Android Reverse Engineering
thomascannon.net
thomascannon.net
Also appreciated the mention of the rageagainstthecage exploit which looks like it could be used to enable a "full user data" backup to be made of a device. One of my complaints about Android is that even the "owner" of the device (without rooting & therefore warranty voiding) can't access all their own data files if an application provides no way of doing so.
The real solution is, "if you have data that's so secure that stealing the phone and running the software on a virtual machine threatens your security, maybe the data should not be on a fucking cell phone".
http://developer.android.com/reference/android/app/admin/Dev...
There doesn't seem to be a policy in the current API docs to prevent a user from enabling USB debugging, but there is a rather large warning when that option is selected.
Without USB debugging and using a password policy, the author's strategy would not have worked. With the current strategy, this has nothing to do with Android, and everything to do with having poorly designed and poorly implemented security on the part of the application author.
I agree it is not an Android issue though, it is the poor design of the app.
Nice work on taking apart the app though.
Anyway, glad people enjoyed it. It's good to get some discussion going too. Thanks =D
Does anyone know why android chose not to use LSM or other kernel based capability enforcement? It would seem like such a hands off platform would be ideal for fine grained enforcement - allowing some amount of security to be maintained even in light of a privilege escalation exploit.