4 ms·
Android is a huge,complex codebase. doesn't this mean it's hard to verify it's security ?
by ippisl 13y ago
Android is a huge,complex codebase. doesn't this mean it's hard to verify it's security ?
- deleted 13y ago[deleted]
- deleted 13y ago[deleted]
- Zigurd 13y agoAndroid has a userland made of unprivileged code running in a VM. To the extent it is different from a desktop Linux, it should have fewer userland components that could subvert system security. So, it's the same or perhaps easier to audit Android. I'd be more worried about peripherals. Telephones are hard to secure. That's why I mentioned open firmware. I'm not an expert on hardware-level security, but the combination of SoC architecture and lots of programmable cores in peripherals makes me think you would find ways of extracting information from a device that way. And the mobile baseband controls some of the audio paths in a handset. It will be interesting to see if there are any revelations about device-makers and security that come out of the heightened interest in this topic.