Post #4122457
2026-07-26 22:39 UTC
@briankrebs@infosec.exchange Really dumb, but I believe most IDE > publish pipelines drop this in as Huawei isn’t permitted to use the same push notification infrastructure as most other Android versions.
Not a defence, and it’s lazy development.
But playing devils advocate you could argue Firebase is probably as risky if not more so, given what is on the other side of it. Might as well be “GitHub[dot]com/*”, it always makes me nervous.
Still, the evergreen statement that SBoMs and people that care about them are a dying breed.
Replies (2)
-
@ADHDruid@infosec.exchange 2026-07-26 22:43
@briankrebs@infosec.exchange also… I would assume, while I cringe in my toes, that BYOD is a factor in some segments of their ‘required install-base’. With or without Mobile Application Management, I could guess, but it’s even uglier.
-
@johntimaeus@infosec.exchange 2026-07-26 22:44
@ADHDruid@infosec.exchange @briankrebs@infosec.exchange Was there ever a time when sboms were happily roaming the earth? I was at a con two years ago and heard two major hardware mfgs say they were 1-2 years behind reaching their target of 80% sbom coverage