• tidderuuf@lemmy.world
    link
    fedilink
    English
    arrow-up
    162
    arrow-down
    11
    ·
    1 day ago

    requires a victim to first install a malicious app

    Let me stop you right there… and leave.

    • NaibofTabr@infosec.pub
      link
      fedilink
      English
      arrow-up
      111
      arrow-down
      2
      ·
      1 day ago

      Normally I would agree with this perspective, but in this case the “malicious app” is just a demo. It requires no permissions to do the malicious behavior, which means that the relevant code could be included in any app and wouldn’t trigger a user approval, a permissions request or a security alert. This could be hiding in anything that you install.

      • krooklochurm@lemmy.ca
        link
        fedilink
        English
        arrow-up
        6
        arrow-down
        1
        ·
        edit-2
        15 hours ago

        Man in the middle an app download or find some kind of exploit to inject the code from a website, ta da.

        I mean, obviously there’s more to it than this but.

        That’s how these things work. They’re chained.

        • NaibofTabr@infosec.pub
          link
          fedilink
          English
          arrow-up
          2
          ·
          12 hours ago

          Hmm, yes that can happen, but can it happen if you’re downloading directly from the Play store?

          • reksas@sopuli.xyz
            link
            fedilink
            English
            arrow-up
            3
            ·
            8 hours ago

            first you download something and it has nothing malicious, then you update it later and then it has something.

            • NaibofTabr@infosec.pub
              link
              fedilink
              English
              arrow-up
              2
              ·
              edit-2
              12 hours ago

              I’m sure there are apps that have malware built in yes, but I mean the MITM approach during an app download that you were describing.

      • NihilsineNefas@slrpnk.net
        link
        fedilink
        English
        arrow-up
        5
        arrow-down
        1
        ·
        18 hours ago

        So they’re using the same programs that the three letter agencies of the world have been using to crack phones since before touchscreens existed?

        • NaibofTabr@infosec.pub
          link
          fedilink
          English
          arrow-up
          4
          ·
          12 hours ago

          This article doesn’t really address that. I don’t think there’s any indication that this particular vulnerability is related to nation-state hacking.

      • FreedomAdvocate@lemmy.net.au
        link
        fedilink
        English
        arrow-up
        2
        arrow-down
        2
        ·
        15 hours ago

        So it could be hiding in, what would you call them…….malicious apps?

        The relevant code isn’t going to be in a non malicious app.

        • ReginaPhalange@lemmy.world
          link
          fedilink
          English
          arrow-up
          4
          arrow-down
          1
          ·
          15 hours ago

          Listen Mr Zuckerberg, we can improve our ad revenue immensely if we can do this one little trick to Facebook’s code…

            • NaibofTabr@infosec.pub
              link
              fedilink
              English
              arrow-up
              2
              ·
              9 hours ago

              Because if it’s doing this it’s a malicious app….

              OK, how would you know?

              Google also said they’ve found zero apps doing this.

              So what? There are millions of apps on the Play store, they aren’t all being reviewed with this level of scrutiny. This means basically nothing.