Remix.run Logo
xg15 5 hours ago

Hadn't thought about that additional attack vector those proxies are enabling. In addition to "internet access from residental connection" privileges, the attacker also gets access to loopback on the device that does the proxying...

But even then, shouldn't this show the same permission prompt for the user that anything else trying to connect to port 5555 would?

londons_explore 4 hours ago | parent [-]

Yes, but users are told to allow it if they want to get free coins etc.

TeMPOraL 4 hours ago | parent | next [-]

You can't fully protect people from the risk of taking bad advice from malicious strangers.

Not the least because most of our industry relies on it to make money. Marketing and advertising themselves are institutionalized forms of "do this thing that's actually harmful to you to get free coins / be safe / get laid".

xg15 4 hours ago | parent [-]

> Not the least because most of our industry relies on it to make money.

I mean, this seems more like one of the root causes for a lot of bad things in the industry me...

xg15 4 hours ago | parent | prev [-]

Told by whom though? If it's through proxyware, then there are three parties who mostly don't know each other:

- the app embedding the proxyware SDK for money

- the proxy operators

- the attackers/botnets using the proxy to access ADB.

The botnet has no access to the app, so it can't show any messages.

The app can show messages, but probably has no connection to the botnet. (I hope)

The proxy operators could show a message by abusing the SDK even more, but that would mean they actively colluded with the botnet. Is that likely? Then they could just give the botnet direct access to the app, no need to do the whole proxy thing.

londons_explore 4 hours ago | parent [-]

It isn't being done behind-the-back of proxy operators.

It's one more revenue stream to be able to remote control real android phones to pass device attestation checks etc.

It's marketed to users with phrases like "earn money from your phone whilst you sleep".

xg15 4 hours ago | parent [-]

Ok, that makes more sense. Hooray for stuff getting even worse...

TeMPOraL 3 hours ago | parent [-]

Remote attestation itself being a questionable idea at best, so it's bad things creating a market for even worse workarounds.

xg15 3 hours ago | parent [-]

No objection there.

Also telling that advertising and locking down devices are driven by the same companies...