Black Hat 2013 - Android: One Root to Own them All

แชร์
ฝัง
  • เผยแพร่เมื่อ 18 ม.ค. 2025

ความคิดเห็น • 12

  • @sp1n3team
    @sp1n3team 9 ปีที่แล้ว +7

    best android blackhat talk ever

  • @TurnGameOn
    @TurnGameOn 9 ปีที่แล้ว +1

    Thanks for the talk..

  • @infotruther
    @infotruther 2 ปีที่แล้ว

    I don't think his mic is on

  • @vortexcortex666
    @vortexcortex666 10 ปีที่แล้ว +10

    It really pisses me off that Android doesn't have the basic package manager feature to add another trusted software source. It's Anticompetitive Anti-consumer Nincompoopery that you can't have both Amazon and Google Play sources trusted. Cert chains have been around since before SSL, so it's not like they don't know how: At 1st boot, generate a user cert, it signs the Google or Amazon or etc. store cert to add new sources. It aren't hard, derp.

    • @orangea9458
      @orangea9458 5 ปีที่แล้ว

      well that changed fast

    • @PetersFXfilms
      @PetersFXfilms 5 ปีที่แล้ว

      Can't you just sideload apps downloaded from the internet?

  • @arnaldogonzalez1
    @arnaldogonzalez1 7 ปีที่แล้ว

    Beast

  • @easyappscompany
    @easyappscompany 6 ปีที่แล้ว +2

  • @paulthomann5544
    @paulthomann5544 11 ปีที่แล้ว

    Probably no american users doing this after black friday, but in the rest of the world, the PokerStars COM mobile app is somewhat popular, too.
    It allows you to play for real money, which seems to be against Google Play policy (it's available in iPhone AppStore, however), so that's how I ended up checking 'allow untrusted sources'. Of course, after installation that setting *can* be unchecked again.
    Am I right that even with the option checked, you need physical access to my device or to somehow trick me into actually installing a malicious app (not too difficult)? Or could you do it remotely, say in a drive-by?

  • @larrygall5831
    @larrygall5831 5 ปีที่แล้ว +3

    Google's OS.. nuff said. Level of trust.. zero.