5 ms·
Google has been decoupling things like Play Services from the BSP for a long time now. They could certainly push a backdoored version to a specific set of phone
by Skunkleton 5y ago
Google has been decoupling things like Play Services from the BSP for a long time now. They could certainly push a backdoored version to a specific set of phones if they so wished.
If you wanted to add the exploit to the kernel, there are plenty of hooks to do so that would not require the kernel to be recompiled (e.g. a loadable module, or BPF). Again, these could be targeted at specific individuals, or groups of individuals.
Still, Google is extremely unlikely to add any backdoor willingly, and unlikely to add one in general. And more to the point, controlling the signing keys for a specific App does not make it easier to backdoor someones phone.