Adventures In Distributed Garbage Collection

Binary XML


The Great Android Security Hole Of ’08 ?

  1. ZIP Files
  2. Signed JARs
  3. dalvik.system.PathClassLoader
  4. What Exactly Is/Was The Problem ?
  5. And The Answer Is …
  6. The Gory Details — The APK Verification Considered Ineffective Edition
  7. The Gory Details — The Loading The Classes From The ‘Wrong’ classes.dex Edition
  8. Signed JAR Verification Revisited
  9. The Root Cause ? — Signed JARs Considered Harmful
  10. Appendix: JAR Signing The Easy Way (TM)

