Yeah. I can absolutely see the problem with ms granularity timers, but they're refusing to allow any bucketed information at all. You get three-hour bucketed battery use data and that's it. Not great for "why is this device laggy right now".
-
-
-
Replying to @RichFelker @jonathanstray
Rooting massively reduces the effective security of the device. Even turning on dev tools isn't a great idea, which your now have to do to even get memory usage.
1 reply 0 retweets 5 likes -
Replying to @Dymaxion @jonathanstray
Depending on your threat model, possibly. But Google doesn't give good alternatives to know or trust what your own device is doing & they're hardly trustworthy.
1 reply 0 retweets 0 likes -
It is relatively plausible that they’re putting out a panic patch because mobile is dreadfully affected.
2 replies 0 retweets 3 likes -
No, this was with Oreo as a whole, and it doesn't feel like an emergency mitigation. And second+ granularity buckets aren't conceivably a side channel.
1 reply 0 retweets 0 likes -
I've been arguing for coarse grain time buckets against side channels for years, so I don't disagree. But Android's almost certainly rife with thousands of variations of attacks here. Coarse grain reactions also include turning it off until you understand it better.
1 reply 0 retweets 1 like -
Yeah. I don't get the feeling that's what they're doing, though.
2 replies 0 retweets 0 likes -
to clarify: are you talking about procfs hardening with hidepid? and are you saying that you'd want them to add a replacement API with artificially coarse CPU usage information?
1 reply 0 retweets 0 likes -
Yes. To let users understand what the system is doing. Not necessarily even accessible from non-SYSTEM apps.
1 reply 0 retweets 1 like
FWIW, even on release builds, you can enable USB debugging in the settings, "adb shell" into the phone over USB and run "top". the adb shell account has access to the "readproc" group, which bypasses hidepid. (yes, that might be less nice to use than an app on the phone.)
-
-
Yeah. I'd honestly rather leave dev mode off on phones I use for real work, but it's also not an even semi-normal user solution.
0 replies 0 retweets 0 likesThanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.