4 ms·
In what way does a Play Services dependency make them insecure?
by tppol 4y ago
In what way does a Play Services dependency make them insecure?
- barbazoo 4y agoPresumably it's being alleged that the app store operator could switch binaries, not sure. Bigger issue is privacy with notifications going through Google, right?
- RamRodification 4y ago> notifications going through Google That has never crossed my mind. Do notifications on Android normally go through Google servers? As in could be spied or data mined on?
- cvwright 4y agoYes, unfortunately the platform providers are the only battery-efficient way of doing notifications on mobile phones.
- jazzyjackson 4y agoI suppose you're talking about push notifications to save battery life instead of an app that is constantly polling for new messages? I don't think all notifications are push notifications, and those that are would be https encrypted between the host and client, so any e2ee message would have to be decrypted on device before showing a notification, google should not have access to this, but of course it comes back to whether you should trust anything software tells you.
- barbazoo 4y agoI might be wrong here, see sibling comment: https://news.ycombinator.com/item?id=33123325 https://news.ycombinator.com/item?id=33123325
- tppol 4y agoThe notifications Signal pops up, with contact name and message text, are generated from within the app itself, not sent via Google. It does receive some Firebase messages from Google, but not the type that automatically pops up a notification. Instead these are silent ones that trigger the app to perform a particular action, such as fetching any new Signal messages from Signal's servers.
- barbazoo 4y agoThat's great to know, thanks!
- formerkrogemp 4y agoI've had my in-laws download malware onto their android devices multiple times, from the play store. Anything is a threat if you're paranoid enough with your threat model, debilitatingly so.
- dylan604 4y ago>I've had my in-laws download malware onto their android devices multiple times I know in-law jokes are fun, but this just makes you sound like an evil arsehat. What in the world did they do to you that you had them do this not once but multiple times? /s I'm assuming you probably meant to word that to read differently
- thereddaikon 4y agoBecause you are unable to verify what the google play service binary is doing. It could potentially bypass any security built in to the app and allow google to read your messages. And the answer to their question is that it depends on your threat model and the amount of risk you are willing to accept. There is no such thing as perfect security or a perfectly validated platform. At some point you have to accept good enough and get on with your life.
- tppol 4y agoHow would it do that? While the Play Services app has more privileges than many other apps on a device, it's still running in an application sandbox, and shouldn't have permission to read the Signal app's data or attach to its process or anything like that.