Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. https://blog.thereallo.dev/blog/decompiling-the-white-house-app

https://blog.thereallo.dev/blog/decompiling-the-white-house-app

Scheduled Pinned Locked Moved Uncategorized
infosecwhitehousemalwarestupidesttimeli
12 Posts 5 Posters 3 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • missconstrue@mefi.socialM This user is from outside of this forum
    missconstrue@mefi.socialM This user is from outside of this forum
    missconstrue@mefi.social
    wrote last edited by
    #1

    https://blog.thereallo.dev/blog/decompiling-the-white-house-app

    Wowy wow wow wow! I’m sure none of y’all planned on downloading the malware from the Mango, but just in case, DO NOT. It will:

    Inject JavaScript into every website you open

    Has a full GPS tracking pipeline always on.

    Loads JavaScript from a random person's GitHub Pages site (lonelycpp.github.io) for YouTube embeds.

    Loads third-party JavaScript from Elfsight (elfsightcdn.com/platform.js) for social media widgets, with no sandboxing.

    Sends email addresses to Mailchimp, images are served from Uploadcare, and a Truth Social embed is hardcoded with static CDN URLs. None of this is government infrastructure.

    Has no certificate pinning.

    Ships with dev artifacts in production.

    Profiles users extensively through OneSignal - tags, SMS numbers, cross-device aliases, outcome tracking, notification interaction logging, in-app message click tracking, and full user state observation

    #infosec #whitehouse #malware #StupidestTimeline

    mediopocillo@boriken.socialM nazokiyoubinbou@mastodon.socialN retreival9096@hachyderm.ioR 3 Replies Last reply
    1
    0
    • missconstrue@mefi.socialM missconstrue@mefi.social

      https://blog.thereallo.dev/blog/decompiling-the-white-house-app

      Wowy wow wow wow! I’m sure none of y’all planned on downloading the malware from the Mango, but just in case, DO NOT. It will:

      Inject JavaScript into every website you open

      Has a full GPS tracking pipeline always on.

      Loads JavaScript from a random person's GitHub Pages site (lonelycpp.github.io) for YouTube embeds.

      Loads third-party JavaScript from Elfsight (elfsightcdn.com/platform.js) for social media widgets, with no sandboxing.

      Sends email addresses to Mailchimp, images are served from Uploadcare, and a Truth Social embed is hardcoded with static CDN URLs. None of this is government infrastructure.

      Has no certificate pinning.

      Ships with dev artifacts in production.

      Profiles users extensively through OneSignal - tags, SMS numbers, cross-device aliases, outcome tracking, notification interaction logging, in-app message click tracking, and full user state observation

      #infosec #whitehouse #malware #StupidestTimeline

      mediopocillo@boriken.socialM This user is from outside of this forum
      mediopocillo@boriken.socialM This user is from outside of this forum
      mediopocillo@boriken.social
      wrote last edited by
      #2

      @MissConstrue
      Even if I don't some of my cousins might. What happens if I'm in their contacts?
      #infosec #malware #StupidestTimeline

      nazokiyoubinbou@mastodon.socialN missconstrue@mefi.socialM 2 Replies Last reply
      0
      • missconstrue@mefi.socialM missconstrue@mefi.social

        https://blog.thereallo.dev/blog/decompiling-the-white-house-app

        Wowy wow wow wow! I’m sure none of y’all planned on downloading the malware from the Mango, but just in case, DO NOT. It will:

        Inject JavaScript into every website you open

        Has a full GPS tracking pipeline always on.

        Loads JavaScript from a random person's GitHub Pages site (lonelycpp.github.io) for YouTube embeds.

        Loads third-party JavaScript from Elfsight (elfsightcdn.com/platform.js) for social media widgets, with no sandboxing.

        Sends email addresses to Mailchimp, images are served from Uploadcare, and a Truth Social embed is hardcoded with static CDN URLs. None of this is government infrastructure.

        Has no certificate pinning.

        Ships with dev artifacts in production.

