3 ms·
> they leave their SDK installed on the user's device after they've deleted your application I have worked on an Android app extensively. I am pretty sure that
by immad 14y ago
> they leave their SDK installed on the user's device after they've deleted your application
I have worked on an Android app extensively. I am pretty sure that's not possible.
- mmastrac 14y agoYou're right - I misread the product description (updated parent post). I was assuming they'd be doing something tricky like asking for INSTALL_PACKAGES (http://developer.android.com/reference/android/Manifest.permission.html#INSTALL_PACKAGES http://developer.android.com/reference/android/Manifest.perm...) and dropping something on the device. Thankfully they don't do that. As someone who has hacked on Android before (ie: http://unrevoked.com http://unrevoked.com), I wouldn't be surprised if there were ways to silently install packages, or even just tricking the user into allowing an install of a further package. Quick googling leads to this: http://jon.oberheide.org/blog/2010/06/28/a-peek-inside-the-gtalkservice-connection/ http://jon.oberheide.org/blog/2010/06/28/a-peek-inside-the-g...
- drivebyacct2 14y agoAndroid apps can't have that permission, only the Market gets that permission. No offense, but you're spreading some pretty false FUD. Unrevoked uses multiple exploits and requires a lot of user interaction and a computer to initiate the process. Further that last link basically describes how Play remote installs applications and is all under the assumption that someone has somehow MITM the SSL connection, something I'm presuming is not at all easily done. (Further it's going on two years old, I wouldn't be shocked if Google is now signing their INSTALL_ASSET messages, Play has changed a LOT in the last two years). Apps are sandboxed overall similarly in iOS, WinRT, Android, WP7. Uninstalling them, uninstalls them. It even removes all data attached assuming the dev doesn't manually put data on the SD card instead of using the API to store data on the SD card.
- androidoka 14y agoTrue. INSTALL_PACKAGES is a permission with protectionLevel=signatureOrSystem. All other applications can do is take the user to an install-Activity hosted by the OS. For my intention for installing SellAring, please see my answer above.
- jonoberheide 14y agoFYI, it is possible for unprivileged apps to invoke the INSTALL_ASSET functionality themselves. One such example described here: http://blog.duosecurity.com/2011/05/when-angry-birds-attack-android-edition/ http://blog.duosecurity.com/2011/05/when-angry-birds-attack-... Another variation of that attack is still unpatched, allowing any app to invoke INSTALL_ASSET. Certainly that's not intended functionality and is a bug that will be (eventually) patched, but I wouldn't classify it as FUD.
- gurkendoktor 14y agoThat is indeed a little scary. Thanks!