Bones' Tech Garage
3.18K subscribers
238 photos
31 videos
4 files
4.15K links
Tech repair and configuration of Computers, de-Googled Phones, Pi, and other Projects. Personal Hobbyist Projects welcome too!
Download Telegram
Forwarded from Hacker News
Show HN: Gmail unsubscribe tool with bulk deletion and personal data removal
Article, Comments
πŸ‘12
Is this author correctly interpreting the consequences of this Android signature policy?

Discuss:

How Google Kills Privacy and Security

One of many atrocities destroying privacy and security introduced in Android 12 and later is:

'Known signers permission'.

Per Android doumentation

"Starting in Android 12, the knownCerts attribute for signature-level permissions allows you to refer to the digests of known signing certificates at declaration time.

Your app can declare this attribute and use the knownSigner flag to allow devices and apps to grant signature permissions to other apps, without having to sign the apps at the time of device manufacturing and shipment."


What this essentially means is that a third party app that declares the attribute (known certificates) can obtain system level permissions without any additional action.

This is a huge security hole, because the actual signatures (by OEMs or custom rom developers) do NOT matter, as they automatically become 'known certificates'.

So, basically, starting from Android 12, your device is sold to third party apps, which essentially become system apps.

Another 'nice' feature is 'lease or credit' scheme, which for now is being implemented in branded phones:

if you leased or financed the phone, it could be disabled for non-payment.

Essentially, it's a Kill Switch. Welcome to the Brave New World.

I 'wonder' what could possibly go wrong?

https://t.me/LeOS_Support/138172
πŸ‘7πŸ€”4
Forwarded from Bones' Tech Garage
"A quick link back to the beginner's videos for Linux. The videos will be the first post of the day."

https://t.me/BonesTechGarage/2304
πŸ‘7❀1
πŸ‘† Just in case we need a refresher or you are just starting out.
πŸ‘12