

They are a bit vague on this but I suspect all of these attack vectors start with LEOs having physical access to the unlocked phone. They then set up a trusted desktop without the phone owners knowing.
Which is clever, to be fair. Whether or not that’s legal is already a court case. The law is so frightfully grey.



I think if I was caught like this, the last thing I’d want to do is talk to the media about it. Not even under a pseudonym. But this story is probably not here to make Google feel bad and return some of the money. This is a reminder for parents everywhere to review payment and parental settings on anything their kids use online. You can be smug enough to say my 8yo doesn’t stream on Twitch or whatever because why tf would you let them anyway. But you’re deleting the credit card off of Google Play because you forgot it was there because parenting makes you forgetful at times.