4 ms·
> They could backdoor the process isolation and poke around at Signal memory if they felt like it. Actual question: are google services not apps that run on an
by thinkloop 10y ago
> They could backdoor the process isolation and poke around at Signal memory if they felt like it.
Actual question: are google services not apps that run on android similar to other apps, within confined environments?
- arghwhat 10y agoYes, it is isolated with interaction through IPC and intents, although Google Play Services have a lot of permissions, it is a normal "app". To communicate with it, you use a Google-provided, obfuscated library which potentially could be malicious. However, the "real backdoor" mentioned is in a component that is loaded dynamically when Signal prepares a MapView. The dynamic load means that Google can change what is loaded into the Signal app in the future, unlike the Google API client which while potentially malicious, is static until OWS updates it.
- thinkloop 10y agoTy. In that case, specifically regarding poking in memory, isn't that not possible regardless of how malicious the program is?
- arghwhat 10y agoYes, although the system can be modified to permit it. Also, google play services require a library to use, and this library runs in your process. Likewise, the dynamically loaded mapview problem takes some external code and stuffs it into your process.