• 1 Post
  • 85 Comments
Joined 1 year ago
cake
Cake day: June 9th, 2023

help-circle
  • Here’s the actual relevant part

    These are security risks to be sure, and while these permissions are (mostly) on the surface, possibly defensible, together they do clearly represent an app trying to gather all of the data that it can.

    However, a lot of info from this report is overblown. For example code compilation is sketchy to be sure, but without a privilege escalation attack, it can’t do anything the app couldn’t do with an update.

    Also, there’s some weird language in the report, like counting the green security issues in other apps (like tiktok) as if they were also a problem, despite the image showing that green here means it doesn’t present that particular risk.

    All of this to say, if you have temu, probably uninstall it. It’s clearly collecting all the data it can get.

    But it’s unlikely to be the immediate threat that will have China taking over your phone like this report implies.


















  • For me, since I use the flatpak version of steam, at no point have I ever provided the admin password in order to install steam or any game. It, like all of my desktop software, runs in it’s own little sandbox that has limited access to the rest of the computer. It would take a somewhat sophisticated attack for an anticheat to actually run in kernalspace on the host os.

    But that’s also why companies like riot have their anticheat block Linux from running the game at all.

    If Linux becomes a populate enough platform, I’m sure cheaters will start using it to get around anticheat and something else will have to be done. Until then, I’m happy knowing this is a problem that I can mostly avoid.