31
submitted 3 months ago* (last edited 3 months ago) by ijeff@lemdro.id to c/android@lemdro.id
top 22 comments
sorted by: hot top controversial new old
[-] Jackthelad@lemmy.world 46 points 3 months ago

iVerify vice president of research Matthias Frielingsdorf points out that while Showcase represents a concerning exposure for Pixel devices, it is turned off by default. This means that an attacker would first need to turn the application on in a target's device before being able to exploit it. The most straightforward way to do this would involve having physical access to a victim's phone as well as their system password or another exploitable vulnerability that would allow them to make changes to settings.

Just a bit of alarmism then, with something that can be easily removed in an update.

[-] wccrawford@lemmy.world 7 points 3 months ago

Not only can it be removed, they've already said it going to happen soon.

[-] unrushed233 44 points 3 months ago

The story isn't nearly as dramatic as it seems. Maybe this thread can offer some nuance: https://grapheneos.social/@GrapheneOS/112967309987371034

[-] ijeff@lemdro.id 6 points 3 months ago

Thanks for sharing!

[-] sunzu2@thebrainbin.org 24 points 3 months ago

The issue relates to a software package called “Showcase.apk” that runs at the system level and lurks invisible to users. The application was developed by the enterprise software company Smith Micro for Verizon as a mechanism for putting phones into a retail store demo mode—it is not Google software. Yet for years, it has been in each Android release for Pixel and has deep system privileges, including remote code execution and remote software installation. Even riskier, the application is designed to download a configuration file over an unencrypted HTTP web connection that iVerify researchers say could be hijacked by an attacker to take control of the application and then the entire victim device.

"flaw"

any idea if de-google phones have this "feature"

[-] evo@sh.itjust.works 27 points 3 months ago

The app isn't enabled by default so stock Pixels aren't even vulnerable without physical access to an unlocked device.

[-] BakedCatboy@lemmy.ml 8 points 3 months ago

I couldn't find the APK on my pixel 5 running lineage so I think only stock-based roms should be affected. I checked using an APK extractor app that lists all system apps including things like 3 button navigation bar.

[-] unrushed233 5 points 3 months ago

GrapheneOS doesn't include this, along with many other unnecessary carrier apps

[-] AmbiguousProps@lemmy.today 9 points 3 months ago

I have doubts that this apk is enabled and running on all pixels, it's especially not on custom roms such as Graphene (I just checked my own).

[-] unrushed233 8 points 3 months ago

The GrapheneOS guys also explained why this isn't nearly as bad as it sounds, and how Wired is simply fearmongering: https://grapheneos.social/@GrapheneOS/112967309987371034

[-] LostXOR@fedia.io 7 points 3 months ago

Yeah, doesn't look like it affects GrapheneOS. More validation of my choice to run Graphene I guess.

[-] DarkThoughts@fedia.io -1 points 3 months ago

I'm too stupid to install it. Would've liked to plonk it on my old tablet instead of throwing it into the trash.

[-] unrushed233 6 points 3 months ago

It's only compatible with modern Pixel devices, so unless you're old tablet is a Google Pixel Tablet, you can't install it anyway. But the installer is super easy to use (if you have a compatible device). It's literally all in your web browser.

[-] DarkThoughts@fedia.io 1 points 3 months ago

It's an old Xperia Z4 and there's a few custom images on the forums. But the "how to" suggest using a tool that does not even exist in that version and is otherwise so sparse on information that I gave up after that.

[-] unrushed233 1 points 3 months ago

I don't recommend installing random builds from forums like XDA. GrapheneOS definitely doesn't have an official version for anything other than Pixels, you might want to try LineageOS if you want to throw the tablet out anyway

[-] DarkThoughts@fedia.io 0 points 3 months ago

you might want to try LineageOS

Same thing there basically.

[-] unrushed233 1 points 3 months ago

Oh man, I just looked up the Xperia Z4 and noticed that it's like 10 years old. Can't say that I'm surprised that there are basically no ROMs.

[-] DarkThoughts@fedia.io -1 points 3 months ago

Well, yes - what else am I going to install a custom rom on other than a device that is no longer receiving actual system updates but still works fine? And as I said, there are a couple roms on the forums, just with very lacking installation instructions.

[-] possiblylinux127@lemmy.zip 6 points 3 months ago

Kind of a nothing burger

[-] MaXimus421@lemmy.world 1 points 3 months ago

All these updates and they let this get by. That's pretty ridiculous.

[-] unrushed233 8 points 3 months ago

Don't let this misleading Wired article fearmonger you. I recommend this thread, which provides some nuance to this drama: https://grapheneos.social/@GrapheneOS/112967805820394815

[-] MaXimus421@lemmy.world 2 points 3 months ago

Many thanks. I'll check it out.

this post was submitted on 15 Aug 2024
31 points (69.6% liked)

Android

17671 readers
55 users here now

The new home of /r/Android on Lemmy and the Fediverse!

Android news, reviews, tips, and discussions about rooting, tutorials, and apps.

🔗Universal Link: !android@lemdro.id


💡Content Philosophy:

Content which benefits the community (news, rumours, and discussions) is generally allowed and is valued over content which benefits only the individual (technical questions, help buying/selling, rants, self-promotion, etc.) which will be removed if it's in violation of the rules.


Support, technical, or app related questions belong in: !askandroid@lemdro.id

For fresh communities, lemmy apps, and instance updates: !lemdroid@lemdro.id

💬Matrix Chat

💬Telegram channels / chats

📰Our communities below


Rules

  1. Stay on topic: All posts should be related to the Android OS or ecosystem.

  2. No support questions, recommendation requests, rants, or bug reports: Posts must benefit the community rather than the individual. Please post to !askandroid@lemdro.id.

  3. Describe images/videos, no memes: Please include a text description when sharing images or videos. Post memes to !androidmemes@lemdro.id.

  4. No self-promotion spam: Active community members can post their apps if they answer any questions in the comments. Please do not post links to your own website, YouTube, blog content, or communities.

  5. No reposts or rehosted content: Share only the original source of an article, unless it's not available in English or requires logging in (like Twitter). Avoid reposting the same topic from other sources.

  6. No editorializing titles: You can add the author or website's name if helpful, but keep article titles unchanged.

  7. No piracy or unverified APKs: Do not share links or direct people to pirated content or unverified APKs, which may contain malicious code.

  8. No unauthorized polls, bots, or giveaways: Do not create polls, use bots, or organize giveaways without first contacting mods for approval.

  9. No offensive or low-effort content: Don't post offensive or unhelpful content. Keep it civil and friendly!

  10. No affiliate links: Posting affiliate links is not allowed.

Quick Links

Our Communities

Lemmy App List

Chat and More


founded 1 year ago
MODERATORS