this post was submitted on 24 May 2026
1 points (100.0% liked)

Technology

87575 readers
3749 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 3 years ago
MODERATORS
top 7 comments
sorted by: hot top controversial new old
[–] knobbysideup@sh.itjust.works 1 points 3 months ago* (last edited 3 months ago) (1 children)

This white house app?

https://thereallo.dev/blog/decompiling-the-white-house-app

The official White House Android app:

Injects JavaScript into every website you open through its in-app browser to hide cookie consent dialogs, GDPR banners, login walls, signup walls, upsell prompts, and paywalls.

Has a full GPS tracking pipeline compiled in that polls every 4.5 minutes in the foreground and 9.5 minutes in the background, syncing lat/lng/accuracy/timestamp to OneSignal's servers.

Loads JavaScript from a random person's GitHub Pages site (lonelycpp.github.io) for YouTube embeds. If that account is compromised, arbitrary code runs in the app's WebView.

Loads third-party JavaScript from Elfsight (elfsightcdn.com/platform.js) for social media widgets, with no sandboxing.

Sends email addresses to Mailchimp, images are served from Uploadcare, and a Truth Social embed is hardcoded with static CDN URLs. None of this is government infrastructure.

Has no certificate pinning. Standard Android trust management.

Ships with dev artifacts in production. A localhost URL, a developer IP (10.4.4.109), the Expo dev client, and an exported Compose PreviewActivity.

Profiles users extensively through OneSignal - tags, SMS numbers, cross-device aliases, outcome tracking, notification interaction logging, in-app message click tracking, and full user state observation.

[–] mriormro@lemmy.zip -1 points 3 months ago

Ahahahahahaha

[–] FauxPseudo@lemmy.world 1 points 3 months ago

That app just became a national security threat. It gives out information to a non-government server. It can be exploited by foreign agents.

Just a reminder to the president, this would include his own secret service detail and their location.

[–] baggachipz@sh.itjust.works 1 points 3 months ago (1 children)

HELLO EMPLOYEE, TODAY WE FIGHT THR WOKE LIBRULS. MAKE SURE YOU GET TO THE KID ROCK CONCERT AND MMA MATCH ON TIME. THANK YOU FOR YOUR ATTENTION TO THIS MATTER!!!

[–] MonkderVierte@lemmy.zip 1 points 3 months ago

The vibecoded one with blaring security holes?