<Thread> Hi @WikoMobile
! It's me...again... I would like to talk about your application called "System updates".
This application is sending your IMEI in clear text to a US server.
-
-
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
well, not a scandal, except if a forged ssl certificate is accepted.
-
Just the regular user root CA you can add in your Android settings. They don't seem to apply any sort of cert pinning for OTA updates.
-
i was thinking to a simple https hijack, without mmanipulating the phone
End of conversation
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.
)
- imei
- session number
- phone language

