Bridgefy's "protest app" is full of backdoors and vulnerabilities

in #waiviodev4 years ago

image

Reverse engineering specialists at the University of London have performed a full analysis of the code of this NOT free application and published a non-consoling report for many (https://martinralbrecht.files.wordpress.com/2020/08/bridgefy-abridged.pdf), which reveals numerous loopholes , for attackers, contributing to:
🔻Deanonymization of users
🔻Decipher and read private messages
🔻Build social graphs of user interactions both in real time and post factum
🔻Pretending to be other netizens
🔻Perform active attacker-in-the-middle attacks, which allow an attacker not only to read messages, but also to interfere with them.
🔻Complete disconnection of the selected user from the network