3 ms·
Looking at those permissions, I think whatever fear he decompiled this out of was justified. I guess that's one way to implement industrial espionage. Build t
by heroprotagonist 2y ago
Looking at those permissions, I think whatever fear he decompiled this out of was justified.
I guess that's one way to implement industrial espionage.
Build telemetry and malware, or code that can become malware with a little tweaking or remote checks, into a component that's likely to be used by technologists in whatever sector you're interested in.
Make it a bit better and a lot cheaper than all the alternatives. Get on their phone with lots of permissions, and use the telemetry. Once you know who they are you can decide on more targeted actions to turn them into a vector against their employer or whoever, or just watch what you can to collect information.
- daghamm 2y agoAlternative take: maybe the app developer is combining random snippets found online mostly without knowing what he is doing. Remember that not long ago, Facebook was caught having deliberately bad sample code with too broad permissions https://privacyinternational.org/report/2647/how-apps-android-share-data-facebook-report https://privacyinternational.org/report/2647/how-apps-androi...
- heroprotagonist 2y agoAssuming ignorance, would you trust said app developer with remote management of your device if he accidentally asked for it?
- daghamm 2y agoMy point is that this could very well be incompetent instead of malice. Doesn't really change anything and I would not install an app that requests all these permissions and I am also very careful with apps distributed outside the official store. With that said, Android by default disables dangerous permissions and almost everything has to be opted in these days.
- dzdt 2y agoThe horseshoe principle applies on the malice/incompetence dimension. Any sufficiently advanced malice is indistinguishable from incompetence. (Disguising ill intent by as incompetent design is one of the strongest deniability approaches.) But also any sufficiently advanced incompetence is indistinguishable from malice. (A bad actor can fully compromise an incompetently designed system as well as if the vulnerabilities had been intentional.)
- mavamaarten 2y agoI'd have to look into the app myself, but at first sight the permissions are scary but the decompiled code he showed was just about enough to show a map using Baidu maps. Probably just a feature of the app. I honestly think that yes they are probably collecting too many analytics for comfort, but at the same time it's really not that easy for a random app to really collect anything useful these days. All apps are sandboxed by definition, so all they're getting is what you give them. Also don't forget that high-accuracy location permission could also mean they just want to use Bluetooth for pairing something. I'm all for calling out espionage and malware. But I'd also like to see proof and not just "this could potentially be used for bad".
- heroprotagonist 2y agoI agree someone needs to look into this more directly. The bits he was specifically interested in and wrote most about were the thermography pieces. And that's where the focus of the article was. The author notes only skimming the parts he found where the requested permissions were used, given that the experience of the author was not focused in either Android nor Java. It's not a comprehensive analysis but what is there is very alarming. There is absolutely NO reason for this app to need MDM_APP_MGMT. This is capability for remote administration of the device, including ability to install additional apps (which is likely where this vector would expand exploitation). We don't see where that permission is used from the few screenshots of non-thermo sections. Same for a number of the other permissions. For an 'at-a-glance' review, compare this app's requested permissions to those requested by stalkerware in this stalkerware analysis and notice the similarities: https://andpalmier.com/posts/stalkerware-analysis/#analysis-of-the-sample https://andpalmier.com/posts/stalkerware-analysis/#analysis-...