<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[So that White House App they just released?]]></title><description><![CDATA[<p>So that White House App they just released?   this won't come as a shock but hoo boy is it a treasure trove of terrible security and outright fraud to mine your data and track your location</p><p><a href="https://dmv.community/tags/WhiteHouse" rel="tag">#<span>WhiteHouse</span></a> <a href="https://dmv.community/tags/Trump" rel="tag">#<span>Trump</span></a> </p><p><a href="https://blog.thereallo.dev/blog/decompiling-the-white-house-app" rel="nofollow noopener"><span>https://</span><span>blog.thereallo.dev/blog/decomp</span><span>iling-the-white-house-app</span></a></p><p>The official White House Android app:</p><p>    Injects JavaScript into every website you open through its in-app browser to hide cookie consent dialogs, GDPR banners, login walls, signup walls, upsell prompts, and paywalls.</p><p>    Has a full GPS tracking pipeline compiled in that polls every 4.5 minutes in the foreground and 9.5 minutes in the background, syncing lat/lng/accuracy/timestamp to OneSignal's servers.</p><p>    Loads JavaScript from a random person's GitHub Pages site (lonelycpp.github.io) for YouTube embeds. If that account is compromised, arbitrary code runs in the app's WebView.</p><p>    Loads third-party JavaScript from Elfsight (elfsightcdn.com/platform.js) for social media widgets, with no sandboxing.</p><p>    Sends email addresses to Mailchimp, images are served from Uploadcare, and a Truth Social embed is hardcoded with static CDN URLs. None of this is government infrastructure.</p><p>    Has no certificate pinning. Standard Android trust management.</p><p>    Ships with dev artifacts in production. A localhost URL, a developer IP (10.4.4.109), the Expo dev client, and an exported Compose PreviewActivity.</p><p>    Profiles users extensively through OneSignal - tags, SMS numbers, cross-device aliases, outcome tracking, notification interaction logging, in-app message click tracking, and full user state observation.</p>]]></description><link>https://board.circlewithadot.net/topic/2244249d-38b8-45eb-81d2-d7eb4da3eaec/so-that-white-house-app-they-just-released</link><generator>RSS for Node</generator><lastBuildDate>Fri, 17 Apr 2026 17:37:18 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/2244249d-38b8-45eb-81d2-d7eb4da3eaec.rss" rel="self" type="application/rss+xml"/><pubDate>Sun, 29 Mar 2026 04:22:54 GMT</pubDate><ttl>60</ttl></channel></rss>