zlacker

[parent] [thread] 2 comments
1. lmm+(OP)[view] [source] 2016-01-10 22:09:26
What's the threat model there? It's not like Amazon are going to start stealing customer credit card numbers - if anything they're one of the few companies I'd trust to get security right. Tick the checkbox in settings, install the APK, untick the checkbox again. It's really not a lot of effort or risk.

(The most sensible-sounding negative claim I've heard is that Amazon do that so that they can do more invasive location tracking than Google permits (though the same kind that Google does themselves))

replies(2): >>sunnyp+We >>rdtsc+eh
2. sunnyp+We[view] [source] 2016-01-11 02:21:04
>>lmm+(OP)
I'm pretty sure you have to keep the checkbox unticked so that the Amazon app can install apks and even update itself. In fact Amazon's official documentation[1] for installing their app doesn't tell users to uncheck the checkbox. The way I see it, keeping the untrusted apks checkbox ticked is a massive security risk.

[1] https://www.amazon.com/underground

3. rdtsc+eh[view] [source] 2016-01-11 03:07:00
>>lmm+(OP)
> What's the threat model there?

* It annoys me as a consumer.

* It reeks of incomptency ( yeah, go and disable that security check that looks like it is there to prevent malicious software to be installed on your device, yeah, yeah, that one ).

* It is a convoluted process.

* It leaves my device vulnerable. Let's not speculate (like you did apparently) but copy and paste from their own source:

https://www.amazon.com/gp/feature.html?ie=UTF8&docId=1003016...

---

Update Phone Settings

    Go to your phone Settings page
    Tap Security or Applications (varies with device)
    Check the Unknown Sources box
    Confirm with OK
Step 2 Go to Downloads

    Open Downloads on your device by going to My Files or Files
    Tap on the Amazon App file (Amazon_App.apk)
    Tap Install when prompted
Step 3 Launch Underground App

    Tap Open to launch the Amazon Underground App
    Use the Menu on the left and select Apps & Games
---

Yeah, I don't see anything about the "untick the checkbox again" part.

[go to top]