On Fri, 13 Apr 2012 15:05:21 -0700 (PDT)
Paul Brodeur wrote:

> The purpose of this was to find apps that use world-readable 
> permission on their files, such as the Skype vulnerability linked in the 
> article or the Lookout vulnerability from last year: 
> http://blog.mylookout.com/look-11-001/ -- these are not Android OS 
> vulnerabilities, they are vulnerabilities in apps that specifically go 
> against the suggestions in the documentation. I don't think it's stated any 
> differently in the article.

Does that include all apps that allow moving to the msdos filesystem
sdcard? Maybe android should use some sort of RBAC as mandating a non
dos filesystem like nexus uses looks troublesome to me for those who
want to use the card directly.

-- 
You received this message because you are subscribed to the Google Groups 
"Android Security Discussions" group.
To post to this group, send email to [email protected].
To unsubscribe from this group, send email to 
[email protected].
For more options, visit this group at 
http://groups.google.com/group/android-security-discuss?hl=en.

Reply via email to