3 ms·
I'm not sure that "sheesh" is an appropriate response. It's perfectly valid for an app to reply on the security of its own storage space, and isolation from ot
by scarybeast 10y ago
I'm not sure that "sheesh" is an appropriate response.
It's perfectly valid for an app to reply on the security of its own storage space, and isolation from other apps, and drive encryption services of the platform. These are the guarantees provided by the underlying OS, and if they are broken, all bets are off.
And what would you do differently? Any effort you put in here is going to cost you complexity and only likely provide security through obscurity. Fundamentally, the app has the authority to unlock and start the car. And a root exploit fundamentally has power over the app. This doesn't change even if you put the "key" material into hardware storage. Or maybe you could add an in-app password to encrypt the Tesla password? This is nasty UX, and the root exploit can still wait around for a moment when the password is provided.
If there's any take away here, it is regarding Android. If you want a secure Android phone, choose it carefully. Very few Android phones keep up with the Google automatic security patch schedule. You may want one that does, such as a Pixel.
- leephillips 10y agoThat's a reasonable reply. I think my comment was hasty, made after skimming the article and not thinking about it too deeply.