▲ 548 ▼ I Decompiled the White House's New App— The app has a cookie/paywall bypass injector, tracks your GPS every 4.5 minutes, and loads JavaScript from some guy's GitHub Pages. (blog.thereallo.dev) submitted 4 months ago* (last edited 4 months ago) by Beep@lemmus.org to c/technology@lemmy.world 60 comments fedilink hide all child comments Social Media Lobsters; Hacker News; Reddit. What Is This App? It's a React Native app built with Expo (SDK 54), running on the Hermes JavaScript engine. The backend is WordPress with a custom REST API. The app was built by an entity called "forty-five-press" according to the Expo config.
[–] artyom@piefed.social 4 points 4 months ago (1 child) ELI5? permalink fedilink source hideshow 2 child comments replies: [–] KairuByte@lemmy.dbzer0.com 13 points 4 months ago Likely nothing illegal. Quite a bit of bad dev habits. Some concerning security fuck ups, including pulling in JavaScript from a server they don’t control. Injecting JavaScript to subvert cookie/gdpr/login/etc popups on third party sites. Just generally bad things to do, especially in a government provided app. permalink fedilink source parent
[–] KairuByte@lemmy.dbzer0.com 13 points 4 months ago Likely nothing illegal. Quite a bit of bad dev habits. Some concerning security fuck ups, including pulling in JavaScript from a server they don’t control. Injecting JavaScript to subvert cookie/gdpr/login/etc popups on third party sites. Just generally bad things to do, especially in a government provided app. permalink fedilink source parent