If an app tries to detect that I have root or a non-stock OS, I will give it a 1-star review on Google Play 100% of the time. Everyone who has a rooted device should do this.
Trusting clients is probably a security flaw
131–140 of 150 posts
Re: Trusting clients is probably a security flaw
#132Earlier quoted context omitted.
Is it not the same for computers most of the apps data is accessible by all the apps. Mobile OS came from the paradigm of the past and as the way we use our phones change so do the way how mobile os work. For a long time Android devs have wanted to obfuscate the disk from the user like iOS does but have faced push back from users and developers so in the end they created a permission where an app needs to ask permiss…
Definitely the same for computers. LOTS of software rely on saving data on "secret" locations for shareware-style trials. macOS for one has been asking to allow access to specific folders. Other OSs are possibly starting to do the same, but it used to be a free-for-all.
Older software tended to be less obnoxious about it. I have never had a desktop app refuse to run for this sort of reason.
Desktop software installers do not claim to offer this security. Mobile OSes claim to be sandboxed so your expectations are different.
The sorts of applications you install are different too. Many mobile apps are things you would do using a web browser on a desktop. They should therefore be locked down the way webapps are.
Re: Trusting clients is probably a security flaw
#133Earlier quoted context omitted.
Sure, but all the interesting data is stored in a subtree that mostly won't even show on that list. In fact, there doesn't seem to be a way for a user of non-rooted phone to view this data. This sucks.
Do you mean Android/data? This is accessible on a non-rooted device using Marc apps & software's "Files" https://play.google.com/store/apps/details?id=com.marc.files (an easily accessible shortcut to the native Android file manager).
Re: Trusting clients is probably a security flaw
#134Earlier quoted context omitted.
It has certainly been locked down a bit. This makes easily backing up all your data using some techniques harder/impossible. I can't include podcasts in the backup I do via rsync via termux anymore, unless I switch to an app that uses a shared storage area instead, as termux can not longer read app directories only its own and shared storage. You have to rely on each app that used app-local storage to have its own ba…
That's doesn't make sense either - not an android iser or dev but shouldn't there be a system level backup interface. Even if its storing the app-local storage as an opaque blob with a label?
It is somewhat disjointed.
When I last changed phones, between phones from the same manufacturer both running recent Android versions, the "copy apps, settings, and data" process didn't include all app data either so I need to take extra steps.
I don't think there will be any big push to address the matter, because for the vat majority of users it isn't a big issue: most of their data is synched to various services anyway and that which isn't wouldn't be particularly missed if lost. There are very few app dealing with important data that are local-only.
Re: Trusting clients is probably a security flaw
#135Earlier quoted context omitted.
That's doesn't make sense either - not an android iser or dev but shouldn't there be a system level backup interface. Even if its storing the app-local storage as an opaque blob with a label?
Sounds logical, but it doesn't seem to be the case. The backup options are "Photos/Videos" "phone data" and "both". I don't think phone data includes all app-local data. Contacts, calendar entries, and such, get synced but that isn't due to a global backup process that is the Google apps syncing with your Google account. Other apps could do that with the right integrations, but not all have the option and either have…
From what I can tell, Google intentionally broke Android’s backup subsystem in order to force people on to their non-E2E encrypted cloud storage.
It makes me sad that, in practice, Android somehow manages to give people less control over their devices than iOS.
Re: Trusting clients is probably a security flaw
#136If an app tries to detect that I have root or a non-stock OS, I will give it a 1-star review on Google Play 100% of the time. Everyone who has a rooted device should do this.
Sadly almost every mobile bank app in my country does this.
Re: Trusting clients is probably a security flaw
#137Earlier quoted context omitted.
Do you happen to remember which bus company this was? Is there any article you can link me too as I’m quite interested in reading some more on it.
I think it was Arriva. Defineitely one that operated in Manchester st the time. Cannot find a link.
Re: Trusting clients is probably a security flaw
#138Earlier quoted context omitted.
This sort of things happens a lot. A few years ago a British bus company put certificates in the app to sign tickets. The HSBC UK app will not run if you have any apps installed from outside play store. I cannot log into the website without the app. Luckily all I have with them is a lightly used credit card with a low limit so I have just stopped using it and rely on paper statement. I find it disturbing that any app…
The HSBC app runs fine on my rooted phone with a few magisk plugins and 5 marketplaces installed and a ton of sideloaded apps.
Re: Trusting clients is probably a security flaw
#139This is like the fifth article I've read about the McDonald's app not having any sort of server-side validation. How do they keep getting this wrong???
This sort of things happens a lot. A few years ago a British bus company put certificates in the app to sign tickets. The HSBC UK app will not run if you have any apps installed from outside play store. I cannot log into the website without the app. Luckily all I have with them is a lightly used credit card with a low limit so I have just stopped using it and rely on paper statement. I find it disturbing that any app…
I travel a lot and I would benefit from opening a "global money" account. However this requires the app, so I've never done it.
If they ever drop support for the physical authentication calculator, I will move to a different bank that doesn't require an app. Which is increasingly difficult these days.