Last year, security researchers found that over 2 million Android devices were silently infected by malware that entered through exposed ADB ports. That's not a theoretical risk—it's a real attack vector that's already been exploited at scale.
The argument that restricting developer tools is an overreach misses the point. It's not about limiting what developers can do. It's about making sure the default setting doesn't leave a door wide open for anyone with a simple script. Developers can toggle it back on in seconds. For the average user, though, that default could mean the difference between a secure device and one that's silently sending their data somewhere else.
We accept similar defaults in all kinds of software. Windows doesn't enable Remote Desktop out of the box. Macs have System Integrity Protection on by default. This is the same principle: sensible defaults that protect people without getting in the way of those who know what they're
08:04 AM