>All extracted information is bundled as a ZIP file, without applying any protection like a
password. The ZIP file is then sent via an HTTP POST request to
http://192.168.43.1:8080/. This shows that not only no transport security (e.g. https://) is
in place, but also that an internal IP address is used.
Unless they're expecting a MITM from the police network (or wherever they use this app) why is no https a problem?
>BXAQ uses the default icon for Android apps, which means there is no attempt at being covert or discreet about it.
...or maybe they didn't put an icon because it's optional and unnecessary for what essentially is an internal app.
I mean really they are not trying to be unbiased or anything about the analysis.