3 ms·
Sandboxing had nothing to with any app store, and Android security empathetically doesn't suck.
by tpush 3y ago
Sandboxing had nothing to with any app store, and Android security empathetically doesn't suck.
- scarface_74 3y agoI just had a coworker say that he surreptitiously installed an app on his son’s phone that allowed him to see everything his son was doing remotely and listen in to his son’s conversations. He showed it to us in action.
- inkysigma 3y agoIt's a difficult security model when the threat actor is a parent who presumably has access to the device and in an unlocked state along with permissions to install anything from anywhere. It's not like the threat actor realistically couldn't (with some effort) see everything the child was doing already just by asking so I don't really see this as a very good threat model. Sure, Apple might prevent you from installing such applications on devices (though they offer monitoring app usage and websites for parental controls), but that's just because they have a walled garden that could disallow such apps and it's less clear how to weigh app freedom against user safety. If you're worried about zero days, Android exploits are priced around the same as iOS exploits apparently so take that how you will.
- scarface_74 3y agoIt’s not a zero day. It’s insecure by design. There is a huge difference between parental control and snooping. You really think you are going to ask a child what are they doing every second and what they talked about and they are going to tell the truth? What’s stopping someone also from surreptitiously installing the same snooping software on another adult’s phone? It’s not less clear. There is no reason to allow this type of software to be installed on a phone without a clear indication that it is on there.
- inkysigma 3y ago> You really think you are going to ask a child what are they doing every second and what they talked about and they are going to tell the truth? Of course not, but usually adults can force a passcode out (or take the device altogether) or force the child to sign in for them to see at regular intervals, in which case they can observe everything. I would agree that this is excessive for a parent to do, but clearly the parent you are talking about is already taking excessive measures. > What’s stopping someone also from surreptitiously installing the same snooping software on another adult’s phone? Presumably, an attacker will not have access to the device and not be freely given the password or access with the ability to install an app. If they do, then there's nothing stopping the attacker from just going through the phone. Installing a app without the person's knowledge would either require you to have inside access or have a zero day. > It’s not less clear. There is no reason to allow this type of software to be installed on a phone without a clear indication that it is on there. A lot of the permissions individually make sense and this software could just be composed by a significant number of them. I'm not sure exactly how the software you are referring to works and its scope, so I'll take a narrow example. In the case of messages, users may legitimately want a different messaging app. If the adult just side loads an arbitrary SMS app, how is that supposed to be distinguishable to the OS whether the app additionally happens to sync these messages to a third party? In the case of screen capture, that's a perfectly normal use case to stream your screen. Android does warn you when this is occuring. Or for that matter, many Android devices permit side loading an entire OS. This could be used by the adult to basically bypass any restrictions on apps altogether. This has a completely legitimate use case. Should we block that as well?
- scarface_74 3y agoEven if the parent “forces a passcode”, they can’t remotely listen in on conversations and see exactly what their child is doing at any given minute. > Presumably, an attacker will not have access to the device and not be freely given the password or access with the ability to install an app. Are you really unaware of what a jealous partner can do? > A lot of the permissions individually make sense In what world does a permission to “remotely monitor your screen and intercept your voice and hide that the app is installed make sense”? > A lot of the permissions individually make sense and this software could just be composed by a significant number of them. I'm not sure exactly how the software you are referring to works and its scope, so I'll take a narrow example. Maybe it’s a bad idea to allow a third party app to have access to your SMS messages especially seeing they are often used for 2FA? > In the case of screen capture, that's a perfectly normal use case to stream your screen. Android does warn you when this is occuring. And yet there are plenty of apps for Android that can do this surreptitiously… You realize you aren’t making a great case for Android here don’t you?
- thfuran 3y agoThat's like saying Linux is insecure because sudo exists.
- scarface_74 3y agoYes and because of Linux’s “openness” it’s being used by most people as their main desktop OS and in the US 60% of the market are buying iPhones. Have you thought that their priorities aren’t the same as yours?
- thfuran 3y agoI'm not sure what you're trying to say.
- scarface_74 3y agoI’m saying that A) most people don’t care about openness based on their revealed preference B) if you do care, you are free to choose a more “open” choice
- thfuran 3y agoSurely most people care at least enough about openness to want to be able to install apps on their phone. Your threat model is considering an authorized user installing an app to be a security breach.
- oarsinsync 3y agoThis sounds suspiciously similar to the “evil maid” attack: all bets on security are off when you’ve got physical access to the device. This is a well known weakness in all platforms. Some platforms manage short term protections against this, but nothing ever withstands it in the long run.
- kmeisthax 3y agoIf the adult demanded the kid's phone password, it's rubber hose cryptanalysis. If the adult set up the password for the kid, it's a supply chain attack. Evil maid implies you don't know the password at all, which doesn't sound like the case here.
- scarface_74 3y agoHaving the kids password doesn’t allow the parent to see real time what the kid is doing every second and remotely monitor them.
- kmeisthax 3y agoAndroid has privacy indicators for when software is recording things on the phone. Wouldn't that give the coworker away? Or does his son just have an old phone? (The privacy indicators are fairly new, IMO, but it mirrors a thing Apple did a few years ago.)
- UncleMeat 3y agoCompare this to a desktop. The desktop spyware will be even more capable than the mobile spyware. And these sorts of child-tracking (and sadly, abused-partner-tracking) apps exist on both Android and iOS platforms.
- scarface_74 3y agoWhat “child tracking” device on iOS lets you intercept phone calls, text messages and remotely monitor in real time what someone is doing on their phone?