logoalt Hacker News

UncleMeatyesterday at 8:19 PM2 repliesview on HN

Codes arrive via SMS, which is available to all apps with the READ_SMS permission. This isn't an OS vuln. It is a property of the fact that SMS messages are delivered to a phone number and not an app.

On the Play store there is a bunch of annoying checking for apps that request READ_SMS to prevent this very thing. Off Play such defense is impossible.


Replies

jhasseyesterday at 11:00 PM

Only require Developer Registration for apps with READ_SMS then.

show 1 reply
Retr0idyesterday at 8:40 PM

If they restricted sideloaded apps from sniffing SMS then I wouldn't mind all that much.

show 2 replies