• 49 Posts
  • 567 Comments
Joined 2 年前
cake
Cake day: 2023年6月23日

help-circle









  • steventhedevtoAndroidHow does Play Protect exactly work?
    link
    fedilink
    English
    arrow-up
    1
    arrow-down
    1
    ·
    3 个月前

    Source: worked on something similar a long time ago

    Likely hash based scanning like most virus scanners. It will have a set of signatures for various types of malware (keyloggers, local DNS servers, etc), and looks through the apk (which is just a zip file) for things it knows are bad like financial malware added to the app.

    Their process for adding signatures to their database and how they label them is fully opaque and completely up to them, like any other antivirus company. So they could incorrectly label things intentionally and you’d have no way to know.

    given your device is now compromised you should probably get a new one unless you trust android is able to fully remove the app. Because some financial malware will intercept 2fa sms from your bank.




  • steventhedevtoNonCredibleDefenseyes, again.
    link
    fedilink
    English
    arrow-up
    59
    ·
    4 个月前

    At this point, I’m half convinced these are intentional leaks as part of either disinformation campaigns, cover stories for other intelligence ops, or something like that.

    It can’t possibly be that expecting a bunch of obsessed 19 year olds to keep something secret would be unreasonable.