Remix.run Logo
UncleMeat 4 hours ago

Codes arrive via SMS, which is available to all apps with the READ_SMS permission. This isn't an OS vuln. It is a property of the fact that SMS messages are delivered to a phone number and not an app.

On the Play store there is a bunch of annoying checking for apps that request READ_SMS to prevent this very thing. Off Play such defense is impossible.

jhasse an hour ago | parent | next [-]

Only require Developer Registration for apps with READ_SMS then.

Retr0id 3 hours ago | parent | prev [-]

If they restricted sideloaded apps from sniffing SMS then I wouldn't mind all that much.

warkdarrior 2 hours ago | parent [-]

So no access to SMS for apps distributed on F-Droid?

Retr0id 7 minutes ago | parent [-]

Fine by me, what are people using SMS for in 2026 except for spam and sending 2FA codes insecurely?

(I'm being facetious here but this is massively preferable to disabling sideloading altogether)