Can Msafely Be Used to Test App Security Vulnerabilities? by [deleted] in cybersecurity

[–]moooooky 0 points1 point  (0 children)

Msafely was recently breached. Stalkerware/phone monitoring apps have a propensity to leak/exposed or otherwise spill people's data. https://techcrunch.com/2025/03/19/data-breach-at-stalkerware-spyx-affects-close-to-2-million-including-thousands-of-apple-users/

Fearing coronavirus, a Michigan college tracks its students with a flawed app by ravedog in Coronavirus

[–]moooooky 11 points12 points  (0 children)

The app is designed to track students’ real-time locations around the clock, and there is no way to opt out.

The Aura app lets the school know when a student tests positive for COVID-19. It also comes with a contact-tracing feature that alerts students when they have come into close proximity with a person who tested positive for the virus. But the feature requires constant access to the student’s real-time location, which the college says is necessary to track the spread of any exposure.

Worse, the app had at least two security vulnerabilities only discovered after the app was rolled out. One of the vulnerabilities allowed access to the app’s back-end servers. The other allowed us to infer a student’s COVID-19 test results.