Remix.run Logo
xg15 4 hours ago

Told by whom though? If it's through proxyware, then there are three parties who mostly don't know each other:

- the app embedding the proxyware SDK for money

- the proxy operators

- the attackers/botnets using the proxy to access ADB.

The botnet has no access to the app, so it can't show any messages.

The app can show messages, but probably has no connection to the botnet. (I hope)

The proxy operators could show a message by abusing the SDK even more, but that would mean they actively colluded with the botnet. Is that likely? Then they could just give the botnet direct access to the app, no need to do the whole proxy thing.

londons_explore 4 hours ago | parent [-]

It isn't being done behind-the-back of proxy operators.

It's one more revenue stream to be able to remote control real android phones to pass device attestation checks etc.

It's marketed to users with phrases like "earn money from your phone whilst you sleep".

xg15 4 hours ago | parent [-]

Ok, that makes more sense. Hooray for stuff getting even worse...

TeMPOraL 3 hours ago | parent [-]

Remote attestation itself being a questionable idea at best, so it's bad things creating a market for even worse workarounds.

xg15 3 hours ago | parent [-]

No objection there.

Also telling that advertising and locking down devices are driven by the same companies...