Hacker News new | ask | show | jobs
by 3form 4 days ago
Because you know, the actual solution would be to have more granularity in authentication process than "allow whole device to attach to ADB", but that would be like, difficult... so they're not going to so that.

Right now any app on my PC connected to ADB could manipulate my phone then, and that's somehow not a CVE?

1 comments

Is it a CVE that an app running on my PC could actually be running under GDB? It's the entire purpose of these tools.
Mind you, I'm not arguing for the CVE, just complaining that the current thinking is very selective.