logoalt Hacker News

Dibby053today at 7:35 PM3 repliesview on HN

>no data can be exfiltrated.

Well, that depends on the other apps you have installed. Unless things have changed in newer versions, apps with no networking can still do IPC, so any app can for example use Cronet to make network requests via Google Play Services, regardless of the toggle, as long as sandboxed Google Play Services has network permission.


Replies

gf000today at 8:56 PM

Good point and thanks for the heads up.

Mostly asking it as a question, given that graphene runs Google play services (optionally) as a normal, sandboxed service with no special permissions might help a bit, but I guess unless you disable networking for every other service installed, this is sort of impossible to plug 100%? IPC can be quite the security hole.

subscribedtoday at 8:04 PM

Yep, nothing has changed yet. GOS project still has this in the road map, but as of now Inter Profile Sharing still works.

Cider9986today at 8:00 PM

Agreed.