TRUMP’S WHITE HOUSE APP TRACKS USERS, TOTALLY COMPROMISES THEIR SECURITY
IT’S A SHAME, BECAUSE A GOOD WHITE HOUSE APP WOULD BE AMAZING ACROSS THE BOARD
And that’s a damn shame, really. Because just think about all the things that the app could provide! There could be a section where you could explore the entire structure’s history, room to room, president to president. Another for the grounds, not one anymore for the rose garden, and not one for the ballroom either, at least for the foreseeable future. But I guess when you want to spend ONE BILLION dollars on a ballroom, things like a secure White House app that doesn’t track users could slip thru the cracks. And no, not the cracks of the demolished ballroom.
Related:
WHITE HOUSE APP TRACKS USER GPS, LOADS OUTSIDE CODE, JAVASCRIPT, LACKS SSL CERTIFICATE PINNING
But a researcher detailed how much of a nightmare the White House app really is. It includes hidden GPS-tracking capabilities, weak security protections, and code loaded from an outside GitHub page. That’s pretty appalling, if we’re being honest. But there’s more, as the app also loads JavaScript from a random person’s GitHub site for YouTube embeds. Which means anyone’s phone could suddenly run foreign code from inside the app’s WebView. Oh! And there’s no SSL certificate pinning, which means that anyone using the White House app could have their traffic intercepted while using sus networks, public WiFi or proxies.
But there’s even more! The White House app also loads JavaScript and CSS into every page you visit in the in-app browser! That means no cookie consent dialogues, GDPR banners, any login walls, and paywalls. So who made this app? Someone really working for Russia or China? Because it’s that bad.


