Thanks for sharing! Entertaining read.
The app uses rot(4) to obscure data, includes a debug link with the collected data, and has the Fluzo service api key hardcoded, among other gems.
The app uses rot(4) to obscure data, includes a debug link with the collected data, and has the Fluzo service api key hardcoded, among other gems.
Your hardcoded credential could then become a cryptographic key that you could rotate on app upfates.
I am not sure how many apps actually go through this trouble.