Smartphone Security: You'll Never Guess Who Just Messaged You
jordansmith.io
jordansmith.io
However, when trusted apps are installed, they often demand all sorts of privileged access. And if they're malicious, there's no way to protect against them. Except that they get reported to Google/Apple and become unavailable. But that doesn't help people who already got pwned.
What am I missing?
A non-root user (hopefully) can't root the system or rm -rf /root.
But everything interesting is stored in that user's home folder with implicit RW permissions anyway.
On Android apps just request everything. I imagine (without explicit knowledge) that an app given permissions could rewrite, erase, or pull down over the network contacts / photos / etc in the background.
Yet I was confused, because as a user all I cared about was my stuff that was ... right there in a non root account.
As you say all the stuff I was concerned about was right there, but nobody talked about how important that was.
On my Linux systems, particularly under Debian, there's some assurance provided through the Debian Project, its guiding documents (social contract, constitution, policy), and debian developers. The project explicitly serves the users. This doesn't prevent bugs and occasional malice, but tends to tremendously reduce incentives for it.
Smartphones ... are a mess, and Android rather particularly so. I've suggested entirely rethinking how app development is performed, particularly for basic utilities, closer to the Debian model. I have little hope of this occurring.
That was true up to Marshmallow (Android 6), when finer grained permissions were added.
> On Android apps just request everything
Well, this is as true as with any other operating system, isn't it?
Nowadays, I try to use F-droid as much as I can, applications there ask for reasonable permissions, and are open source, which makes it easier to trust them.
And it looks like it's been ported to Android and iOS. But it's not default, I guess.
But neither is AppArmor in Linux. So why haven't we heard about apps stealing stuff from /home/user/? Is it just that distros do a better job of policing their repos? Or that the userbase is too small to attract malicious app developers?
I don’t think this will do much besides blow away the root user's home directory, which probably doesn't have much in it anyway. But I get what you mean.
http://www.marriedtothesea.com/041808/this-is-what-i-get.gif
On German consumer shops, most "deal of the day" are still a mix of 4.4 and 5.1.
Not true on Android. Apps can be installed from third party sources, without having to root the phone.
Aside from making the permissions system even _more_ fine-grained, I don't know how you'd make the situation much better than it already is.
This isn't how many users use apps. For them any of these prompts are getting in the way of using the app, so they tap the button that would let them use the app quicker, without reading what the message said.
I'd say open source apps are more trustworthy that Google or Apple.
I've installed plenty of OSS apps but I've never built them myself and while I've looked at the source code, I have no way of knowing if what was in the repository was what got delivered.
You're right; I don't usually vet apps past the simple "is it FLO?" check (although I will do this before accepting a suspicious permission). However, I do keep a copy of the source of most of the apps I use. As a result, if it were to come out that the app is doing something shady, I could remove that part and keep enjoying the functionality of the app, whereas with a proprietary app I'd be SoL.
I also know that the developers know this, so they have an incentive not to do that stuff if they don't want a competing fork to take off. That is the main reason why I trust FLO apps more.
But the second one is, if there really is something off, there's an unambiguous proof of it - you can point directly at the implementation! And with luck, even at the particular person or organization responsible.
You can’t be sure of that at all. This isn’t just an epistemological point either - people are still routinely finding vulnerabilities in the most widely used open source software that were introduced two decades ago. This is despite extremely lucrative incentives for finding them. In many cases it’s because no one bothered to look; in other cases it’s because the numerous (ostensibly qualified) people who looked weren’t capable of finding them.
Open source software is a red herring for security. Its benefits are vastly overstated. You gain an incremental improvement in the theoretical ease of review, but this almost always comes at the cost of the overseeing organization having fewer resources to devote to security because its more difficult and uncommon to monetize open source software.
Overall I’d say open source software is at best weakly correlated with improved security posture. As it turns out most people don’t inspect their code before running it, and this includes those who fully buy into the many eyes aphorism. Of those who do inspect it, approximately all of them are woefully incapable of identifying real vulnerabilities beyond all but the lowest hanging fruit. Those who remain are typically extremely well paid for their expertise and will only look at software which features a sizable bounty.
Unfortunately most open source software, including widely used open source software, does not have a bug bounty and isn’t on e.g. Google Project Zero’s radar.
I and sure many others do look at the code, even for languages that I don't know. I often end up removing functionality that I don't need (less unnecessary code often means less security vulnerabilities) or patch it slightly to suit my needs better. For proprietary code I don't have that luxury, the other issue is that a lot of free-ware software tracks you and won't give you any opt-out options.
It's not weakly correlated if let's say I can remove finger protocol and get direct security benefits. Things like that make outdated proprietary binaries unusable from security perspective.
> approximately all of them are woefully incapable of identifying real vulnerabilities beyond all but the lowest hanging fruit.
Sure, but more often that not it is those that will get exploited and open source makes it damn easy to fix. Bug bounty shouldn't be the only incentive to make the software more secure.
But even with that, it's taken years to find some serious bugs.
When Android cloned the same model, they got much more granular with permissions [1][2], but then completely undermined it by making it occur only once at app install. As someone put it [3], they're not permissions because you can't turn them off -- they're warnings about what the app does. Then they further mucked this up, by eventually grouping them together into broad categories within which apps could automagically gain all other permissions without your approval [4].
