
Dailydave mailing list archives
Android Attacks Slides
From: Jeffrey Walton <noloader () gmail com>
Date: Fri, 30 Mar 2012 17:50:23 -0400
Hi Guys, Android Attacks (Bas Alberts/Massimiliano Oldani), http://www.immunityinc.com/infiltrate/2011/presentations/Android_Attacks.pdf. Perhaps I'm reading Slide 15 wrong: Fine grained Permission/Capability model ● Per installed Application (Manifest) ● Per URI (Intent permission flags) I believe Android lacks Fine Grained permissions: Felt, Adrienne Porte; Chin, Erika; Hanna, Steve; Song, Dawn; Wagner, David. "Android Permissions Demystified," http://www.cs.berkeley.edu/~afelt/android_permissions.pdf. Jeon, Jinseong; Micinski, Kristopher K.; Vaughan, Jeffrey A.; Reddy, Nikhilesh; Zhu, Yixin; Foster, Jeffrey S.; Millstein, Todd." Dr. Android and Mr. Hide: Fine-grained security policies on unmodified Android," http://www.cs.umd.edu/~jfoster/papers/acplib.pdf. In fact, the permissions are so coarse grained and borked that Google was giving everone READ_PHONE_STATE whether they wanted it or not (the practice has been changed). And READ_PHONE_STATE includes call status, incoming number, identity iformation such as IMSI, etc. See "Android permissions: Phone Calls: read phone state and identity," http://stackoverflow.com/questions/1747178/android-permissions-phone-calls-read-phone-state-and-identity. Jeff _______________________________________________ Dailydave mailing list Dailydave () lists immunityinc com https://lists.immunityinc.com/mailman/listinfo/dailydave
Current thread:
- Android Attacks Slides Jeffrey Walton (Apr 02)
- Re: Android Attacks Slides Bas Alberts (Apr 03)
- Re: Android Attacks Slides Tim (Apr 03)
- Re: Android Attacks Slides James Manico (Apr 03)
- Re: Android Attacks Slides Jeffrey Walton (Apr 05)
- Re: Android Attacks Slides Dean Pierce (Apr 05)
- Re: Android Attacks Slides James Manico (Apr 03)
- Re: Android Attacks Slides r3dRAND (Apr 05)
- Re: Android Attacks Slides Moxie Marlinspike (Apr 05)