Attend XDA's Second Annual Developer Conference, XDA:DevCon 2014!
5,729,985 Members 54,139 Now Online
XDA Developers Android and Mobile Development Forum

USB Bug in Android???

Tip us?
 
brauckmiller
Old
#1  
Member - OP
Thanks Meter 0
Posts: 40
Join Date: Apr 2010
Default USB Bug in Android???

Ok, on another board (not Android related), one of the members was posting a piece on cryptography. Interesting stuff. His intent was to encourage people to start using encrypted communications more.

Another member then asked about any apps that you could run on your smartphone such as an Android based device. The OP stated that using such an app on Android is useless because with physical access, he could install any app on your phone (such as a keylogger) and the encryption is moot. Here is his exact quote:

Quote:
I do though. You can sideload an APK into a phone, even if USB debug isn't turned on, it's password protected, and even if the device storage is encrypted. There's a 'bug' in the USB stack of Android that's never been fixed. There's a similar bug in IOS. Some PDs even have a device that does exactly this. I really don't want to get too much into exactly how it happens, but it affects every phone I've ever played with. It's about as difficult as breaking into a warded padlock. All you need is the shim.
Does such a bug still exist? If so, has any XDA dev ever considered patching it for security's sake so that a law enforcement agency would not be able to access your device?

Thanks
 
Walter.White
Old
#2  
Walter.White's Avatar
Senior Member
Thanks Meter 952
Posts: 750
Join Date: Nov 2013

 
DONATE TO ME
@jcase would know for sure.
 
jcase
Old
#3  
jcase's Avatar
Forum Moderator / Senior Recognized Developer - Taco Vendor
Thanks Meter 6730
Posts: 3,546
Join Date: Feb 2010
Location: Sequim WA

 
DONATE TO ME
I'm unaware of any such in android, I've found some in OEM builds in the past but nothing in android. Possible tho

Sent from my One using XDA Premium 4 mobile app
I'm taking a break of an undetermined length. Please don't contact me about exploits

Something important? jcase@cunninglogic.com
Like Android security topics? Join our G+ community -> https://plus.google.com/communities/...07618051049043
My Bitcoin address : 1Newifz6yETTmbziCsZZstmHHPH6ejNr75
The Following User Says Thank You to jcase For This Useful Post: [ Click to Expand ]
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes