An app that helps users track ICE agents
I’ve seen this app panned by folks who don’t like that it’s iOS only and the legitimate concerns they have about anonymity with android, even if you’re on graphene or the like.
Their concerns regarding push notifications on android are legitimate, they’re basically saying “we don’t want to collect data on our users and android would necessarily require this for push notifications to work”.
unexposedhazard@discuss.tchncs.de 1 day ago
Stop recommending this shit ffs. Its super suspicous, closed source and intransparent in its operation. If the feds raid this guys house and push a malicous version, all the users are fucked. This is not a good app to recommend.
prettybunnys@sh.itjust.works 1 day ago
Do you believe the independent security analysis of the app to be malicious then?
cubism_pitta@lemmy.world 1 day ago
When you do business with companies in certain industries not only is your software audited but your entire development process, business processes and staff are audited.
It’s not unreasonable to question a closed source application for something like this as one version was audited, but what about the next?
How do we know their dev process hasn’t been compromised? Or the person building app wasn’t compromised? Or that the entire thing was not compromised from the start?
Likewise, an audit without full access to code isn’t useless, but hiding behavior from an audit and for a certain period of time would be straight forward. How do you know there is not a dormant command and control system in the app that will cause it to behave in a malicious manner after a set amount of time or after a specific push notification is received?
I am not saying this is present, just that Audits like this are only able to catch what they can observe and the existence of an audit does not mean to blindly trust something
Having the App be open source would be a big step towards providing the transparency needed to address these concerns users would not have to trust anyone and can confirm the builds on the app stores match what is on their Git.
I am not pointing this out to jump on the “Don’t use this app” bandwagon. I am pointing it out to say that there are reasons to be skeptical of these sorts of things in our current political climate.
Remember Sabu and LulzSec