858
this post was submitted on 27 Jun 2024
858 points (97.5% liked)
Technology
59378 readers
2838 users here now
This is a most excellent place for technology news and articles.
Our Rules
- Follow the lemmy.world rules.
- Only tech related content.
- Be excellent to each another!
- Mod approved content bots can post up to 10 articles per day.
- Threads asking for personal tech support may be deleted.
- Politics threads may be removed.
- No memes allowed as posts, OK to post as comments.
- Only approved bots from the list below, to ask if your bot can be added please contact us.
- Check for duplicates before posting, duplicates may be removed
Approved Bots
founded 1 year ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
The article links to this as technical proof https://grizzlyreports.com/we-believe-pdd-is-a-dying-fraudulent-company-and-its-shopping-app-temu-is-cleverly-hidden-spyware-that-poses-an-urgent-security-threat-to-u-s-national-interests/
There's analysis of decompiled source code.
The analysis shows it's spyware, which I don't question. But it's spyware in the bounds of Android security, doesn't hack anything, doesn't have access to anything it shouldn't, and uses normal Android permissions that you have to grant for it to have access to the data.
For example the article mentions it's making screenshots, but doesn't mention that it's only screenshots of itself. It can never see your other apps or access any of your data outside of it that you didn't give it permission to access.
Don't get me wrong, it's very bad and seems to siphon off any data it can get it's hands on. But it doesn't bypass any security, and many claims in the article are sensational and don't appear in the Grizzly report.
I agree on the sensationalism in the article.
Still sounds like shitty company doing shitty things
That is not entirely correct. The reported found the app using permissions that are not covered by the manifest. It also found the app being capable to execute arbitrary code send by temu. So it cannot be clearly answered if the app can utilize these permissions or not. Obviously they would not ship such an exploit with the app directly.
It didn't found them using them, it's an important distinction. It found code referring to permissions that are not covered by the Manifest file. If that code was ran, the app would crash, because Android won't let an app request and use a permission not in the Manifest file. The Manifest file is not an informational overview, it's the mechanism through which apps can declare permissions that they want Android to allow them to request. If it's not in the Manifest, then it's not possible to use. It's not unusual to have a bunch of libraries in an app that have functionality you don't use, and so don't declare the required permissions in the Manifest, because you don't use them.
Yeah, which is shady, but again, there is nothing to indicate that code can go around any security and do any of the sensational things the article claims.
The Grizzly reports shows how the app tricks you into granting permissions that it shouldn't need, very shady stuff. But it also shows they don't have a magical way of going around the permissions. The user has to actually grant them.
Do you know if there people who have gone this far analysing the TikTok and WeChat apps?