• mtchristo@lemm.ee
    link
    fedilink
    English
    arrow-up
    0
    ·
    1 year ago

    Aren’t apps on android hermetically sealed from other apps and malware. How could this be achieved ?

    • whyrat@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      1 year ago

      Since the other reply was unhelpful: apps are supposed to have limited privileges and isolation from each other, yes… But the whole point of malware like this is that they figure out ways to break those restrictions and get escalated privileged.

      You can get more technical detail from reading the report, in this case it looks like the app does not contain malware, but instead requests an update after install that contains the bad code and then breaks the app limitations and scans for the target banking applications and copies the security certificates.

      • catnip@lemmy.zip
        link
        fedilink
        English
        arrow-up
        0
        ·
        1 year ago

        Why? They’re absolutely right. The article doesn’t say anything about a root exploit or phishing either so were left wondering…

        • jackeryjoo@lemmy.world
          link
          fedilink
          English
          arrow-up
          0
          ·
          1 year ago

          He’s being condescending because he believes as a developer nothing is actually fully secure. If I spend 100 hours building and securing something, that’s not going to stack up very favorably vs the 1,000’s or even 1,000,000’s of hours attackers and communities can spend trying to break my security layers.

          Basically, he’s a dick in how he answered the question, but the truth every software engineer learns, is that there is no fully secure system. There’s always an angle/attack vector you didn’t think of and secure.

          • Miaou@jlai.lu
            link
            fedilink
            English
            arrow-up
            0
            ·
            1 year ago

            Of course there are (or there can be) fully secure systems. The problems come when you assume something is.

    • dev_null@lemmy.ml
      link
      fedilink
      English
      arrow-up
      0
      ·
      1 year ago

      Yes, the app doesn’t steal any information from other apps. The report says the malware just displays a fake bank login page, in the hope the user gives it their details willingly.