[flagged]
Every move Apple and Google are making on their platforms is about turning the devices we pay for into devices for the companies whose apps we install.
81–90 of 136 posts
[flagged]
Every move Apple and Google are making on their platforms is about turning the devices we pay for into devices for the companies whose apps we install.
[flagged]
Seems Meta’s (or at least Messenger’s) RE defense is quite lenient here. Should be trivial for them to drop IsUsingSandbox() from prod builds entirely, that’s before we get into advanced obfuscation techniques.
Meta's apps come with entire debug menus in production builds. The string that author found is likely part of such a menu.
https://www.facebook.com/whitehat/bugbounty-education/261571...
Earlier quoted context omitted.
Meta's apps come with entire debug menus in production builds. The string that author found is likely part of such a menu.
Their Android application in particular allows the participation in a developer program which allows access to one of these menus. Not available on macOS and iOS unfortunately!
You don't really need to do that if you want to intercept Meta apps traffic. https://www.facebook.com/whitehat/bugbounty-education/261571...
[flagged]
If you can convince someone to install a certificate to violate their privacy you can just block the network, forcing the user to flip the setting. This allow apps to be able to protect their user's privacy from nosy enterprise network administrators.
[flagged]
>I don't get why it has to be this hostile toward developers and why no option is offered to disable it. If you can convince someone to install a certificate to violate their privacy you can just block the network, forcing the user to flip the setting. This allow apps to be able to protect their user's privacy from nosy enterprise network administrators.
Earlier quoted context omitted.
>I don't get why it has to be this hostile toward developers and why no option is offered to disable it. If you can convince someone to install a certificate to violate their privacy you can just block the network, forcing the user to flip the setting. This allow apps to be able to protect their user's privacy from nosy enterprise network administrators.
I get it, but that's ultimately the user's choice.
Earlier quoted context omitted.
I get it, but that's ultimately the user's choice.
That line of thinking leads you to the path where users are free to install malware and give it all the capabilities it needs because the user chose to do so.
Your line of thinking is basically "think of the children".