Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

If I understand this correctly this is an orbital nuke on android security.


The existence of leaked platform signing certificates breaks a core Android security feature: the application sandbox. Theoretically, a malicious actor with the leaked cert can sign an app and declare the shared user ID Manifest element to run in the same process as 'android', ie. the operating system process.


I think it’s more an orbital dung beetle.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: