Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

What's the blast radius of this? Are only specific models of phones affected (if so, which?), or does this impact entire brands or the whole ecosystem?


I'm no expert but judging from what seem to be informed comments in this topic, the main attack vector might be restricted to the side-loading not of regular apps, but of system-level components. If that's true, the blast radius would be fairly small indeed (though still not good in those cases).


It's isolated to devices from the specific brands whose platform certs were leaked and are still being used to sign apps.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: