<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[https:&#x2F;&#x2F;blog.thereallo.dev&#x2F;blog&#x2F;decompiling-the-white-house-app]]></title><description><![CDATA[<p><a href="https://blog.thereallo.dev/blog/decompiling-the-white-house-app" rel="nofollow noopener"><span>https://</span><span>blog.thereallo.dev/blog/decomp</span><span>iling-the-white-house-app</span></a></p><p>Wowy wow wow wow! I’m sure none of y’all planned on downloading the malware from the Mango, but just in case, DO NOT.  It will: </p><p>Inject JavaScript into every website you open</p><p>Has a full GPS tracking pipeline always on.</p><p>Loads JavaScript from a random person's GitHub Pages site (lonelycpp.github.io) for YouTube embeds.</p><p>Loads third-party JavaScript from Elfsight (elfsightcdn.com/platform.js) for social media widgets, with no sandboxing.</p><p>Sends email addresses to Mailchimp, images are served from Uploadcare, and a Truth Social embed is hardcoded with static CDN URLs. None of this is government infrastructure.</p><p>Has no certificate pinning.</p><p>Ships with dev artifacts in production.</p><p>Profiles users extensively through OneSignal - tags, SMS numbers, cross-device aliases, outcome tracking, notification interaction logging, in-app message click tracking, and full user state observation</p><p><a href="https://mefi.social/tags/infosec" rel="tag">#<span>infosec</span></a> <a href="https://mefi.social/tags/whitehouse" rel="tag">#<span>whitehouse</span></a> <a href="https://mefi.social/tags/malware" rel="tag">#<span>malware</span></a> <a href="https://mefi.social/tags/StupidestTimeline" rel="tag">#<span>StupidestTimeline</span></a></p>]]></description><link>https://board.circlewithadot.net/topic/950bfbc2-f005-49be-9802-21efc96ea2a8/https-blog.thereallo.dev-blog-decompiling-the-white-house-app</link><generator>RSS for Node</generator><lastBuildDate>Fri, 17 Apr 2026 17:37:16 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/950bfbc2-f005-49be-9802-21efc96ea2a8.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 30 Mar 2026 22:31:22 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to https:&#x2F;&#x2F;blog.thereallo.dev&#x2F;blog&#x2F;decompiling-the-white-house-app on Tue, 31 Mar 2026 03:01:59 GMT]]></title><description><![CDATA[<p><span><a href="/user/missconstrue%40mefi.social">@<span>MissConstrue</span></a></span> <br />it doesn't even considered installing on GraphineOS, saying my phone is incompatible</p>]]></description><link>https://board.circlewithadot.net/post/https://hachyderm.io/users/Retreival9096/statuses/116321558175957432</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://hachyderm.io/users/Retreival9096/statuses/116321558175957432</guid><dc:creator><![CDATA[retreival9096@hachyderm.io]]></dc:creator><pubDate>Tue, 31 Mar 2026 03:01:59 GMT</pubDate></item><item><title><![CDATA[Reply to https:&#x2F;&#x2F;blog.thereallo.dev&#x2F;blog&#x2F;decompiling-the-white-house-app on Tue, 31 Mar 2026 02:11:17 GMT]]></title><description><![CDATA[<p><span><a href="/user/gbargoud%40masto.nyc">@<span>gbargoud</span></a></span> <span><a href="/user/missconstrue%40mefi.social">@<span>MissConstrue</span></a></span> Hopes and wishes aren't illegal after all.</p><p>At least not yet...</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/nazokiyoubinbou/statuses/116321358781134136</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/nazokiyoubinbou/statuses/116321358781134136</guid><dc:creator><![CDATA[nazokiyoubinbou@mastodon.social]]></dc:creator><pubDate>Tue, 31 Mar 2026 02:11:17 GMT</pubDate></item><item><title><![CDATA[Reply to https:&#x2F;&#x2F;blog.thereallo.dev&#x2F;blog&#x2F;decompiling-the-white-house-app on Tue, 31 Mar 2026 02:05:55 GMT]]></title><description><![CDATA[<p><span><a href="/user/nazokiyoubinbou%40mastodon.social">@<span>nazokiyoubinbou</span></a></span> <span><a href="/user/missconstrue%40mefi.social">@<span>MissConstrue</span></a></span> </p><p>It would be, especially if they also take down Mecha Hitler's Child Porn O Matic while they're consistently enforcing their rules.