You are viewing a single thread.
View all comments View context
-124 points

As a developer this question is hilarious to me

permalink
report
parent
reply
64 points

Why? They’re absolutely right. The article doesn’t say anything about a root exploit or phishing either so were left wondering…

permalink
report
parent
reply
11 points

He’s being condescending because he believes as a developer nothing is actually fully secure. If I spend 100 hours building and securing something, that’s not going to stack up very favorably vs the 1,000’s or even 1,000,000’s of hours attackers and communities can spend trying to break my security layers.

Basically, he’s a dick in how he answered the question, but the truth every software engineer learns, is that there is no fully secure system. There’s always an angle/attack vector you didn’t think of and secure.

permalink
report
parent
reply
2 points

Of course there are (or there can be) fully secure systems. The problems come when you assume something is.

permalink
report
parent
reply
1 point

Hey I was just trying to make a joke… but looks like I didn’t consider the wording too carefully.

permalink
report
parent
reply
2 points

They actual report does say it just displays a fake login page. It’s just phishing.

permalink
report
parent
reply
45 points

please enlighten the rest of us

permalink
report
parent
reply
110 points

As a curious Android user this comment is useless to me

permalink
report
parent
reply
19 points
*

For a real answer here’s the Zscaler blog write up: https://www.zscaler.com/blogs/security-research/technical-analysis-anatsa-campaigns-android-banking-malware-active-google

It looks like they are doing it after app install with a malicious patch. This patch asks for SMS and accessibility access to gain privileges necessary to get into the banking apps. I haven’t thoroughly read it but just looking at the attack chain that’s what I gleaned.

permalink
report
parent
reply
4 points

Ugh, TIL zscaler actually does more than just send my PII to the USA without my consent.

permalink
report
parent
reply
-4 points

As an Android developer that comment makes me sad. Then I remind myself that Lemmy is full of people who migrated from Reddit.

permalink
report
parent
reply
3 points

Dude, do you not want people on this platform? Reddit migrants come with baggage yes but I’d rather that than the husk that was Lemmy before.

permalink
report
parent
reply
3 points

We each have our specialties, and it would be unreasonable to ask that everyone share yours.

permalink
report
parent
reply
1 point

Hey don’t pretend that you didn’t migrate as well.

permalink
report
parent
reply
6 points

Explain yourself

permalink
report
parent
reply
1 point

There’s no such thing as perfect security… unless your application is trivial and doesn’t do very much. Android is designed to collect data from the dozen plus sensors on your phone in order to get money from app vendors to push ads.

permalink
report
parent
reply
14 points

and one day you’ll say why, right?

permalink
report
parent
reply
1 point

Android as a system has too many moving parts. You not only have to worry about various device manufacturers compiling their own versions of AOSP, you have to worry about how manufacturers package unremovable apps like facebook, candy crush, etc.

The backdoor is actually the front door… and it is app vendors who are actually the customers… not the phone owners.

The main reason smartphones took off is that business people were salivating at an always on, always listening device with 10+ sensors collecting data on this whole world. And we pay for the privilege.

Android has to be designed to collect data and show you ads. Is it really surprising that security here is just security against free access to this data from outsiders… and not caring about your security?

permalink
report
parent
reply

Technology

!technology@lemmy.world

Create post

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


Community stats

  • 17K

    Monthly active users

  • 12K

    Posts

  • 555K

    Comments