Live data from Hacker News

Yes, Android 14 still allows modification of system certificates

g1a55er.net

81–89 of 89 posts

Re: Yes, Android 14 still allows modification of system certificates

#81

Earlier quoted context omitted.

> Elsewhere in this thread, people are saying that you can’t protect people from themselves… but Apple seem to be doing a good job of it Precisely my point. I think there are benefits to both locked-down devices and open devices, and both are desirable. If Android is transitioning towards more constrained-by-default, (a) that's smart given it's working so well for their largest competition, and (b) it opens the field…

> it opens the field wider for the truly open-stack phones to gain users. Win-win. Microsoft couldn't break into this market for billions of dollars. Open phones breaking in because android becomes more locked down is a complete fantasy. What do you do when oppressive governments insist that your now constrained environment implement some of their suggestions with the alternative to compliance being your local yokels…

In the event that fantasy scenario plays out, there's no winners period; if Android complied, they'd still get to sell, and if they didn't they'd end up on the black market alongside the Pinephones.

None of this category of openness matters if the government turns to oppression.

Re: Yes, Android 14 still allows modification of system certificates

#82
post #46
post #43

Earlier quoted context omitted.

As much as I want to agree with you, I can't blame Google here. Corporate security departments have bought into the idea that mobile is different and you can't trust the user with root. Google has little choice but to provide them with the tools to detect root access.

Why? If Google didn't implement it, what would they do?

Not allow their cards in Google Wallet, and or only support web access to their functions.

Some of the entities that want it do have pull.

Re: Yes, Android 14 still allows modification of system certificates

#83

Earlier quoted context omitted.

I think that really overstates the risk scenario. If we're going to descend into hyperbole, let's turn it around... If a free and open device is so important, won't some smart hacker always come along to build one? I'd rather my grandmother have an easy life and trust that Neo will be around to save the technorati eventually than make life easier on people who already know how to hack things they want to behave diffe…

> If a free and open device is so important, won't some smart hacker always come along to build one? This just isn't how the universe works at all. We both grew up in the era roughly analogous to the early era of flight with 100 bad designs competing for most incompetent and are now moving into the an era of commercial jets and here you are arguing that planes wont make a difference in war. If you build an ecosystem…

I mean... Netflix is clearly part of the larger control scheme in the scenario where the country is fascist, even as it is currently constructed. For everyone else, there'll be BitTorrent through VPN and good ol' fashion swapping of hard drives of bootlegs.

Re: Yes, Android 14 still allows modification of system certificates

#84

Earlier quoted context omitted.

Do you have any kind of docs on doing this. I want to get some stats from a game I'm playing and think that the server fudges the number to keep whales happy. Any quality documentation on how to do this would be great.

https://httptoolkit.com/blog/frida-certificate-pinning/ has a detailed blog on it. Frida receives updates all the time, so the exact commands and scripts don't always work with the latest version, but you can start there. As a concept, Frida works by running a gadget on the phone (as root, or as part of an app) and a client on another device (or the same device, I suppose, if you're using a terminal emulator on Andro…

Thank you for taking the time to reply. This has put me on the right path.

Re: Yes, Android 14 still allows modification of system certificates

#85
post #63

Earlier quoted context omitted.

Apple honestly did a pretty good job. You can sideload your own code with a free developer account, but you have to jump through some minor hoops to get “developer” mode set on your account (I went through this to get the tvOS 17 beta). And the app signing expires in 7 days, so it’s really painful for a normal user who isn’t actually developing and testing an app to use like that for a long term thing. If you want mo…

> Apple honestly did a pretty good job. They did. Over here, there are regular news articles and warnings from the government as yet more Android users get conned into installing fake banking app APKs that let attackers steal all their money. It’s always the same news article and the same warning – only Android users affected. Elsewhere in this thread, people are saying that you can’t protect people from themselves……

> Over here, there are regular news articles and warnings from the government as yet more Android users get conned into installing fake banking app APKs that let attackers steal all their money. It’s always the same news article and the same warning – only Android users affected.

Like clockwork, here’s today’s article:

> The victims would then contact the “sellers” via the platforms or messaging app WhatsApp. Following this, the “sellers” would send a uniform resource locator (URL) link for the victims to download an Android Package Kit (APK) file, an app created for Android’s operating system.

https://www.channelnewsasia.com/singapore/android-malware-sc...

Re: Yes, Android 14 still allows modification of system certificates

#86

Earlier quoted context omitted.

