4 ms·
Pushing a malicious app update creates an inspectable artifact. Researchers can discover exactly when it happened and therefore who is vulnerable and which mess
by schmichael 1y ago
Pushing a malicious app update creates an inspectable artifact. Researchers can discover exactly when it happened and therefore who is vulnerable and which messages.
This is a much much much better situation than handing someone your keys and letting them MITM you at any time with no hope of knowing.
- IshKebab 1y agoYou're not thinking sneakily enough. Obviously you wouldn't push a visibly malicious app update to everyone. Instead you make it so that you can push malicious code to specific users. Then all researchers can say is "it's a bit suspicious that this webview has access to Java APIs" and you just need to say "it's needed so we can get your app version" or whatever. They'll never be able to actually see you reading the messages, unless you happen to be very stupid and target a security researcher. I agree it's definitely better to do proper e2e encryption like WhatsApp / Signal do, but I don't think we should pretend they are magically fully secure against this attack.
- danielscrubs 1y agoApple doesn’t allow it?
- IshKebab 1y agoAs far as I know they do. You aren't allowed to dynamically load binary code but there's nothing against scripting or using JS in webviews.