        Profiles users extensively through OneSignal - tags, SMS numbers, cross-device aliases, outcome tracking, notification interaction logging, in-app message click tracking, and full user state observation

        #infosec #whitehouse #malware #StupidestTimeline

        nazokiyoubinbou@mastodon.socialN This user is from outside of this forum
        nazokiyoubinbou@mastodon.socialN This user is from outside of this forum
        nazokiyoubinbou@mastodon.social
        wrote last edited by
        #3

        @MissConstrue It sounds like people should report the app then.

        Imagine how much the orange one would explode if the app were pulled from the store for being in violation of basic rules (and, uh, laws by the look of it... Despite what the article says, I'm pretty sure some of it is surely illegal.)

        Just *imagine* what it would do to his puny ego...

        gbargoud@masto.nycG 1 Reply Last reply
        0
        • mediopocillo@boriken.socialM mediopocillo@boriken.social

          @MissConstrue
          Even if I don't some of my cousins might. What happens if I'm in their contacts?
          #infosec #malware #StupidestTimeline

          nazokiyoubinbou@mastodon.socialN This user is from outside of this forum
          nazokiyoubinbou@mastodon.socialN This user is from outside of this forum
          nazokiyoubinbou@mastodon.social
          wrote last edited by
          #4

          @mediopocillo @MissConstrue That's the fun thing about this stuff. With access to contacts, anything and everything they've saved in that contact is shared with whoever they grant access to and there is absolutely nothing said contact can do about it. (Isn't it *GREAT*??)

          It's down to how much they actually put in there what is gotten, so make sure they don't have anything like your social media profiles or etc saved in there because that's all you can do from your end is ask those people.

          missconstrue@mefi.socialM 1 Reply Last reply
          0
          • mediopocillo@boriken.socialM mediopocillo@boriken.social

            @MissConstrue
            Even if I don't some of my cousins might. What happens if I'm in their contacts?
            #infosec #malware #StupidestTimeline

            missconstrue@mefi.socialM This user is from outside of this forum
            missconstrue@mefi.socialM This user is from outside of this forum
            missconstrue@mefi.social
            wrote last edited by
            #5

            @mediopocillo Unknown at current, I believe.

            1 Reply Last reply
            0
            • nazokiyoubinbou@mastodon.socialN nazokiyoubinbou@mastodon.social

              @mediopocillo @MissConstrue That's the fun thing about this stuff. With access to contacts, anything and everything they've saved in that contact is shared with whoever they grant access to and there is absolutely nothing said contact can do about it. (Isn't it *GREAT*??)

              It's down to how much they actually put in there what is gotten, so make sure they don't have anything like your social media profiles or etc saved in there because that's all you can do from your end is ask those people.

              missconstrue@mefi.socialM This user is from outside of this forum
              missconstrue@mefi.socialM This user is from outside of this forum
              missconstrue@mefi.social
              wrote last edited by
              #6

              @nazokiyoubinbou @mediopocillo I hadn't even thought about contact contamination until y'all mentioned it.

              nazokiyoubinbou@mastodon.socialN 1 Reply Last reply
              0
              • missconstrue@mefi.socialM missconstrue@mefi.social

                @nazokiyoubinbou @mediopocillo I hadn't even thought about contact contamination until y'all mentioned it.

                nazokiyoubinbou@mastodon.socialN This user is from outside of this forum
                nazokiyoubinbou@mastodon.socialN This user is from outside of this forum
                nazokiyoubinbou@mastodon.social
                wrote last edited by
                #7

                @MissConstrue @mediopocillo These days, sadly, it's a given.

                1 Reply Last reply
                0
                • nazokiyoubinbou@mastodon.socialN nazokiyoubinbou@mastodon.social

                  @MissConstrue It sounds like people should report the app then.

                  Imagine how much the orange one would explode if the app were pulled from the store for being in violation of basic rules (and, uh, laws by the look of it... Despite what the article says, I'm pretty sure some of it is surely illegal.)

