• 0 Posts
  • 50 Comments
Joined 1 year ago
cake
Cake day: October 31st, 2023

help-circle



  • berahi@alien.topBtoTech SupportPhone screen replacement
    link
    fedilink
    English
    arrow-up
    1
    ·
    1 year ago

    Because the software receives nearly all input from the screen. The proof of concept shows a laptop running the screen, but the actual attacker would have their own controller embedded. This way it can log all presses including the unlock pattern, wait until the phone is idle for hours and a notification wakes the screen, replay the unlock pattern, launch a webpage to download further payload, etc.

    Basically, the question is “how bad it would be if someone could watch everything on your phone’s screen and touch it when you’re not looking”.


  • berahi@alien.topBtoTech SupportPhone screen replacement
    link
    fedilink
    English
    arrow-up
    1
    ·
    1 year ago

    It’s possible because Android doesn’t verify that the components are genuine. Unlike in iOS, as long as the components conform to a very minimal spec, it will work. The screen is large enough to carry extra payload, including malicious ones. See my other link in this thread to see the demo.




  • berahi@alien.topBtoTech SupportPhone screen replacement
    link
    fedilink
    English
    arrow-up
    1
    ·
    1 year ago

    The research paper merely proves that it is possible, and relatively affordable for a targeted attack, but in reality, someone interesting enough for such an attack would already have their device attacked through other means, no need to wait for the screen to be damaged. For mass surveillance, nobody is wasting extra money for each and every broken screen, there are much cheaper solutions such as updates that include malware.


  • berahi@alien.topBtoTech Supportrent out server
    link
    fedilink
    English
    arrow-up
    1
    ·
    1 year ago

    That seems like a terrible idea. Unless you have a gigabit connection with a dedicated IP at home, an ISP that completely ignores any DMCA & DDoS traffic, and law enforcement who’ll just leave after you explain that the CP coming from home is due to your renting out servers, however much you got paid isn’t worth the trouble.