3 ms·
> HTTP with their own half-baked hardcoded AES key in app for sending credit card info. You mean, no TLS, JavaScript crypto and credit card info? Are there no
by qb45 9y ago
> HTTP with their own half-baked hardcoded AES key in app for sending credit card info.
You mean, no TLS, JavaScript crypto and credit card info?
Are there no authorities to report that kind of garbage? No certification they are supposed to pass? I would research that angle first before hacking. It doesn't take any reversing to realize everyone can pwn you on a public WiFi.
Otherwise, at the very least use tor...