Do you have any kind of docs on doing this. I want to get some stats from a game I'm playing and think that the server fudges the number to keep whales happy. Any quality documentation on how to do this would be great.

https://httptoolkit.com/blog/frida-certificate-pinning/ has a detailed blog on it. Frida receives updates all the time, so the exact commands and scripts don't always work with the latest version, but you can start there. As a concept, Frida works by running a gadget on the phone (as root, or as part of an app) and a client on another device (or the same device, I suppose, if you're using a terminal emulator on Andro…

I've now confirmed that if you pay money for the game, you -automatically- get exactly 12% more damage than someone who hasn't, and it appears to drop 1% a day over time.

Not much I can do with that data, other than sleep in comfort knowing that its the case.

Re: Yes, Android 14 still allows modification of system certificates

#87

Earlier quoted context omitted.

https://httptoolkit.com/blog/frida-certificate-pinning/ has a detailed blog on it. Frida receives updates all the time, so the exact commands and scripts don't always work with the latest version, but you can start there. As a concept, Frida works by running a gadget on the phone (as root, or as part of an app) and a client on another device (or the same device, I suppose, if you're using a terminal emulator on Andro…

I've now confirmed that if you pay money for the game, you -automatically- get exactly 12% more damage than someone who hasn't, and it appears to drop 1% a day over time. Not much I can do with that data, other than sleep in comfort knowing that its the case.

Perhaps it's worth writing a quick blog about it? If this system wasn't documented before you purchase anything, you may even be able to get the attention of certain game review websites.

There are plenty of pay2win games out there, but if the game doesn't tell you that paying will give you an unfair advantage /or what advantage you're getting, exactly) I'd consider that worth reporting on, especially if the game has a decently large following!

Re: Yes, Android 14 still allows modification of system certificates

#88

Earlier quoted context omitted.

> Apple honestly did a pretty good job. They did. Over here, there are regular news articles and warnings from the government as yet more Android users get conned into installing fake banking app APKs that let attackers steal all their money. It’s always the same news article and the same warning – only Android users affected. Elsewhere in this thread, people are saying that you can’t protect people from themselves……

> Over here, there are regular news articles and warnings from the government as yet more Android users get conned into installing fake banking app APKs that let attackers steal all their money. It’s always the same news article and the same warning – only Android users affected. Like clockwork, here’s today’s article: > The victims would then contact the “sellers” via the platforms or messaging app WhatsApp. Followi…

Like clockwork, here’s today’s article:

> DBS, UOB become latest banks to restrict access if unverified apps are found on customers' phones

> They are the latest banks in Singapore to do so – after OCBC and Citibank – amid a spate of malware scams targeting users of Android devices.

> DBS said on Tuesday (Sep 26) that its new anti-malware tool for Android phones seeks to prevent scammers from fraudulently logging into customers’ accounts by restricting app access if it detects potential risks.

> “For now, it appears (that) scam vulnerability by malware is a major issue and therefore, it is appropriate to strike the balance in favour of protection for now. If this changes over time, then we may be willing to revisit the situation,” he said.

https://www.channelnewsasia.com/singapore/dbs-uob-anti-scam-...

Re: Yes, Android 14 still allows modification of system certificates

#89

Earlier quoted context omitted.

> Over here, there are regular news articles and warnings from the government as yet more Android users get conned into installing fake banking app APKs that let attackers steal all their money. It’s always the same news article and the same warning – only Android users affected. Like clockwork, here’s today’s article: > The victims would then contact the “sellers” via the platforms or messaging app WhatsApp. Followi…

Like clockwork, here’s today’s article: > DBS, UOB become latest banks to restrict access if unverified apps are found on customers' phones > They are the latest banks in Singapore to do so – after OCBC and Citibank – amid a spate of malware scams targeting users of Android devices. > DBS said on Tuesday (Sep 26) that its new anti-malware tool for Android phones seeks to prevent scammers from fraudulently logging int…

Like clockwork, here’s today’s article:

> The elderly man, who wanted to be known only as Mr Loh, lost about $70,000 to scammers who siphoned money from his DBS and POSB credit card and bank accounts after infecting his Android phone with malware.

> The seller texted Mr Loh on WhatsApp and instructed him through voice messages to download a third-party app called Grab&Go on his phone.

https://www.straitstimes.com/singapore/74-year-old-man-loses...

Post reply on HN