Live data from Hacker News

Android may soon restrict on-device ADB

kitsumed.github.io

391–400 of 536 posts

Re: Android may soon restrict on-device ADB

#391
post #367

Earlier quoted context omitted.

"Security" is just a scourge on software at this point. It means 2FA on every trivial site, being logged out every few hours for no good reason, having to fuck with settings and type "disable sandbox" to run an agent in YOLO mode which still won't work over mobile, being unable to install an unsigned extension at all in firefox (not behind a setting, literally impossible - you have to get Firefox Developer Edition),…

> 2FA on every trivial site But it helps against account sharing, err I mean they make database leaks irrelevant except for private info of the customer, err I mean that we can now send more mail to the customer about new AI features without risking they think it is phishing, err I mean this is the easiest measure for the auditor findings so since we implemented this we don't need to fix all the crappy internal api a…

> But it helps against account sharing

This is actually a feature, very common in real world, that security maximalists keep insisting is a bug.

Re: Android may soon restrict on-device ADB

#392

Google is going the Apple route. When will we get the year of the Linux Phone?

The apps that are the reason some people use smartphones at all — bank apps — require Google services and remote attestation that runs in an environment with more privileges than the OS kernel. Otherwise everyone interested would just unlock their bootloader and use a ROM with all the asinine restrictions removed.

Re: Android may soon restrict on-device ADB

#393
I think one attack vector this sort of overlooks in the first point, regular users installing malicious apps.

My elderly mum has an Android phone. She is not very tech-literate.

She might see a full page ad "your phone has a virus, clean it now", or somehow end up on something like it (e.g. a scam email).

She then dutifully clicks on it, which prompts to download an apk. The webpage provides clear instructions for how to install the just-downloaded APK.

That APK (app) then walks her though enabling ADB, so it can "clean the phone". The app gave very good instructions (customized to reflect the UI that her device manufacturer would use), so she manages to click through to the hidden settings menu and enable ADB.

The app can now exfiltrate all sorts of data, without needing any scary permissions prompt which will tell the user what is being accessed.

I think this sort of pattern is very real, and many users are being affected by these scams. And undoubtedly more android users than iOS ones.

Finding a balance that allows power users like me to use my device as I wish, and protecting regular users, is quite hard. I think the solution Google came up with of requiring a 24 hour wait, + some extra scary warnings, for unsigned apps is a step in the right direction, it helps less tech literate users avoid scams, and power users just have to be patient for 24h. But of course it's still not satisfactory for everyone, mum might still get scammed, and power users get annoyed at it.

Re: Android may soon restrict on-device ADB

#394
post #341

Earlier quoted context omitted.

Then maybe the best course of action is Google adding a warning before enabling certain settings that help normies avoid these attacks. Along the lines of "Are you being asked to do this by someone else? Be cautious, as your device could become compromised."

its ridiculous how many people will ignore the warnings and relay the security challenge/solution to the attacker. "we will never ask for this over the phone" takes second place to: "we will send/save you money/time if you make it convenient" dress it up to taste like developer needs, and you can hook the newbies.

> "we will never ask for this over the phone" takes second place to:

Doesn't help that the banks then do, in fact, call you, and ask for this over the phone.

Re: Android may soon restrict on-device ADB

#395

I think one attack vector this sort of overlooks in the first point, regular users installing malicious apps. My elderly mum has an Android phone. She is not very tech-literate. She might see a full page ad "your phone has a virus, clean it now", or somehow end up on something like it (e.g. a scam email). She then dutifully clicks on it, which prompts to download an apk. The webpage provides clear instructions for ho…

Your post switched half-way from "this hypothetical app your mum might hypothetically install" to "this apparently real app doing these specific things". Which way is it? Are you describing an actual threat in the wild, or just speculating about possibility?

FWIW, similar kinds of attacks is exactly why side-loading apps is about to require a reboot and 24 hour cooldown. Which you mention at the end. It sucks, but it's a decent compromise; power users like me will just do the dance and pick the "indefinite" option the moment they unpack their new phone, and rest of the people will never even know about it until they're half-way through being scammed.

