#privacy
-
Reading a Caller-ID App That Forgot to Add Authentication
Dalil Arabi's backend has no authentication layer at all - grepping the decompiled app for any auth header comes back empty. Reverse lookups are anonymous, and note ownership is decided entirely on the client. A static teardown, and the single live test that would turn it from likely into proven.
-
No Login Required: Breaking Down NumberBook's Caller-ID API
NumberBook asks for your entire contact list, then answers reverse phone lookups through a backend that has no authentication, no rate limiting, and 'encrypts' its responses with a key that ships inside the app itself.