Then, the following year, in 2015, they finally introduced iOS-style runtime-granted permissions, if your device was lucky enough to be up-to-date and your apps were gracious enough to target the new API level; otherwise you missed out on this change.
In fairness, by this point, hoover-style request-everything permission requests were extremely common among mainstream apps like Facebook, Messenger, Snapchat... so reigning in on contact-harvesting flashlight apps was a bit of a lost cause.
[1] https://developer.android.com/reference/android/Manifest.per... [2] https://developer.android.com/reference/android/Manifest.per... [3] https://news.ycombinator.com/item?id=7959925 [4] https://news.ycombinator.com/item?id=7959660
Just another thing to be paranoid about in modern life.
I wish I had more time and patience for smart phone development and that the heroic efforts of those unlocking these devices, writing OS drivers for proprietary (and adversarial) hardware and making alternative operating systems possible were more widely acknowledged. It just feels hopeless out of the box.
So for me that's a non-story.
While I agree that access to contacts should be read-only, and write access should be a special permission, for me it appears to be not a problem. While I have a few other apps installed, most didn't ask for contacts permission (i.e. all games), and from those that did ask, I denied in some cases where it didn't make much sense (why should twitter access my contacts? to find my friends on twitter? I don't need that.)
I actually like the way iOS handling the permissions. The privacy overview in the settings is very easy to understand and maintain. Permissions are only asked once when access to them is actually required in that moment (like when you tap on "take photo" in some app). Permission is not asked for while the app is launching (aside of push notifications and location).
So on iOS usually what happens is this:
- I install some app, lets say WhatsApp
- I launch it, it asks for push notifications and contacts permission
- i use the app
- if i dont share my location, i'll never get asked for the permission to GPS
- if i use "send photo" - it will ask for access to photos, but not to the camera
- sometimes, months or years after usage, it will ask me for a permission, i.e. microphone, because I have never used that feature before and only now want to use it
- etc.Don't expect goodwill or good behavior when the fundamental incentives are surveillance and hoovering user data. The multi billion dollar ad economy is based on this.
A system designed with user privacy would be designed to lock down hard on contacts, sms, location, and other personally identifying information access. But the android permission system for instance is so involved it's not surprising lay people are not able to understand the implications, read between the lines of actual motivations and take proper actions.
Facebook does not need your location, contact or sms information. Neither does Google. Yet Google insists on creepily telling you your location on every Google search. This itself is sinister and attempts to normalize stalking behavior.
Uber and others don't strictly need location access, you can type it in, and if required it should be used for the convenience it offers - you are paying for the service - without the possibility of Uber and others collecting historical location and ride information to build invasive files on their users.
But Google is stupid, yesterday I read this commentary about a movie about a plane hijacking in the 70's that landed the plane in Entebbe, Uganda:
https://www.theguardian.com/commentisfree/2018/apr/07/entebb...
Being interested in the historical context, I googled the name of the city. Later on Google showed me as one of its results "Flights to Entebbe". Gee, how clever.
Unlike the OP, the attacker can't receive replies from the recipient.
I’d like to know if this is actually being done in the wild. Certainly once caught would be banned from the App Store and possibly a lawsuit or two filed.
The author didn’t note that a new thread would have started on iOS, which would provide some visual feedback that something was different. You could click for further info and see the different number. I know it would foil most but it’s something.
But the issue is that it's impossible to detect. An app could've added the extra number months ago, and you've deleted the app since then. There is no way to find out which app did it.
The best heuristic would probably be the contact that has messaged you {first|second|third} most frequently in the last week.
And make an indicator in the status bar similar to how an app recently checked your location.
They might even highlight (in red) new changes in the Contacts app. Or when you get such a message from a new user, the Messages app would do the highlight the first time.
Seems that would mitigate this particular thing.
The current Apple system is slightly better: when the app asks to use one capability (camera, smartphone, contacts) the user is prompted to Grant permission the first time this capability is requeated by the app.
This approach should be further developed with prompt dialogs to continue allowing the app to use the requested capabilities.
Examples:
The App XYZ is requesting read and write access to your contacts. It was granted access on {date} and has read 224 phone numbers, 121 names and 56 addresses and modified two contacts.
Continue allow access? Disallow? Report?
App XYZ is requesting access to microphone. In the last month it accessed and recorded 342 hours of microphone.
Continue allow access?Disallow? Report?
App XYZ is accessing your geolocation in the background. Permission was granted on XXX. During the last month it accessed to your geolocation approximately 461 times every day.
Continue allow access?Disallow? Report?
Apple Goole and others don't have to get on the way of every users all the time with these prompts. They can identify at which time to show this prompt based on analytics (how many users already reported this app etc). They can also identify users who are more privacy aware and that will be glad to read carefully these dialogs and report wrongdoing, and send more prompts to these users.
https://developer.android.com/training/permissions/requestin...
https://www.howtogeek.com/230683/how-to-manage-app-permissio...
This hasn't been true for some years now
https://inthecheesefactory.com/blog/things-you-need-to-know-...
Contacts, Mail, Agenda, Messages legitimately want contacts.
All google apps ask for contacts (Photos, Keyboard, Maps, Docs, Keep, Play Store...), all (undeactivable) samsung doppelgangers also (Browser, Gallery, AppStore, Music), as well as all (deactivated) microsoft apps (Powerpoint, Onenote, Excel)...
I do hope you don't mean that you're going to be using it in your own software…