                  Just *imagine* what it would do to his puny ego...

                  gbargoud@masto.nycG This user is from outside of this forum
                  gbargoud@masto.nycG This user is from outside of this forum
                  gbargoud@masto.nyc
                  wrote last edited by
                  #8

                  @nazokiyoubinbou @MissConstrue

                  Should definitely be reported but I wouldn't hold my breath on any company that made a donation to the ballroom doing anything other than metaphorically lick his taint.

                  nazokiyoubinbou@mastodon.socialN 1 Reply Last reply
                  0
                  • gbargoud@masto.nycG gbargoud@masto.nyc

                    @nazokiyoubinbou @MissConstrue

                    Should definitely be reported but I wouldn't hold my breath on any company that made a donation to the ballroom doing anything other than metaphorically lick his taint.

                    nazokiyoubinbou@mastodon.socialN This user is from outside of this forum
                    nazokiyoubinbou@mastodon.socialN This user is from outside of this forum
                    nazokiyoubinbou@mastodon.social
                    wrote last edited by
                    #9

                    @gbargoud @MissConstrue Same, but wouldn't it be amazing if they actually did uphold the standards they enforce on other devs just this once?

                    gbargoud@masto.nycG 1 Reply Last reply
                    0
                    • nazokiyoubinbou@mastodon.socialN nazokiyoubinbou@mastodon.social

                      @gbargoud @MissConstrue Same, but wouldn't it be amazing if they actually did uphold the standards they enforce on other devs just this once?

                      gbargoud@masto.nycG This user is from outside of this forum
                      gbargoud@masto.nycG This user is from outside of this forum
                      gbargoud@masto.nyc
                      wrote last edited by
                      #10

                      @nazokiyoubinbou @MissConstrue

                      It would be, especially if they also take down Mecha Hitler's Child Porn O Matic while they're consistently enforcing their rules.

                      nazokiyoubinbou@mastodon.socialN 1 Reply Last reply
                      0
                      • gbargoud@masto.nycG gbargoud@masto.nyc

                        @nazokiyoubinbou @MissConstrue

                        It would be, especially if they also take down Mecha Hitler's Child Porn O Matic while they're consistently enforcing their rules.

                        nazokiyoubinbou@mastodon.socialN This user is from outside of this forum
                        nazokiyoubinbou@mastodon.socialN This user is from outside of this forum
                        nazokiyoubinbou@mastodon.social
                        wrote last edited by
                        #11

                        @gbargoud @MissConstrue Hopes and wishes aren't illegal after all.

                        At least not yet...

                        1 Reply Last reply
                        0
                        • missconstrue@mefi.socialM missconstrue@mefi.social

                          https://blog.thereallo.dev/blog/decompiling-the-white-house-app

                          Wowy wow wow wow! I’m sure none of y’all planned on downloading the malware from the Mango, but just in case, DO NOT. It will:

                          Inject JavaScript into every website you open

                          Has a full GPS tracking pipeline always on.

                          Loads JavaScript from a random person's GitHub Pages site (lonelycpp.github.io) for YouTube embeds.

                          Loads third-party JavaScript from Elfsight (elfsightcdn.com/platform.js) for social media widgets, with no sandboxing.

                          Sends email addresses to Mailchimp, images are served from Uploadcare, and a Truth Social embed is hardcoded with static CDN URLs. None of this is government infrastructure.

                          Has no certificate pinning.

                          Ships with dev artifacts in production.

                          Profiles users extensively through OneSignal - tags, SMS numbers, cross-device aliases, outcome tracking, notification interaction logging, in-app message click tracking, and full user state observation

                          #infosec #whitehouse #malware #StupidestTimeline

                          retreival9096@hachyderm.ioR This user is from outside of this forum
                          retreival9096@hachyderm.ioR This user is from outside of this forum
                          retreival9096@hachyderm.io
                          wrote last edited by
                          #12

                          @MissConstrue
                          it doesn't even considered installing on GraphineOS, saying my phone is incompatible

                          1 Reply Last reply
                          0
                          • R relay@relay.mycrowd.ca shared this topic
                          Reply
                          • Reply as topic
                          Log in to reply
                          • Oldest to Newest
                          • Newest to Oldest
                          • Most Votes


                          • Login

                          • Login or register to search.
                          • First post
                            Last post
                          0
                          • Categories
                          • Recent
                          • Tags
                          • Popular
                          • World
                          • Users
                          • Groups