This is kinda scary, because it's hard to protect against this attack method when you're already trusting some app.