Live data from Hacker News

More Than 1M Google Accounts Breached by Gooligan

blog.checkpoint.com

101–110 of 183 posts

Re: More Than 1M Google Accounts Breached by Gooligan

#101
post #91

Earlier quoted context omitted.

You definitely can't win, but those two complaints are not mutually exclusive. Instead of locking down apps to solve the first problem, in theory Microsoft could have redesigned Windows to make third party executables less of a risk. Obviously that's harder, but it's not hypocritical to make both those statements.

I'm not exactly a fan of those, but I think MS is already doing that with UWP, which apps weren't exactly greeted with rejoice.

UWP apps can't be run outside of the MS store. So that's the lock-in he was talking about. It would be nice if Microsoft enabled "mini-VMs" for legacy x86 apps at least.

That way it could shoot two birds with one stone - make x86 apps a little slower and more resource intensive, and thus give both users and developers a reason to switch to UWP, while at the same time it would also make legacy x86 apps vastly more secure.

Re: More Than 1M Google Accounts Breached by Gooligan

#102
post #98
post #87

Earlier quoted context omitted.

What's "insane" about explicitly having to opt-in to 3rd party application installs in Android ? That switch existed for years and was praised upon. The media opinion only shifted after Android becoming most widely distributed phone OS. It's just easy clicks. Android is fine.

I agree with the first comment, but Android is "not fine". The lack of a sane updating model is a real security problem.

Yeah, Android's not fine. The business model, the weak full disk encryption, inability to set strong FDE password separate from your pin, centralization around Google Play Services, moving AOSP into GAPPS iteratively, forced obsolecense via carriers/hardware producers

Long way to go.

Re: More Than 1M Google Accounts Breached by Gooligan

#103
post #77
post #29

Earlier quoted context omitted.

Thanks for making this comment. This post is a wonderful example of the rampant marketing that has given the security industry a bad name. - The title is technically accurate, which is the best kind of accurate for clickbait. This is not a novel vulnerability representative of an application security flaw within Google - the malware campaign specifically targets older devices using previously known vulnerabilities.[1…

The fact that most consumers aren't aware they most Android devices are susceptible to these kind of vulnerability argues for more noise about these issues - not calming press releases talking about how the issues are moot with the latest build.

> The fact that most consumers aren't aware they most Android devices are susceptible

Are they really? I've assumed that I'm taking the same risks installing an app on Android as running a .exe on Windows.

Re: More Than 1M Google Accounts Breached by Gooligan

#104
post #101
post #91

Earlier quoted context omitted.

I'm not exactly a fan of those, but I think MS is already doing that with UWP, which apps weren't exactly greeted with rejoice.

UWP apps can't be run outside of the MS store. So that's the lock-in he was talking about. It would be nice if Microsoft enabled "mini-VMs" for legacy x86 apps at least. That way it could shoot two birds with one stone - make x86 apps a little slower and more resource intensive, and thus give both users and developers a reason to switch to UWP, while at the same time it would also make legacy x86 apps vastly more sec…

I think you can sideload them since 1607 (or even 1511?), there's a developer switch in new Control panel for that.

Re: More Than 1M Google Accounts Breached by Gooligan

#106
The difference between iOS and android could not be more clear in this regard. It's interesting to see the difference in security between the two. It's night and day. Google has some serious problems to address. But it seems like they don't care. Their track record is deplorable regarding android security. Is this really the best google can do?

Re: More Than 1M Google Accounts Breached by Gooligan

#107
post #99
post #84

Earlier quoted context omitted.

That's not to say Google has no responsibility in this. Google's OS has a terrible security-update policy. Being able to buy a new computing device from a store that will receive no security updates is terrible, and is fairly common in Android devices. Now, there are valid technical reasons that Google can't be as good as Microsoft at pushing out updates to every device running their OS, but still, it's hard to say t…

Google in most cases is not the device's manufacturer, and in a mobile device OS and application SW are tightly coupled, so you cannot really have OS updates separate from firmware updates, bypassing the actual manufacturer's own updates. Google (and Apple and Microsoft) can totally do it for devices that manufactures and maintains on its own, and actually it is one of the selling points of their new phone. In additi…

Google have an approval system before they allow a manufacturer to bundle Google services. Update mechanisms could easily be built into that approval process. I suspect that they haven't turned the screws too hard on manufacturers for fear of Samsung or LG making an Amazon-style fork.

Google have already drawn their own roadmap with the Android One project - a number of low-end manufacturers have devices that get updates directly from Google. They could easily create a Nexus-type brand that manufacturers can opt into, guaranteeing timely updates and long-term support. This could be a big draw for mid-tier manufacturers.

https://en.wikipedia.org/wiki/Android_One

Re: More Than 1M Google Accounts Breached by Gooligan

#108
post #60

Earlier quoted context omitted.

"Windows is a mess because you can install a virus executable on it." "You can't install Windows software outside App Store anymore, MS is taking muh freedoms." You can't win.

You definitely can't win, but those two complaints are not mutually exclusive. Instead of locking down apps to solve the first problem, in theory Microsoft could have redesigned Windows to make third party executables less of a risk. Obviously that's harder, but it's not hypocritical to make both those statements.

The problem with that is that you can't tell programmatically if a potentially risky action is performed by a program acting as the user's agent or by a program acting on behalf of some malicious fuckwit.

You can just forbid it, sure, but then you're reducing the usefulness of your platform.

Re: More Than 1M Google Accounts Breached by Gooligan

#109
post #60

Earlier quoted context omitted.

"Windows is a mess because you can install a virus executable on it." "You can't install Windows software outside App Store anymore, MS is taking muh freedoms." You can't win.

You definitely can't win, but those two complaints are not mutually exclusive. Instead of locking down apps to solve the first problem, in theory Microsoft could have redesigned Windows to make third party executables less of a risk. Obviously that's harder, but it's not hypocritical to make both those statements.

[deleted]

Re: More Than 1M Google Accounts Breached by Gooligan

#110

Earlier quoted context omitted.

Do you actually know which stores they mean? I'd hate for F-Droid to be vilified. F-Droid isn't just a store, it's an Android Repository Browser[1]. It would be a shame if the F-Droid repository was exploited beyond the concessions[2] that they allow. [1] https://f-droid.org/wiki/page/Known_Repositories [2] https://f-droid.org/wiki/page/Antifeatures

I do not, just wanted to throw a couple that I know of out there. Hopefully neither of those third party stores because I like and use them both. I hope it was clear from the question marks in my post that those were just examples, certainly don't want to smear either one.

If you're going to name app stores, I would think places like Baidu would be more likely, given their size and popularity with users of lower-tier Android devices.
Post reply on HN