logoalt Hacker News

ok123456today at 8:41 PM2 repliesview on HN

Isn't keeping ADB enabled (most people who do this don't enable it and then promptly disable it) a huge security problem? ADB enabled means an adversary can completely own your device and "back it up" by simply plugging it in.

This is much worse than nagging about "untrusted sources".


Replies

dvdkontoday at 8:52 PM

No, there's a trust-on-first-use procedure where you have to accept the computer's key on your phone.

show 1 reply
sigmartoday at 8:53 PM

>ADB enabled means an adversary can completely own your device and "back it up" by simply plugging it in.

each adb host has to be individually white-listed by an unlocked device. also the current behavior is that it auto forgets any white listed host that hasn't connected within 7 days.