I personally don't believe doing anything more in this direction is warranted.

Re: Android may soon restrict on-device ADB

#396

Earlier quoted context omitted.

"Security" is just a scourge on software at this point. It means 2FA on every trivial site, being logged out every few hours for no good reason, having to fuck with settings and type "disable sandbox" to run an agent in YOLO mode which still won't work over mobile, being unable to install an unsigned extension at all in firefox (not behind a setting, literally impossible - you have to get Firefox Developer Edition),…

IT has always been a spectrum with security at one end and convenience at the other. There is no recent trend that’s changed that. That’s just how life works.

Right, but security maximalist are running the asylum now, and they try to sell everyone the lie that more security is possible.

Also, the original sin: framing it as "security" vs. "convenience". It's not. The other end of the spectrum is utility - as in, maximally secure computing device is an inert rock. More security means less utility - reduced functionality, constrained capability, reasonable use cases no longer possible. It means manual process where previously automation or batching was possible. It means more electricity, more compute, more money spent.

It means more user time and therefore more human lives wasted.

This ultimate non-renewable resource is what we're trading off when we accept even more security. This trade-off needs to be respected much more than it is.

Re: Android may soon restrict on-device ADB

#397
post #263

Earlier quoted context omitted.

Sometimes attacks happen from users being instructed to enable settings in order to achieve something regardless of whether you’d expect them to have a reason to use the setting

I think that these victims are paid by the likes of Google to create a precedent. It is unbelievable stupid scheme to fall to.

While I certainly think we should not be taking features away from people just because there exist people who will let themselves be social-engineered through arbitrary hoops, don't go creating wild conspiracy theories to explain something that supports much simpler explanations instead.

It's easy enough to imagine that Google is trying to fix something they see as a problem, and not caring about the developer case rather than specifically seeking to destroy it.

When Apple fixed security issues that allowed for jailbreaking, they weren't doing it specifically because people use it for jailbreaking, they were doing it because it was a security issue.

We should have 100% control of our own devices. But we should have it by design, in a fashion that makes sure that we control them rather than other people.

Re: Android may soon restrict on-device ADB

#398
post #242

Earlier quoted context omitted.

It seems to me a lot of Google lately is to block things they don't like using ways that only look like side effects. The introduction of Manifest V3 API in Chrome for extensions, and disabling Manifest V2 for security reasons. It just so happened that ad blockers were made incompatible with the Manifest V3 API. It's a little blatant considering this came right around the time that YouTube began showing warning messa…

I still can’t believe that an advertising company was able to effectively neuter ad/content blocking for 80% of the world under the guise of wholly invented safety issues.

They wouldn't have been able to if people didn't use a browser created by an advertising company.

Re: Android may soon restrict on-device ADB

#399

Earlier quoted context omitted.

I think expert users on HN seriously downplay the ability and willingness of "regular users" to do very stupid things on their devices. If grandma wants that app that gives her a beautiful horse as a lock screen image, she will follow every one of those six steps that the malware HorseLockScreen app developer presents to her. She will tap a button that has a skull and crossbones icon, that says "tapping this will dra…

On multiple occasions I had trouble getting people to accept a self signed cert to show them something on a local webpage. It seems that elderly nowadays are super vary of any hacking or scams. YMMV.

Excellent, security education is working. The correct response to someone trying to convince you to accept a self-signed certificate is extreme skepticism; don't undermine people's understanding of good security practices.

Re: Android may soon restrict on-device ADB

#400

Earlier quoted context omitted.

That's why they're going to fully locked down devices.

So, they will use other vectors, like convincing people to transfer money. Set up fake webshop. Run scams through online marketplaces, etc. The solution is not to make everything impossible. The solution is to educate people.

Until they will look indistinguishable from regular businesses doing regular marketing, advertising, and "value engineering" bullshit. It's xkcd://810 of the advertising industry, I guess - all the scammers doing the legitimate, sanctioned scamming like one big happy family, instead of unfairly competing.
Post reply on HN