• 0 Posts
  • 102 Comments
Joined 11 months ago
cake
Cake day: August 15th, 2023

help-circle




  • That… is not a study by anyone who knows what they are talking about. It also does not mention fingerprints at all.

    They seem to believe that the app can use permissions undeclared in the manifest file because they obviously think it’s only for the store to show the permissions to the user. Android will not actually allow an app to use undeclared permissions. The most rational explanation is the codebase is shared with different version of the app (possibly not released) that had different manifests.

    It also makes a big deal of checking if running as root. That is not evidence of having an escalation exploit. If they have an ability to get root before running the app why would they need to use the app to exploit it? They could just do whatever they wanted and avoid leaving traces in the app. Though I doubt they would root phones to just brick them. It’s the kind of mischief you would expect from a kid writing viruses, not an intelligence agency or criminal enterprise.

    Users who root their own phones are very unlikely to run temu as root. In fact a lot of apps related to shopping or banking try to detect root to refuse to work as your system is unsafely. In any case it’s a very niche group to target.

    To keep things short, that ‘study’ does not really look credible or written by actual experts.
















  • I think most internet arguments are like that, the opposing parties are trying to argue their case for the neutrals, people who have not really made up their mind on the issue.

    After all nobody likes to be ‘corrected’ by random strangers. Additionally it’s clearly an important issue for rgullis, he has written some software for lemmy (think a migration tool), has his own instance (with communities, not just to keep track of downvotes). You would expect him to have though his position out (according to his beliefs) and thus not be easily swayed.

    I am just stubborn, perhaps it would be better to ignore being ‘called out’ but… no.