Get the latest tech news

Trusting clients is probably a security flaw


If your service needs to trust the clients, hold my Big Mac

The result of such open-ness is that an entire series of services that need to trust the client (used in the oauth sense of the word) are not available to web apps. For example, some of the RootBeer checks will trigger on some unmodified Xiaomi, Asus, or Fairphone, or random cheap phones that happened to be in someone's nearest Tesco. Their devices by default do not have Google Play Services that can be tricked like this, and will require more work than I described to pass these checks.

Get the Android app

Or read this on Hacker News

Read more on:

Photo of Security flaw

Security flaw

Photo of Trusting clients

Trusting clients

Related news:

News photo

The company that sold cameras with ‘terrible’ security flaw has a new problem

News photo

D-Link says it won’t fix a serious security flaw affecting 60,000 older NAS devices

News photo

Researcher reveals ‘catastrophic’ security flaw in the Arc browser