> I could be mistaken, but TrustCor CA is company C. TrustCor (company B) is where rouge contractor allegedly added "malware", or in industry parlance, analytics software, to a product as part of work to instrument the app that never shipped publicly and thus never harmed users.
> Anyway I don't believe it's correct to say Company B that "put malware in" their app is the same as Company C that operates an above board CA.
You are mistaken. There is no Company C.
The company that put the malware in their app is MsgSafe.io, a "secure email" provider that advertises E2EE but doesn't actually provide E2EE. MsgSafe is owned by TrustCor. Again, this is something that Rachel readily and repeatedly admits in the email thread, for example in her 18 November email:
> Also, I will use "our company" when speaking of TrustCor (the CA operator) and MsgSafe (the email service).
MsgSafe may technically be a different company from Trustcor in the same sense that Google and Alphabet are technically different companies, but Rachel considers them both together to be "our company."
TrustCor/MsgSafe, Rachel's "our company," is Company A.
Company B is Measurement Systems. Measurement Systems is the company that provides the malware to app developers, not the company that put the malware in in their app. As quoted in my previous post, Rachel admits that TrustCor and Measurement Systems had the same investors. According to public records they still have the same investors. Rachel claims that the previous owners have since divested, but (1) this is not reflected by public records and (2) she is unable or unwilling to provide any documentation of it. Also as quoted in my previous post, Rachel admits that TrustCor/MsgSafe's app contained Measurement Systems' SDK.
> to a product as part of work to instrument the app that never shipped publicly and thus never harmed users.
This is false. The app, although in "beta," was available on the Play Store and linked from MsgSafe.io as well as publicly advertised from the MsgSafe.io twitter account.
> Furthermore, this entire thing is predicated on an allegation that because some piece of analytics malware appears unobfuscated in their app but obfuscated in others, they must have exclusive access to the source and therefore must be the authors. That's.. quite the leap. I can think of many other simple explanations for why the incorrect build of some software might appear in a software product.
No, it's not. There are various other pieces of evidence tying TrustCor/MsgSafe to Measurement Systems, including domain registrations and common investors.
> And I'm beginning to question whether this software the opportunistic researches found is actually even malware in the first place.
This, now, is truly absurd. The Measurement Systems' malware SDK captured and uploaded information including wifi router SSID and MAC, the phone number and email address associated with the device it's running on, the device IMEI, clipboard contents, and GPS locations [1]. There is no good-faith argument that can be made against it being malware.
[1] https://blog.appcensus.io/2022/04/06/the-curious-case-of-cou...