Post #4119624
2026-07-26 19:48 UTC
Replies (11)
-
@deFractal@infosec.exchange 2026-07-26 19:53
@briankrebs@infosec.exchange Considering that the Trump regime's actions have been more aligned with the strategy foreign policy interests of #China in general, and especially the #CCP in particular, than any other government principal's interests, I suppose it should not be too surprising if the #WhiteHouse app leaks information to #Huawei. #uspol
-
@TycoonTom@infosec.exchange 2026-07-26 20:06
@briankrebs@infosec.exchange Does the App also needs📱 GPS📡 🛰️ on & No VPN.📵 disabled?
-
@briankrebs@infosec.exchange 2026-07-26 20:31
BTW, this latest version of the White House app actually has one one reference to Huawei. Previous versions had them all over the place, including under network permissions https://www.virustotal.com/gui/file/7b9a5247ef81bff63598505efd95af8e1a36b7b3d0042aa62316f2b9b1dce039/details
-
@SuperMoosie@mastodon.au 2026-07-26 20:12
@briankrebs@infosec.exchange
-
@noplasticshower@infosec.exchange 2026-07-26 21:19
@briankrebs@infosec.exchange god those guys are idiots
-
@briankrebs@infosec.exchange 2026-07-26 20:18
I realize this is small potatoes compared to other dumb/actively harmful stuff this administration is doing, but the POTUS just got done telling the world that China interfered with the election he lost, and here he's mandating that govt workers install an app that has components referencing Huawei??
-
@ADHDruid@infosec.exchange 2026-07-26 22:39
@briankrebs@infosec.exchange Really dumb, but I believe most IDE > publish pipelines drop this in as Huawei isn’t permitted to use the same push notification infrastructure as most other Android versions. Not a defence, and it’s lazy development. But playing devils advocate you could argue Firebase is probably as risky if not more so, given what is on the other side of it. Might as well be “GitHub[dot]com/*”, it always makes me nervous. Still, the evergreen statement that SBoMs and people that care about them are a dying breed.
-
@n_dimension@infosec.exchange 2026-07-27 02:08
@briankrebs@infosec.exchange A full an exhaustive #infosec analysis (including the updated version) of the #Whitehouse app is here: https://www.atomic.computer/blog/white-house-app-security-analysis/ As a counterpoint, this security firm says "nothing to see here... because everything is shitty in mobile world" https://www.nowsecure.com/blog/2026/03/31/an-experts-perspective-on-the-white-house-app-putting-security-findings-in-context/ I am going with the 1st source, as it still has major designed-in anti-privacy/malware features.
-
@TurnipCannon@mstdn.ca 2026-07-26 19:50
@briankrebs@infosec.exchange A lot of that stuff is just thrown in by default by mobile development IDEs, and no-one removes them because they don't really understand what they're for and "don't want to break anything"
-
@sylvie@gabriel.havfruefestning.com 2026-07-26 19:52
@briankrebs@infosec.exchange Slopcoding to blame perhaps?
-
@JoergA@social.tchncs.de 2026-07-26 19:52
@briankrebs@infosec.exchange Just a guess: Maybe they distribute the same app also in the Huawei App store and want to use push messages with Huawei smartphones, too... which is of course inconsistent wuth the ban, but well. It's the White House 😉