news.volyx.in

I decompiled the White House's new app (thereallo.dev)

668 points by amarcheschi · 156 days ago · 259 comments on HN

Article summary

The official White House Android app has been decompiled, revealing features such as a cookie and paywall bypass injector, GPS tracking every 4.5 minutes, and loading JavaScript from a GitHub Pages site. The app also profiles users extensively through OneSignal, tracking tags, SMS numbers, and cross-device aliases. The app's security and data collection practices have raised concerns. The app's use of third-party services, including Mailchimp and Uploadcare, has also been noted.

Main themes

  • App Security
  • Data Collection
  • Government Surveillance
  • User Profiling
  • Supply Chain Risks
  • Privacy Concerns

What commenters say

  • The app's tracking features and data collection practices are standard for many commercial apps, but are particularly concerning given the app's origins and potential for government surveillance.
  • The use of arbitrary JavaScript from a random GitHub user's account poses a significant security risk, as it could be modified to run malicious code.
  • Some commenters argue that the app's features, such as the cookie and paywall bypass injector, could be seen as a positive development for users, improving their experience and reducing annoyance.
  • Others disagree, arguing that the app's actions undermine user consent and the ability to opt-out of tracking, and that the government should not be engaging in such practices.
  • The app's compliance with relevant laws and regulations, such as the GDPR, is uncertain and may be subject to jurisdictional and constitutional limitations.
  • The development of the app may have been outsourced to a consultancy, which used a standard app architecture that included location tracking code and other features without fully considering the implications.
  • Some commenters note that similar apps and services have been developed in other contexts, such as the Polish covid quarantine app, and that reuse of existing code and architectures is not uncommon.
  • The lack of transparency and oversight in the app's development and deployment has raised concerns about accountability and the potential for abuse of user data.