Earlier quoted context omitted.
[flagged]
> It’s hard to imagine a smug article like this dissecting a product of some other administration Did the other administration put a "fake news" and "report to ICE" and grifting link to their own social network in their apps? I feel like you are perhaps papering over a whole lot of general shittiness of this app that didn't exist in less amateur previous administrations that at least tried to follow the norms.
I decompiled the White House's new app
91–100 of 291 posts
Re: I decompiled the White House's new app
#92Earlier quoted context omitted.
Because there is a quadrillion trusted CAs in every device you might use. A good chunk of these CAs have been compromised at one point or another, and rogue certificates are sold in the dark market. Also any goverment can coerce a domiciled CA to issue certs for their needs.
That is a wild claim. I can't imagine that being correct given how that's been abused in the past https://www.eff.org/deeplinks/2011/08/iranian-man-middle-att...
China telecom regularly has BGP announcements that conflict with level3's ASNs.
Just as a hint in case you want to dig more into the topic, RIR data is publicly available, so you can verify yourself who the offenders are.
Also check out the Geedge leaked source code, which also implements TLS overrides and inspection on a country scale. A lot of countries are customers of Geedge's tech stack, especially in the Middle East.
Just sayin' it's more common than you're willing to acknowledge.
Re: I decompiled the White House's new app
#93A bit skeptical of how this article is written as it seems to be mostly written by AI. Out of curiosity, I downloaded the app and it doesn't request location permissions anywhere, despite the claims in the article. I've noticed Claude Code is happy to decompile APKs for you but isn't very good at doing reachability analysis or figuring out complex control flows. It will treat completely dead code as important as a co…
Re: I decompiled the White House's new app
#94Earlier quoted context omitted.
> It’s hard to imagine a smug article like this dissecting a product of some other administration Did the other administration put a "fake news" and "report to ICE" and grifting link to their own social network in their apps? I feel like you are perhaps papering over a whole lot of general shittiness of this app that didn't exist in less amateur previous administrations that at least tried to follow the norms.
[flagged]
Also I'd say the federal government's approach to ICE deportations is a little stronger than even the COVID measures.
Re: I decompiled the White House's new app
#95Re: I decompiled the White House's new app
#96[flagged]
Re: I decompiled the White House's new app
#97Earlier quoted context omitted.
He explicitly says he can't determine it, but that the location tracking as configured will turn on once the user grants consent. All true statements. How would you have written it differently
"If the user chooses to opt-in and grants location-tracking permission, the app is then, and only then, able to track the user's location?"
Re: I decompiled the White House's new app
#98Earlier quoted context omitted.
> It’s hard to imagine a smug article like this dissecting a product of some other administration Did the other administration put a "fake news" and "report to ICE" and grifting link to their own social network in their apps? I feel like you are perhaps papering over a whole lot of general shittiness of this app that didn't exist in less amateur previous administrations that at least tried to follow the norms.
[flagged]
The only case they cite of an actual intervention resulting seems... entirely legit?
> An adult entertainment club lost its liquor license after a dancer and others were seen not wearing masks, the state said.
People call 911 for goofy things, too.
Re: I decompiled the White House's new app
#99Earlier quoted context omitted.
Because there is a quadrillion trusted CAs in every device you might use. A good chunk of these CAs have been compromised at one point or another, and rogue certificates are sold in the dark market. Also any goverment can coerce a domiciled CA to issue certs for their needs.
That is a wild claim. I can't imagine that being correct given how that's been abused in the past https://www.eff.org/deeplinks/2011/08/iranian-man-middle-att...
https://support.apple.com/en-us/126047
The chances of zero of these CAs having been compromised by state-level actors seems… slim.
Do you trust "Hongkong Post Root CA 3" not to fuck with things?
Your link's from 2011; the US government was still in the trusted list until 2018. https://www.idmanagement.gov/implement/announcements/04_appl...
Re: I decompiled the White House's new app
#100[flagged]
Every default setup on every website and app for the last five or so years has been encouraging users to add pronouns, making it difficult to avoid it, even my iPhone asks me to add each person’s pronouns when I add a new contact. I don’t know why Siri needs to know that, but it’s there. There’s one website I use that won’t let you sign up as a contributor without “completing your profile”, which includes mandatory p…