Alex Rivera | Logout

Android AIDL security

Asked 2012-09-06T05:58:36.817
9

Is there any security provided when an application calls a remote service using AIDL? Or is it simply like a malicious application could read the data?

Edit
Report

1 Answer

1

you could always filter in your methods to restrict the packages that are allowed. Throw a SecurityException if the package does not have permission

Collection<String> callingpackages = getCallingPackages();

if(!callingpackages.contains("yourpackagename"){
//Throw securityException.
}

And getCallingPackages

private Collection<String> getCallingPackages() {
     int caller = Binder.getCallingUid();
     if (caller == 0) {
         return null;
     }
     return Lists.newArrayList(mContext.getPackageManager().getPackagesForUid(caller));
 }
answered 2012-09-06T06:23:21.147

Your Answer