There are a variety of Trump enthusiasts, though I suspect less than there are here in the US.

I think they just fine the entity doing business in the EU. If they don't do business there, I can't see any issues.

I'm not an attorney, but I don't find any cases that extend beyond that.

Re: I decompiled the White House's new app

#65
post #3

"An official United States government app is injecting CSS and JavaScript into third-party websites to strip away their cookie consent dialogs, GDPR banners, login gates, and paywalls." In their defense, this is the first thing the Trump admin has done that's unambiguously positive for ordinary people.

I too love it when US imperialism invades digital spaces, just ignore how the US treats people critical of its own government (not just referring to the Trump admin here) then yeah sure great.

Let me know when this can ignore malware/adware from US companies then I'll give accolades.

Re: I decompiled the White House's new app

#66

Earlier quoted context omitted.

Aren't the banners for EU page visitors. I don't think there is a US law about this, is there?

Some states have them. California has a similar one "Don't Sell My Personal Information."

I think the Supremacy Clause protects federal agencies but not sure. Also Privileges and Immunities, and Commerce clauses...

Re: I decompiled the White House's new app

#67

The argument regarding no certificate pinning seems to miss that just because I might be on a network that MITM's TLS traffic doesn't mean my device trusts the random CA used by the proxy. I'd just get a TLS error, right?

Not if someone can issue the certificate signed by the CA your phone trust. Imagine being in a cafe nearby, say, embassy of the certain north African country known for pervasive and wide espionage actions, which decides to hijack traffic in this cafe. Or imagine living in the country where almost all of the cabinet is literally (officially) being paid by the propaganda/lobbying body of such country. Or living int he…

> Imagine being in a cafe nearby, say, embassy of the certain north African country known for pervasive and wide espionage actions, which decides to hijack traffic in this cafe.

How would they get your phone to trust their CA? Connecting to a Wi-Fi network doesn’t change which CAs a device trusts.

Re: I decompiled the White House's new app

#68
post #24

Earlier quoted context omitted.

Ok, fair point. However, I would consider any MDM-enabled device fully "compromised" in the sense that the org can see and modify everything I do on it.

An MDM orga cannot install a trusted CA on non-supervised (company owned) devices. By default on BYOD these are untrusted and require manual trust. It also cannot see everything on your device - certainly not your email, notes or files, or app data.

If it is untrusted, you also won’t have a TLS connection be established based on that CA.

Re: I decompiled the White House's new app

#70
post #32

Earlier quoted context omitted.

And when the app links off to an EU site? Nothing prevents an EU user from using this app. There are a variety of Trump enthusiasts, though I suspect less than there are here in the US.

They conduct a pervasive, hidden, persistent user tracking not only without consent, looking at the analysis, but also stripping the user from a chance of declining tracking on other sites. I'm quite sure that's illegal.

Which federal law would be relevant here? I'm only aware of California and EU laws that might be. But, I'm fairly certain they don't apply to the US government because of several Constitutional and international laws superseding.

I'm not sure. If there is an attorney to answer that would be interesting.

Post reply on HN