this post was submitted on 25 Dec 2023
108 points (95.8% liked)

Technology

58303 readers
14 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS
 

Chameleon Android malware can turn off fingerprint unlock to steal your pin::Be careful out there.

all 20 comments
sorted by: hot top controversial new old
[–] Deebster 31 points 10 months ago (1 children)

It still needs a gullible user to change their settings for this to work; not much to worry about here.

[–] [email protected] 0 points 10 months ago* (last edited 10 months ago) (1 children)

Note that for this attack to work, you have to be on Android 11 or below (or possibly an earlier patch) as by default accessibility services aren't allowed to draw-over or interact with elements in the settings app unless you explicitly override it in developer options.

This extends to some other areas, like for when biometric/system lock APIs are used.

[–] [email protected] 2 points 10 months ago

So you have to enable the "draw over settings", which is pretty deep in settings (developer options).

You kinda deserve it if you do this. Lol