FINDING · EVALUATION

The SAT Móvil app (Mexico's official tax service, 1M+ downloads) consistently fetches its 'Chat' page over cleartext HTTP, exposing citizen ID numbers (CURP, RFC), passwords, and tax documents to any in-path attacker. None of the four major Latin American telco apps (MiTelcel, MiTigo, MiClaro, MiMovistar) implement HSTS on SMS-delivered external links, making all of them uniformly vulnerable to SSL strip downgrade attacks.

From 2024-kujath-analyzingAnalyzing Prominent Mobile Apps in Latin America · §7.2, Table 3 · 2024 · Free and Open Communications on the Internet

Implications

Tags

censors
generic
techniques
dpimiddlebox-interference

Extracted by claude-sonnet-4-6 — review before relying.