2 ms·
There are valid RASP techniques that involve dynamic code loading, so it actually makes a lot of sense. Source: I worked on RASP a long time ago :) IMO headlin
by StrLght 1mo ago
There are valid RASP techniques that involve dynamic code loading, so it actually makes a lot of sense. Source: I worked on RASP a long time ago :)
IMO headline is very misleading, and OP should have tried disabling all exploit protection options before jumping to any conclusions. PayPal isn't actively trying to block GrapheneOS as of now.
- skinfaxi 1mo agoSo to use paypal you actually have to reduce the security of the phone?
- iamnothere 1mo agoNot too surprising. I usually have to reduce my browser security on the rare occasion that I access PayPal via the web.
- StrLght 1mo agoAs with all things about security — it depends on your threat model. It reduces security of the app itself, but doesn't affect security of the phone by much.
- water-drummer 1mo ago[flagged]
- grapheneos 1mo agoIn this case, it only reduces the security of the app against exploits rather than the security of the OS. Secure spawning protects the app via unique ASLR bases, random memory tags, etc. Blocking dynamic code loading prevents common accidental vulnerabilities via insecure code loading and hardens against certain exploit techniques.