Project

General

Profile

Issue #1365

Install from unknown sources and adb enabled by default

Added by Wolfgang Wiedmeyer over 5 years ago. Updated almost 2 years ago.

Status:
Closed
Priority:
High
Category:
Security
Target version:
Start date:
10/01/2015
Due date:
% Done:

0%

Estimated time:
Resolution:
wontfix
Device:
Grant:
Type of work:

Description

Replicant allows by default the installation of apps from unknown sources. As F-Droid nowadays works perfectly without this setting enabled, there is IMHO no reason to keep it enabled.

Having adb enabled by default might be a nice thing for developing and for advanced tasks, but it also adds a big attack vector. There are at the moment alone two open security bugs related to adb on this issue tracker and there might be more yet unpatched. People who need adb will very likely know how to enable it.


Files

#1

Updated by My Self over 5 years ago

Well, I'm not in doubt that this is correct, (please also check this post: http://redmine.replicant.us/boards/39/topics/8079?r=8895#message-8895).
But I think this could lead to some user-requests, because some wiki entries relating to the fact, that ADB is enabled by default. (OK the wiki entries could also be modified).

In short, I (personally) would appreciate this change for security reasons, too.

#2

Updated by Denis 'GNUtoo' Carikli over 5 years ago

  • Device Not device specific added
#3

Updated by Wolfgang Wiedmeyer about 4 years ago

  • Device added
  • Device deleted (Not device specific)

In Replicant 6.0, ADB is disabled by default and installation from unknown sources is disabled by default. The wiki pages are adapted accordingly.

#4

Updated by Wolfgang Wiedmeyer about 4 years ago

  • Target version set to Replicant 4.2
#5

Updated by Kurtis Hanna almost 2 years ago

  • Status changed from New to Closed
  • Resolution set to wontfix

This issue has been closed because Replicant 4.2 is no longer supported or maintained.

Also available in: Atom PDF