</p>]]></description><link>https://board.circlewithadot.net/post/https://masto.nyc/users/gbargoud/statuses/116321337724413273</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://masto.nyc/users/gbargoud/statuses/116321337724413273</guid><dc:creator><![CDATA[gbargoud@masto.nyc]]></dc:creator><pubDate>Tue, 31 Mar 2026 02:05:55 GMT</pubDate></item><item><title><![CDATA[Reply to https:&#x2F;&#x2F;blog.thereallo.dev&#x2F;blog&#x2F;decompiling-the-white-house-app on Tue, 31 Mar 2026 02:02:49 GMT]]></title><description><![CDATA[<p><span><a href="/user/gbargoud%40masto.nyc">@<span>gbargoud</span></a></span> <span><a href="/user/missconstrue%40mefi.social">@<span>MissConstrue</span></a></span> Same, but wouldn't it be amazing if they actually did uphold the standards they enforce on other devs just this once?</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/nazokiyoubinbou/statuses/116321325544652516</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/nazokiyoubinbou/statuses/116321325544652516</guid><dc:creator><![CDATA[nazokiyoubinbou@mastodon.social]]></dc:creator><pubDate>Tue, 31 Mar 2026 02:02:49 GMT</pubDate></item><item><title><![CDATA[Reply to https:&#x2F;&#x2F;blog.thereallo.dev&#x2F;blog&#x2F;decompiling-the-white-house-app on Tue, 31 Mar 2026 02:01:57 GMT]]></title><description><![CDATA[<p><span><a href="/user/nazokiyoubinbou%40mastodon.social">@<span>nazokiyoubinbou</span></a></span> <span><a href="/user/missconstrue%40mefi.social">@<span>MissConstrue</span></a></span> </p><p>Should definitely be reported but I wouldn't hold my breath on any company that made a  donation to the ballroom doing anything other than metaphorically lick his taint.</p>]]></description><link>https://board.circlewithadot.net/post/https://masto.nyc/users/gbargoud/statuses/116321322101618871</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://masto.nyc/users/gbargoud/statuses/116321322101618871</guid><dc:creator><![CDATA[gbargoud@masto.nyc]]></dc:creator><pubDate>Tue, 31 Mar 2026 02:01:57 GMT</pubDate></item><item><title><![CDATA[Reply to https:&#x2F;&#x2F;blog.thereallo.dev&#x2F;blog&#x2F;decompiling-the-white-house-app on Tue, 31 Mar 2026 00:24:07 GMT]]></title><description><![CDATA[<p><span><a href="/user/missconstrue%40mefi.social">@<span>MissConstrue</span></a></span> <span><a href="/user/mediopocillo%40boriken.social">@<span>mediopocillo</span></a></span> These days, sadly, it's a given.</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/nazokiyoubinbou/statuses/116320937436453277</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/nazokiyoubinbou/statuses/116320937436453277</guid><dc:creator><![CDATA[nazokiyoubinbou@mastodon.social]]></dc:creator><pubDate>Tue, 31 Mar 2026 00:24:07 GMT</pubDate></item><item><title><![CDATA[Reply to https:&#x2F;&#x2F;blog.thereallo.dev&#x2F;blog&#x2F;decompiling-the-white-house-app on Tue, 31 Mar 2026 00:23:39 GMT]]></title><description><![CDATA[<p><span><a href="/user/nazokiyoubinbou%40mastodon.social">@<span>nazokiyoubinbou</span></a></span> <span><a href="/user/mediopocillo%40boriken.social">@<span>mediopocillo</span></a></span> I hadn't even thought about contact contamination until y'all mentioned it.</p>]]></description><link>https://board.circlewithadot.net/post/https://mefi.social/users/MissConstrue/statuses/116320935570963025</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mefi.social/users/MissConstrue/statuses/116320935570963025</guid><dc:creator><![CDATA[missconstrue@mefi.social]]></dc:creator><pubDate>Tue, 31 Mar 2026 00:23:39 GMT</pubDate></item><item><title><![CDATA[Reply to https:&#x2F;&#x2F;blog.thereallo.dev&#x2F;blog&#x2F;decompiling-the-white-house-app on Tue, 31 Mar 2026 00:18:40 GMT]]></title><description><![CDATA[<p><span><a href="/user/mediopocillo%40boriken.social">@<span>mediopocillo</span></a></span> Unknown at current, I believe.