Workflow
操作系统权限
icon
Search documents
AI智能体正重写手机安全规则,该不该让“豆包助手”模拟你的手指?
Di Yi Cai Jing· 2025-12-04 03:24
Core Viewpoint - The article discusses the implications of granting the INJECT_EVENTS permission to the "Doubao Assistant" on the Nubia M153 phone, highlighting potential security risks and the necessity of collaboration between AI developers and hardware manufacturers [1][2][3]. Group 1: Technical Aspects - The Nubia M153 has enabled the INJECT_EVENTS permission, allowing applications to simulate user input events, which is a high-risk permission in the Android system [2][3]. - This permission is typically reserved for system-level applications and requires the app to be signed with the manufacturer's system private key, making it a significant security concern if misused [3][6]. - Doubao Assistant's ability to operate like a native system component is contingent upon its collaboration with hardware manufacturers, which is essential for accessing such high-level permissions [3][4]. Group 2: Security Concerns - Granting INJECT_EVENTS permission to third-party applications could lead to severe security risks, such as unauthorized access to sensitive information like banking passwords [3][4]. - The article emphasizes the need for a dual authorization mechanism to ensure user safety when AI interacts with third-party applications [7]. - Experts express that while there are inherent risks, the collaboration between AI and hardware manufacturers can justify the need for such permissions in specific scenarios [4][7]. Group 3: Market Dynamics - The competition among mobile manufacturers, AI developers, and traditional app developers is characterized as a struggle for data access and user entry points [7]. - The current target audience for the Doubao Assistant is primarily developers, not ordinary consumers, indicating a niche market focus [8].