Live data from Hacker News

Android libstagefright still exploitable

blog.exodusintel.com

121–130 of 150 posts

Re: Android libstagefright still exploitable

#121
post #9

Is this timeline correct? April 2015 - Original stagefright exposed July 31st - Author noticed patch was not sufficient but could not test (did not notify google) August 6th - Patch released August 7th - Author notified google that patch was not adequate August 13th - Author went public?!?! They are counting the original date of exploitation as the start date for notification. I would think a more responsible and fri…

My last line would be:

August 13th - Still no response from google(!), disclosing publicly.

Basically that's integer type overflow, the moment I saw the four line patch, I knew what it was going to be. Everyone else would see that too cause it's a classic and can modify whatever exploit code they already have in a matter of minutes to work again.

I have a nit too. I don't like the term "responsible" used in this context. I prefer coordinated if anything. The responsible as in responsible disclosure is such a loaded term.

By the severity and simplicity here as well as the attention from the recent talk, this was a fine course of events in my personal opinion.

What I wish would have happened is someone at google would have done a better code review and caught the bug, it's pretty glaring as these things go, but still it happens all the time so considering that the patches were simply applied the next option I wish would have happened otherwise is that someone at google would have responded. In a case like this I would have liked to see a day or two at the most.

But none of that happened and considering the other concerns laid-out in the post, releasing the info publicly after almost a week is pretty responsible.

Re: Android libstagefright still exploitable

#122

Earlier quoted context omitted.

Google :does: control those devices. They're MADA agreement devices, which means Google approves every device that goes to sale, and Google approves every software update they release. Unfortunately, as a Verizon customer, I don't have a wide variety of options with unlockable bootloaders. And the battery life on the Turbo was simply, the only feature that mattered. Usually there's an unlock within a few months, but…

Obviously it wasn't the only feature that mattered, though? I mean, you're complaining about another feature right now. =) Like, I'm sympathetic, but this is a solvable problem with the information at hand. Buy phones with unlocked bootloaders. (As it happens, this is why I steer clear of Verizon...)

Heh, well, half a year later. I placed more faith in Android security than was warranted. Verizon is non-optional for me.

Re: Android libstagefright still exploitable

#123
post #113

Earlier quoted context omitted.

> I don't think delay is the problem - not being able to get or apply the patch yourself is the problem. Almost all users would be incapable of applying patches themselves.

> Almost all users would be incapable of applying patches themselves. There are currently 357,101 registered users on XDA developers. Saying "almost" every android user can't apply a patch is somewhat far fetched. Most procedures on XDA developers have a much better step by step documentation than most SDKs I've seen - and every time I've used them it's been successful. I've only had one issue regarding flashing a ra…

> Yes - there are grandmas and people who don't even know what Linux is would not be able to apply the patch themselves

Fascinating. What proportion of Android users do you think would be left unpatched?

Re: Android libstagefright still exploitable

#124

Earlier quoted context omitted.

because somehow magically an iphone is more secure because reasons? I agree that iphone's patching model is superior to android, but your statement shows a bit of ignorance.

Because they have a working patching model, yes.

What about the other 15% that don't receive patches of any kind? Should they remain vulnerable just because their devices are too old? I guess that "working patching model" has a time limit.

Re: Android libstagefright still exploitable

#125
post #72

Any competent malware developer must have already figured out how to exploit this the first time around. Now that every single one of those malware developers has learned it is still exploitable, the payload they've spent the past month perfecting can now be deployed in the wild. So, can someone explain why a disastrous worm hasn't already swept the globe and infected 99% of Android devices on the planet within ten m…

With selinux (as most android phones 4.4+ have) I imagine an exploit is not possible.

Re: Android libstagefright still exploitable

#126
post #58

Earlier quoted context omitted.

The isolation seems mostly defined by this SELinux policy: https://github.com/android/platform_system_core/blob/lollipo... service media /system/bin/mediaserver class main user media group audio camera inet net_bt net_bt_admin net_bw_acct drmrpc mediadrm ioprio rt 4 You'd need another exploit to elevate from SELinux (and I think send MSSes for a self-propagating worm). Though given Android's abysmal patching, most An…

That's not an SELinux policy? That's just a service statement for Android's init, defining the process' supplementary groups. There is no explicit seclabel I can deduce.

Whoops, yep -- definitely wasn't that clear. As pointed out below, the policy is linked to: https://android.googlesource.com/platform/external/sepolicy/...

Re: Android libstagefright still exploitable

#127
post #72

Any competent malware developer must have already figured out how to exploit this the first time around. Now that every single one of those malware developers has learned it is still exploitable, the payload they've spent the past month perfecting can now be deployed in the wild. So, can someone explain why a disastrous worm hasn't already swept the globe and infected 99% of Android devices on the planet within ten m…

From what I've read, and could be wrong, is you could be infected and not even know it. The attacker has the opportunity to "clean up" the MMS so you never even get a notification because the bug is before any of that kicks in.

Still, we'd see a bunch of reports from non-Android phones receiving MMS's from infected Android contacts.

Re: Android libstagefright still exploitable

#128
post #113

Earlier quoted context omitted.

> Almost all users would be incapable of applying patches themselves. There are currently 357,101 registered users on XDA developers. Saying "almost" every android user can't apply a patch is somewhat far fetched. Most procedures on XDA developers have a much better step by step documentation than most SDKs I've seen - and every time I've used them it's been successful. I've only had one issue regarding flashing a ra…

> Yes - there are grandmas and people who don't even know what Linux is would not be able to apply the patch themselves Fascinating. What proportion of Android users do you think would be left unpatched?

I think something got lost in translation - I'm not saying for the manufacturers NOT to release updates.

I'm advocating for the ability for people like me to be able to apply the patches manually - and thus as a result the ability to remove and tweak the underlying OS to my liking. As it stands right now I can't do that due to proprietary drivers.

> What proportion of Android users do you think would be left unpatched?

But I'll humor you. Analyzing the breakdown of Android devices [1] - I would argue at this point devices running 4.2.X and lower will never see another update (because 4.2 is almost 3 years old - if there is an upgrade available people haven't or will never upgrade). That is about 34% of Android devices who will, arguably, never see another update.

I do like how they left off Honeycomb (3.X) - I know for a fact there are still devices out there running it so that graph is a little off.

[1] http://www.droid-life.com/2015/08/03/android-distribution-au...

Re: Android libstagefright still exploitable

#129
post #14

Doesn't seem very responsible behavior by the reporter. Google accepted the suggested patches, fixed the original cases. Now some other cases are discovered for these larger numbers, OK, that seems like a new thing to fix next. Not sure why I have to read paragraphs of hate when the company put the suggested patches in already. Seems like just an excuse so they can ride the page view wave.

This doesn't seem hateful to me, and the problem is that google took so long to fix anything at all on top of barely caring about the fix. Why not fuzz the fixed version for 10 seconds?

Re: Android libstagefright still exploitable

#130
post #128

Earlier quoted context omitted.

> Yes - there are grandmas and people who don't even know what Linux is would not be able to apply the patch themselves Fascinating. What proportion of Android users do you think would be left unpatched?

I think something got lost in translation - I'm not saying for the manufacturers NOT to release updates. I'm advocating for the ability for people like me to be able to apply the patches manually - and thus as a result the ability to remove and tweak the underlying OS to my liking. As it stands right now I can't do that due to proprietary drivers. > What proportion of Android users do you think would be left unpatche…

> I think something got lost in translation

Oh, I get it, so when you said you don't think the delay is the problem, while quoting a sentence talking about getting the patch to users, you were in fact talking about what you wanted, not what would be good for general users.

Post reply on HN