Live data from Hacker News

We intercepted the White House app's network traffic

atomic.computer

71–80 of 85 posts

Re: We intercepted the White House app's network traffic

#71

43% (of the 158 3rd-party requests) is... google. youtube, fonts, and analytics. 55% if you include facebook and twitter. a government app shouldnt have crazy analytics and tracking and whatever. but i dont think loading google fonts or embedding youtube videos is really all that wild in the grand scheme of things. given the title, i was half expecting some sort of egregious list with, like, palantir and some ICE dom…

> given the title, i was half expecting some sort of egregious list with, like, palantir and some ICE domains or something. i dont like the app, but google? facebook? that is pretty boring.

Are ICE and Palantir forbidden from buying data from Google or Facebook?

This sounds like a smart way to own an app where you decide what you want to track and nobody is stopping you from getting the data you are phoning home. And you can launder it through normal tracking providers.

Re: We intercepted the White House app's network traffic

#72

Earlier quoted context omitted.

Just because an app embeds YouTube instead of creating their own video hosting solution that does not mean that does not mean that the app sucks.

I didn't mention anything about YouTube.

This thread is about how there are too many requests to third parties for the app. Half of them are for YouTube.

Re: We intercepted the White House app's network traffic

#73

43% (of the 158 3rd-party requests) is... google. youtube, fonts, and analytics. 55% if you include facebook and twitter. a government app shouldnt have crazy analytics and tracking and whatever. but i dont think loading google fonts or embedding youtube videos is really all that wild in the grand scheme of things. given the title, i was half expecting some sort of egregious list with, like, palantir and some ICE dom…

If you read through the article, you'll see that the author focuses more on the OneSignal and Elfsight requests. The generic third party requests to Google, YouTube, etc. presumably were included for completeness + transparency and aren't meant to be some damning evidence against the White House app.

Though if your comment is solely based off of the previous title alone, then fair enough.

Re: We intercepted the White House app's network traffic

#74
post #60
post #45

Earlier quoted context omitted.

Installing the CA requires jumping through some hoops, but yes, intercepting traffic for apps that don’t use cert pinning isn’t that difficult on iOS. Apps that do use cert pinning is a whole other matter, I’ve tried unsuccessfully a few times to inspect things like banking apps. Needs a rooted device at the minimum.

So I assume the white house app doesn’t do cert pinning Also looked into this a long time ago… could someone tell me how to do this with cert pinned apps ?

In general you can't without patching the app itself, statically or at runtime using something like Frida.

Re: We intercepted the White House app's network traffic

#75

Earlier quoted context omitted.

Despite all the sneed on display, it's currently #4 in the App Store (ahead of Threads, Gmail, and Google Maps) and #1 in News so they did something right. Personally, I want the most stringent CORS settings to read about his gold Sharpie pens.

> it's currently #4 in the App Store (ahead of Threads, Gmail, and Google Maps) and #1 in News so they did something right Not disagreeing. But why should its provenance force a higher standard? It’s a glorified news app, to my understanding. Is its breaching worse for national security than some weather app that had its moment in the sunlight?

Because it is at some level officially backed by the White House. That alone brings higher scrutiny.

Re: We intercepted the White House app's network traffic

#76
post #10

Earlier quoted context omitted.

I'm sure that HN's preferred app would be <5MB, and has zero third party SDKs or telemetry, but half a dozen SDKs and third party domains is basically most mass market apps these days. Is it bad? Yes, but the whitehouse isn't being egregiously bad, but "whitehouse app is bad, just like most other apps" isn't going to get clicks.

See gov.uk for a good example

For all our faults I am geniunely impressed by gov.uk. its not pretty, its not particularly fast, and its certainly not flashly, but I've never once not been able to find what I needed or have a flow not work.

Re: We intercepted the White House app's network traffic

#78

Earlier quoted context omitted.

I didn't mention anything about YouTube.

This thread is about how there are too many requests to third parties for the app. Half of them are for YouTube.

Even if we eliminate the YouTube half it's still too many.

Re: We intercepted the White House app's network traffic

#79
post #75

Earlier quoted context omitted.

> it's currently #4 in the App Store (ahead of Threads, Gmail, and Google Maps) and #1 in News so they did something right Not disagreeing. But why should its provenance force a higher standard? It’s a glorified news app, to my understanding. Is its breaching worse for national security than some weather app that had its moment in the sunlight?

Because it is at some level officially backed by the White House. That alone brings higher scrutiny.

That is a reassertion of the same claim. What is the reason why?
Post reply on HN