Impersonating users of 'protest' app Bridgefy was as simple as sniffing Bluetooth handshakes for identifiers


Nice: a "secure" app which clearly has put zero thought into security.

plaintext sender and receiver addresses?

The crypto sigs is a bit more understandable - running those packages on low end cell phones is trickier than an iPhone only crowd.

Nonetheless, the pattern seems much more Zoom than Signal.