</p>]]></description><link>https://board.circlewithadot.net/post/https://mefi.social/users/MissConstrue/statuses/116320915951857205</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mefi.social/users/MissConstrue/statuses/116320915951857205</guid><dc:creator><![CDATA[missconstrue@mefi.social]]></dc:creator><pubDate>Tue, 31 Mar 2026 00:18:40 GMT</pubDate></item><item><title><![CDATA[Reply to https:&#x2F;&#x2F;blog.thereallo.dev&#x2F;blog&#x2F;decompiling-the-white-house-app on Mon, 30 Mar 2026 23:42:58 GMT]]></title><description><![CDATA[<p><span><a href="/user/mediopocillo%40boriken.social">@<span>mediopocillo</span></a></span> <span><a href="/user/missconstrue%40mefi.social">@<span>MissConstrue</span></a></span> That's the fun thing about this stuff.  With access to contacts, anything and everything they've saved in that contact is shared with whoever they grant access to and there is absolutely nothing said contact can do about it.  (Isn't it *GREAT*??)</p><p>It's down to how much they actually put in there what is gotten, so make sure they don't have anything like your social media profiles or etc saved in there because that's all you can do from your end is ask those people.</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/nazokiyoubinbou/statuses/116320775626367304</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/nazokiyoubinbou/statuses/116320775626367304</guid><dc:creator><![CDATA[nazokiyoubinbou@mastodon.social]]></dc:creator><pubDate>Mon, 30 Mar 2026 23:42:58 GMT</pubDate></item><item><title><![CDATA[Reply to https:&#x2F;&#x2F;blog.thereallo.dev&#x2F;blog&#x2F;decompiling-the-white-house-app on Mon, 30 Mar 2026 23:41:03 GMT]]></title><description><![CDATA[<p><span><a href="/user/missconstrue%40mefi.social">@<span>MissConstrue</span></a></span> It sounds like people should report the app then.</p><p>Imagine how much the orange one would explode if the app were pulled from the store for being in violation of basic rules (and, uh, laws by the look of it...  Despite what the article says, I'm pretty sure some of it is surely illegal.)</p><p>Just *imagine* what it would do to his puny ego...</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/nazokiyoubinbou/statuses/116320768054778271</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/nazokiyoubinbou/statuses/116320768054778271</guid><dc:creator><![CDATA[nazokiyoubinbou@mastodon.social]]></dc:creator><pubDate>Mon, 30 Mar 2026 23:41:03 GMT</pubDate></item><item><title><![CDATA[Reply to https:&#x2F;&#x2F;blog.thereallo.dev&#x2F;blog&#x2F;decompiling-the-white-house-app on Mon, 30 Mar 2026 23:08:31 GMT]]></title><description><![CDATA[<p><span><a href="/user/missconstrue%40mefi.social">@<span>MissConstrue</span></a></span> <br />Even if I don't some of my cousins might. What happens if I'm in their contacts? <br /><a href="https://boriken.social/tags/infosec" rel="tag">#<span>infosec</span></a> <a href="https://boriken.social/tags/malware" rel="tag">#<span>malware</span></a> <a href="https://boriken.social/tags/StupidestTimeline" rel="tag">#<span>StupidestTimeline</span></a></p>]]></description><link>https://board.circlewithadot.net/post/https://boriken.social/users/mediopocillo/statuses/116320640141720225</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://boriken.social/users/mediopocillo/statuses/116320640141720225</guid><dc:creator><![CDATA[mediopocillo@boriken.social]]></dc:creator><pubDate>Mon, 30 Mar 2026 23:08:31 GMT</pubDate></item></channel></rss>