“It’s advisable that you don’t install apps from non-trustworthy sources, ” Unpopular opinion but this is why I prefer walled garden apple for my family then alternative.
Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access
81–90 of 236 posts
Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access
#82This is another great chance to root your phone and take complete control of what you should rightly own.
And your chance to share this complete control with every installed app. Phones should be like desktop computers. You install an app, you give it access to everything your account can touch on the computer.
Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access
#83“It’s advisable that you don’t install apps from non-trustworthy sources, ” Unpopular opinion but this is why I prefer walled garden apple for my family then alternative.
And of course, "untrusted sources" is not the same as "all side-loading". I use sources to sideload from that I trust more than the average app developer.
Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access
#84Earlier quoted context omitted.
From the article “However, on Aug. 15, a Google researcher discovered a flaw with the installer, which can let a separate app on your phone hijack what the software actually downloads.” So a separate app can hijack what another app does. That means the sandbox is broken.
their installer downloaded the game into shared storage. They should at least have known that access to shared storage is not sandboxed and should have been verifying what they are about to install instead of trusting no other app would maliciously place an apk where their installer did expect it to be... ideally they would never have used shared storage at all... that said, the sandboxing and permission system worke…
If an app can trash your user data the permission system is useless.
Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access
#85This is another great chance to root your phone and take complete control of what you should rightly own.
Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access
#86Earlier quoted context omitted.
And your chance to share this complete control with every installed app. Phones should be like desktop computers. You install an app, you give it access to everything your account can touch on the computer.
Android has one of the best security models and sandboxing for apps. It's based around SELinux.
You mean a security model that misses the fact that the kernel cannot be updated and relies on a "sanboxing" solution that doesn't bother limiting kernel attack surface. No, I don't think they even had a security model in mind, a threat model or anything beyond random ad hoc ideas. And if they did some thinking, they would not have chosen SELinux either, as it's not a decent solution to anything, it's more like a solution to "we must to do something, this is something, we must do this".
Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access
#87Earlier quoted context omitted.
> How many consumers across the world would actually be at risk… We don't know, because we don't know who bought it and how widespread they deployed it.
Oh come on. We can never know with 100% certainty. But they already know the company is selling to authorities, not random people. Can't we make an educated guess here?
Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access
#88> However, if you install an application from an untrusted source, attackers can take advantage of that. Attackers can also take advantage of the bug if they pair it with vulnerabilities in the Chrome browser to render content. So, you have to sideload an app or from some other source. Is it unreasonable to say don't do that? How common is it anyway? I work with IT folks and only a few ever seem to load outside the P…
I've been using LineageOS on my phones for a couple of years now, recently reinstalled and made the decision to not install the Play Store... and am totally happy with it! I get most of my stuff from F-Droid and some software vendors provide APKs straight from their websites and whatever is Play Store exclusive, I simply don't use. It was going really well, at least until recently, when here in Germany they started i…
[1] https://f-droid.org/en/package/com.github.yeriomin.yalpstore...
Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access
#89After the recent disclosures about Apple vulnerabilities, I've seen a lot of (unwarranted, in my opinion) criticism from HN of Project Zero, specifically the accusation of non-Google bias. For those who hold this position, does this affect your stance?
Will there be a large analysis how frequently this was exploited and so forth? How about a public Google blog post around this?
Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access
#90Earlier quoted context omitted.
I've been using LineageOS on my phones for a couple of years now, recently reinstalled and made the decision to not install the Play Store... and am totally happy with it! I get most of my stuff from F-Droid and some software vendors provide APKs straight from their websites and whatever is Play Store exclusive, I simply don't use. It was going really well, at least until recently, when here in Germany they started i…
Use YALP [1] or Aurora [2] (both are on FDroid) to get the APK's for your banking apps. These apps This is what I do for the Swedish electronic ID app, it has worked for years and hopefully will continue to do so. [1] https://f-droid.org/en/package/com.github.yeriomin.yalpstore... [2] https://f-droid.org/en/packages/com.aurora.store/
Since it was a banking app, I got the APK of many different sites/programs and compared the hashes, and one of the programs had definitely tampered with the APK, but I can't remember which.
Since I left Aurora on my phone, they seemed to have passed on untouched APKs, but don't take my word for it.
EDIT: Also, this voids me of any "warranties" my bank would offer me, so I'm really not going down that path. Really, the only correct thing would be for the bank to offer the APK on their site, but I'd probably have to wait until the government forces this to happen (if ever).