The secret behind “unkillable” Android backdoor called xHelper has been revealed
arstechnica.com
arstechnica.com
Interesting if you've never used chattr I guess
The especially frustrating thing about bespoke special/hidden state is that it doesn't straight up fail hard enough to get scrapped, but rather causes ongoing pain for the lifetime of the implementation. Every additional bit of unnecessary complexity is another layer of knowledge and "tricks" that someone needs to know to competently maintain a device.
Androids file signatures stuff is so close to achieving this - I think they'll finally implement it within a year or two, and that will finally allow reclaiming space when built in apps are deleted or upgraded while keeping the ability to factory reset.
Hashes etc are the DRM direction I was talking about. A continuing push to lock phones to some remote root of trust under the guise of security, while making them tougher to actually secure by making them less transparent.
That makes it inaccessible for most users.
Where downloading a 1GB image or needing an actual computer is prohibitive (eg the developing world), then community will fill the role. If the user really just wants to delete their own data, then rename the current feature to something appropriate rather than the current misleading "factory reset" that doesn't actually do a factory reset.
It's generally fallacious to say that a higher layer needs to be created to make things more "accessible", when that new system just addresses one specific case and punts on most other issues. Taking systematic feedback into account, people not needing a JTAG interface for most phone flashing actually creates a problem whereby these devices get into states that require now-specialized tools and now-arcane knowledge, rather than having been designed as legible/transparent/user-serviceable up front.
I know enough to do this, but obviously most people think a "factory reset" is sufficient. That is a problem - defaults matter.
[0] modulo further hidden state that I am not aware of or in touch with. For example my S4-i9500's emmc firmware which got corrupted somehow and bricked the device.
No? TWRP can flash images to any partition you like iirc. has an ADB sideload feature too... Or am I misunderstanding?