Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> however be aware that lots of malware infected builds have made it to xda dev in the past,

Can you point me to some? How were they caught? I knew this was a possibility, but I hadn't seen it actually happen before.



Back in the days I was maintaining the driver support for Cyanogen for the MSM7227 based models and I found some builds on xda dev that came preinstalled with some RATs.

I only found out by coincidence of another dev asking me to verify the build. The nature of how Android is built (with all its hundreds of repositories) isn't made for verifiable builds, so it's really hard to prove or audit.

From what I've found usually the builds with custom UIs or skins on top are infected with stuff either the person packaging it doesn't know about (benefit of the doubt) or do, but it comes out a year later when someone skeptical checks for it.

Verification is especially hard because everybody on xda dev is using some paid adfly links or some google storage or dropbox links that will change in intervals (depending on how much traffic they produce they'll get blocked quickly).

So yeah, I think the need for a hash based end to end verification tool is kind of there.

But honestly I have no idea how to build it because even the partition setup of old flash storage using devices is so messed up that there can be side effects when an apk is put in /emulated storage folders.

I think the only future proof way to do this is going mainline like the postmarketOS devs try to do. But until we're there I'm probably dead of old age already. I don't believe in the Android ecosystem anymore, because this is a governance coordination problem that's not easily fixable. Hosting all outdated kernels alone with all the custom drivers is way too much traffic for any open source project to pay for.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: