3 ms·
Please elaborate more about security. What can be so seriously wrong on non-rooted device?
by pepemon 8y ago
Please elaborate more about security. What can be so seriously wrong on non-rooted device?
- londons_explore 8y agoQualcomm and Mediatek drivers are an absolute mess. Look at any hardware driver and there'll probably be a couple of buffer overflows right there. There will be lots of world read/writeable devices in /dev, and many of which any random app can write a magic string to enable some debug feature, execute some code, probe some physical memory address, or anything else unwanted. A few years back, Google got annoyed with them for clearly having nobody review any of the code, and they tidied up the worst loopholes (making it harder for apps to directly communicate with device drivers and native vendor extensions), but there are loads left for anyone happy to spend some time looking. I would consider Android phones reasonably secure if you're browsing the web, but for there to be very little security from a malicious app. Google contents that "there can't be any malicious apps because we scan all the code in the store", but we all know that scanning for evil code is snakeoil and it's easy to make an app which only reveals it's evil functions when not running on a "NEXUS 5 (emulated)" as googles scanner uses. Broadcom isn't as bad, but they mistakenly open sourced a lot of their firmware years ago, and still use most of that code today, so finding bugs is far easier considering their hardware doesn't do ASLR, DEP, stack canaries, or any modern code protection method.