Comment on Hackers can steal 2FA codes and private messages from Android phones
krooklochurm@lemmy.ca 2 days agoMan in the middle an app download or find some kind of exploit to inject the code from a website, ta da.
I mean, obviously there’s more to it than this but.
NaibofTabr@infosec.pub 2 days ago
Hmm, yes that can happen, but can it happen if you’re downloading directly from the Play store?
krooklochurm@lemmy.ca 2 days ago
There are reports all the time of play store apps containing malware.
NaibofTabr@infosec.pub 2 days ago
I’m sure there are apps that have malware built in yes, but I mean the MITM approach you were describing.
krooklochurm@lemmy.ca 2 days ago
Oh.
Not sure. I was speaking in hypotheticals. I’m sure it’s possible though.
reksas@sopuli.xyz 1 day ago
first you download something and it has nothing malicious, then you update it later and then it has something.