1 nota · última: 24 Sep 2026
The post shows how the app’s point authorization can be abused by intercepting HTTPS traffic and replacing the PIN flow with beacon data broadcast openly over BLE.