My goodness what are they even planning to patent? Seald SDK? Ract native? Firestone? RSA? The app does nothing, LOL.
Testing a new encrypted messaging app's extraordinary claims
11–20 of 40 posts
Re: Testing a new encrypted messaging app's extraordinary claims
#12It seems these days if your data ends up on a server that's A-ok! With all the talk on HN about the "GDPR" it sure seems like an absolute failure - where's the QC from Google looking at the code and proactively doing something about the real, potential harm that can come from this? It really seems if you want to harvest user data you can whip together an app that looks and feels okay, but behind the scenes is designed to do nothing but collect your data for whatever nefarious purpose the developer has in mind - and this is all 100% legal and the chances are whoever was involved will not even get so much as a fine!
Now there's an app that openly collects user data and is publishing it as a matter of public record, consequences be damned.
Android and Google need to take responsibility here and use Play Protect to treat the app as harmful and to better shield users.
This is an excellent write-up and investigation which is something Google should be doing to expose the dangers of their own platforms - hacking together a few API's/SDK's to mass harvest user data is absolutely not okay. Frankly, they should be legally mandated to review these apps in depth, and be provided full, unobfuscated source code, along with a detailed network-map of all URL's the app accesses, API keys etc and should approve (similar to Apple) before Android allows it to be used. If you install it outside of the app-store a very strong warning should be in place to let users know of potential spy/malware
I also discovered this app is actually on the play store [1]! And the app data safety says "No data shared with third parties Learn more about how developers declare sharing". It's an absolute JOKE this is not being enforced by Google at all. Shame on them.
I believe Mozilla did an investigation and found most apps are outright LYING about their "data safety" so that feature is beyond useless when Google doesn't actively moderate it.
[1]: https://play.google.com/store/apps/details?id=com.conversoap...
Re: Testing a new encrypted messaging app's extraordinary claims
#13My goodness what are they even planning to patent? Seald SDK? Ract native? Firestone? RSA? The app does nothing, LOL.
Re: Testing a new encrypted messaging app's extraordinary claims
#14Re: Testing a new encrypted messaging app's extraordinary claims
#15Have you by chance looked at the new update? Not that anyone should ever use this app in the first place, but I'm curious whether the massive vulnerability you discovered was fixed.
Re: Testing a new encrypted messaging app's extraordinary claims
#16Re: Testing a new encrypted messaging app's extraordinary claims
#17Wow what a read. Best read I’ve had in months.
Re: Testing a new encrypted messaging app's extraordinary claims
#18Amazing. Have you by chance looked at the new update? Not that anyone should ever use this app in the first place, but I'm curious whether the massive vulnerability you discovered was fixed.
Which massive vulnerability in particular? You'll have to be more specific, haha.
I confirmed the Firestore collections had some kind of server-side security rules added before publishing the post.
Re: Testing a new encrypted messaging app's extraordinary claims
#19I wonder if there might be grounds for any users to sue based on the publishing of their personal data online and misrepresentation of the product and its security features.
Re: Testing a new encrypted messaging app's extraordinary claims
#20This is my absolute favourite kind of post on HN. It's got everything; intrigue, mystery, scandal and of course heavy on the technical side too. All packaged up in a compelling narrative.