3 ms·
I think they're arguing that on modern iOS and android the application sandboxing and permissions make a lot of the data collection described improbable/impossi
by hackernewsconvo 6y ago
I think they're arguing that on modern iOS and android the application sandboxing and permissions make a lot of the data collection described improbable/impossible.
- krn 6y agoThere is a huge difference between "improbable" and "impossible" here. Was it highly improbable that Saudi crown prince could hack into Bezos's iPhone? Yes, it was. Nevertheless, that's exactly what happened[1]. Now imagine what Chinese government could do with TikTok. Also, application sandboxing and permissions can mean nothing at all[2]: > A billion or more Android devices are vulnerable to hacks that can turn them into spying tools by exploiting more than 400 vulnerabilities in Qualcomm’s Snapdragon chip, researchers reported this week. > The vulnerabilities can be exploited when a target downloads a video or other content that’s rendered by the chip. Targets can also be attacked by installing malicious apps that require no permissions at all. > From there, attackers can monitor locations and listen to nearby audio in real time and exfiltrate photos and videos. Exploits also make it possible to render the phone completely unresponsive. Infections can be hidden from the operating system in a way that makes disinfecting difficult. [1] https://www.nytimes.com/2020/01/22/technology/jeff-bezos-hack-iphone.html https://www.nytimes.com/2020/01/22/technology/jeff-bezos-hac... [2] https://arstechnica.com/information-technology/2020/08/snapdragon-chip-flaws-put-1-billion-android-phones-at-risk-of-data-theft/ https://arstechnica.com/information-technology/2020/08/snapd...