Bridgefy's "protest app" is full of backdoors and vulnerabilities

in #waiviodev4 years ago


Reverse engineering specialists at the University of London have performed a full analysis of the code of this NOT free application and published a non-consoling report for many (, which reveals numerous loopholes , for attackers, contributing to:
🔻Deanonymization of users
🔻Decipher and read private messages
🔻Build social graphs of user interactions both in real time and post factum
🔻Pretending to be other netizens
🔻Perform active attacker-in-the-middle attacks, which allow an attacker not only to read messages, but also to interfere with them.
🔻Complete disconnection of the selected user from the network