I have been on the other side of the equation professionally speaking.
I think we mostly agree.
The auditors were certainly not malicious, they can simply only see what they can observe.
Appealing to authority without explaining the caveats is risky to do and disingenuous to people who need to take security very seriously right now.
A potential vector or matter of concern does not mean there is a compromise. Without evidence of a hack or compromise you just have the idea that something could happen.
The app model in general has meant that we have given up tremendous amounts of privacy and security in general for the sake of connivence.
If I were the developer of this app I would’ve approached things from the inception with the question of “How do I get people to trust me who absolutely should not trust me?”
That said, it is always easier to tear down than it is to build.
If I were an at risk individual I would likely opt to use the app myself assuming I could share general location instead of specific location. In areas like LA there is likely a lot of data flowing in that would not help a malicious actor if the location is not specific.
I have been on the other side of the equation professionally speaking.
I think we mostly agree.
The auditors were certainly not malicious, they can simply only see what they can observe.
Appealing to authority without explaining the caveats is risky to do and disingenuous to people who need to take security very seriously right now.
A potential vector or matter of concern does not mean there is a compromise. Without evidence of a hack or compromise you just have the idea that something could happen.
The app model in general has meant that we have given up tremendous amounts of privacy and security in general for the sake of connivence.
If I were the developer of this app I would’ve approached things from the inception with the question of “How do I get people to trust me who absolutely should not trust me?”
That said, it is always easier to tear down than it is to build.
If I were an at risk individual I would likely opt to use the app myself assuming I could share general location instead of specific location. In areas like LA there is likely a lot of data flowing in that would not help a malicious actor if the location is not specific.