Live data from Hacker News

Android may soon restrict on-device ADB

kitsumed.github.io

151–160 of 535 posts

Re: Android may soon restrict on-device ADB

#151

Earlier quoted context omitted.

Poland, all banks I know offer web portal. Linux, Firefox - works perfectly.

Follow up question: how many of those still let you log in and authorize transfers without relying on their mobile app as required second factor?

This is all inevitable direction over long period of time

What’s worrying is that noone protests about it

It doesn’t suprise me that corporations and governments want the laziest, most „protective” laws passed that extend their power. But why noone, absolutely noone puts some kind of resistance to it?

Government and citizens are at eternal conflict of interests. It has been this way and it will be this way forever.

Your job as a citizen is to make sure you have greatest amount of liberties

Noone will do it for you.

Re: Android may soon restrict on-device ADB

#153
post #145
post #119

Earlier quoted context omitted.

It seems to require the user to: 1. Enable Developer Mode by going to an obscure settings page and tapping the build number seven times 2. Enable USB ADB debugging in the Developer Options 3. Establish an actual USB ADB session 4. Enable TCP/IP ADB debugging in the Developer Options 5. Unknowingly download a malware app from the official Play Store 6. Blindly click "Yes" on the permission prompt. In other words: this…

> In other words: this is all but impossible to impact regular users, and it requires a particularly careless developer to be hit by it. Have you ever worked with someone who barely knows how to use a mobile phone? They will hand their phone over to someone they barely even know to do something they don't understand. They will follow instructions from a stranger over the phone, without understanding what the phone is…

Can we freaking sell them dumbphones, then, and stop destroying portable computers for everyone else with that excuse?

Which incidentally is often just a pretense for other motives?

If computers have suddenly become so dangerous for normal people, and they want smartphones nonetheless, add to them a dumb-mode encouraged at the initial setup, and requiring some third party assistance to turn it off once enabled..! (and forbid apps to change their behavior if it's not enabled)

Re: Android may soon restrict on-device ADB

#155
post #42

We need Linux on phones. Bank apps not needed as long as I can use browser. But do need some things like wireless cards, popular apps like Sonos and Spotify working.

Unfortunately many banks in the UK no longer offer a web portal or physical branches. I'd love to see legislation that mandated a functioning web experience for critical services like this (banking, utilities, etc) - otherwise it will continue to further entrench the current duopoly. (I suppose this is also an instance where I should do a better job of voting with my feet and supporting services that do offer this)

Huh? Why the hell would you use a bank that doesn't offer a web portal or have branches if there are banks that still do?!?!

I bank with HSBC in the UK and there's still branches (worldwide) and banking via web.

I assume you mean things like Starling and Monzo in this case? Banking with them is simply dangerous.

Re: Android may soon restrict on-device ADB

#156

Earlier quoted context omitted.

Hides memory leaks

Right, that too. But that's a reason to recommend regular reboots[0], not to force them, and "3 days of inactivity" is a suspiciously specific time that I also saw mentioned in Android settings somewhere the other day. -- [0] - Which I find deeply ironic, in that merely a decade ago, people would laugh at Windows with its "reboot after installs, reboot in case of problems" approach, and now frequent reboots are seen…

I have no issue restarting my iOS/Mac/Linux machines because the time to get back to doing fun or productive stuff is measured in seconds. And usually you only have to restart one time. Windows used to take ages, and often you’d reboot only find out that something else that requires a reboot only triggered because of the previous reboot, so you were sometimes in for 2-3 restarts.

It’s not like that anymore in my experience at least but the stigma stuck.

Re: Android may soon restrict on-device ADB

#157
When Google first announced sideloading restrictions, somebody told “but we have ADB”, and who disagreed with them was criticized harshly.

Now, I’m waiting for a workaround to enable ADB, so sideloading can be handled now, too.

Android is not more open that iOS for a very long time now. The trend will continue.

Again, this is not a technical problem (the mindset of Google), so technological solutions won’t help.

Re: Android may soon restrict on-device ADB

#158
post #153
post #145

Earlier quoted context omitted.

> In other words: this is all but impossible to impact regular users, and it requires a particularly careless developer to be hit by it. Have you ever worked with someone who barely knows how to use a mobile phone? They will hand their phone over to someone they barely even know to do something they don't understand. They will follow instructions from a stranger over the phone, without understanding what the phone is…

Can we freaking sell them dumbphones, then, and stop destroying portable computers for everyone else with that excuse? Which incidentally is often just a pretense for other motives? If computers have suddenly become so dangerous for normal people, and they want smartphones nonetheless, add to them a dumb-mode encouraged at the initial setup, and requiring some third party assistance to turn it off once enabled..! (an…

"Can we freaking sell them dumbphones"

Nothing is stopping the guy at Walmart or Tmobile from selling them dumbphones, or are you implying they are forced to?

Re: Android may soon restrict on-device ADB

#159
post #67

Earlier quoted context omitted.

Depends how you define a CVE. If owning and controlling your device is a CVE/bug then sure you need a tight box with anti tempering as well.

"An app can bypass OS security system with certain setting enabled" absolutely fits into CVEs. There's no "depends: on it. I love how quickly you all forget about security and privacy when it gives a chance to angrily rant.

I changed the sudo settings to not require a password.

Now an application on my computer can obtain root without user interaction.

Where is my CVE?

Re: Android may soon restrict on-device ADB

#160
post #147

Earlier quoted context omitted.

You haven't been able to connect to an android device on port 5555 for yeeears. Every time you enable adb/IP it generates a new random port, or you need to use the QR/PIN pairing thing. On top of needing to enable developer options, adb/IP, confirm the fingerprint.

Millions of Superboxes and various digital picture frames say different. https://synthient.com/blog/a-broken-system-fueling-botnets

Kimwolf exploits vulnerable Android Debug Bridge (ADB) services. Many low-cost TV boxes come "pre-infected" with proxy SDKs; Kimwolf then scans these residential proxy networks and exploits the devices within minutes as it propagates.

https://www.cloudflare.com/learning/ddos/glossary/aisuru-kim...

This is like saying that SSH is insecure because some device vendors install SSH, permitting root login with a default password of 'root'.

Post reply on HN