Hacker News new | ask | show | jobs
by 3xpltr3 3 days ago
I agree with user TeMPOraL in his comment. Those who aren't trapped in tunnel-vision, know the app permissions themselves have ALOT of access to all data on your device and users give the apps these permissions. Should we say that every app is a CVE? The real reason any Google dev wants ADB gone is to close open source and lock down the OS to Google sign-ins and a proxy proprietary closed source eco-system. ADB is the master-key to rooting Android devices, getting Android shell access to /root, uploading *.apks, etc... But for the Google monopoly, it makes sense to them to close/restrict this access, then funnel all requests for it through Google's identity gateway for access. So the argument "this app can bypass OS security through ADB and is therefore a CVE" is not valid and an foolish from its /root.
1 comments

> So the argument "this app can bypass OS security through ADB and is therefore a CVE" is not valid

That's not the argument. What gave you the impression that this is what the CVE was about? I'm really confused.

The CVE is "Your android device allows any hacker on your wifi to install/remove apps on your device and steal your private information, unauthenticated"

See: https://news.ycombinator.com/item?id=49046270