The difference between iOS and android could not be more clear in this regard. It's interesting to see the difference in security between the two. It's night and day. Google has some serious problems to address. But it seems like they don't care. Their track record is deplorable regarding android security. Is this really the best google can do?
Most android isn't stock and there are a ton of old versions out there so it's a little apple to oranges. I think if you would have a phone created by google and keep it up to date it would probably be pretty secure.
More Than 1M Google Accounts Breached by Gooligan
151–160 of 183 posts
Re: More Than 1M Google Accounts Breached by Gooligan
#152Malware on your Android device picked up from third party app stores (FDroid? Amazon?) that steals email accounts and auth tokens. Looks like it only works on the older Android 4 Jellybean software (and some Android 5 Lollipop) and below, so mostly concentrated in Asia where there are lower-end phones. You can see if your account has been affected here: https://gooligan.checkpoint.com/
As such an Android device can be used (in a useful way) without having Google Play services (or, for that matter, any other Google apps) installed. I've been doing just that for more than 5 years now without having the feeling I'm missing out on something.
AOSP or a tailor-made Cyanogenmod (with all the Cyanogen-account related stuff removed) plus F-Droid gives you a perfectly usable device.
Re: More Than 1M Google Accounts Breached by Gooligan
#153The difference between iOS and android could not be more clear in this regard. It's interesting to see the difference in security between the two. It's night and day. Google has some serious problems to address. But it seems like they don't care. Their track record is deplorable regarding android security. Is this really the best google can do?
Most android isn't stock and there are a ton of old versions out there so it's a little apple to oranges. I think if you would have a phone created by google and keep it up to date it would probably be pretty secure.
Re: More Than 1M Google Accounts Breached by Gooligan
#154I used to work in an ad-tech company focused on mobile cpi offers that for several months paid the salaries of everyone involved by injecting malware in cracked apps on several third party app stores (they were making a profit out of it enough to dedicate a team only for this). They even managed to automate all the process of "selling" cracked apps on third party stores. It is amazing how easy it is to trick broke 13…
Re: More Than 1M Google Accounts Breached by Gooligan
#155Just to be clear, they didn't obtain any passwords, but auth tokens. This would potentially allow them to log into accounts, but only as long as the tokens are valid. Also, they don't reveal which "third party app stores" served infected apps, but they do provide a list of infected apps, and searching for these yields some real shady download sites: http://imgur.com/a/0luW3
Couldn't Google just revoke all of those access tokens? It'd be a minor inconvenience for some, but it would hardly be a big deal, right? You'd just have to grant access again.
Re: More Than 1M Google Accounts Breached by Gooligan
#156Earlier quoted context omitted.
That's not to say Google has no responsibility in this. Google's OS has a terrible security-update policy. Being able to buy a new computing device from a store that will receive no security updates is terrible, and is fairly common in Android devices. Now, there are valid technical reasons that Google can't be as good as Microsoft at pushing out updates to every device running their OS, but still, it's hard to say t…
> Being able to buy a new computing device from a store that will receive no security updates is terrible, and is fairly common in Android devices. This seems like the kind of problem the free market could solve. Just get one phone vendor to guarantee secruity updates for a few years and then some customers will start buying those phones. After a while other vendors will start promising it or losing sales.
Re: More Than 1M Google Accounts Breached by Gooligan
#157Re: More Than 1M Google Accounts Breached by Gooligan
#158And still people complain that Apple refuses to allow third-party app stores.
Re: More Than 1M Google Accounts Breached by Gooligan
#159Malware on your Android device picked up from third party app stores (FDroid? Amazon?) that steals email accounts and auth tokens. Looks like it only works on the older Android 4 Jellybean software (and some Android 5 Lollipop) and below, so mostly concentrated in Asia where there are lower-end phones. You can see if your account has been affected here: https://gooligan.checkpoint.com/
Thanks for making this comment. This post is a wonderful example of the rampant marketing that has given the security industry a bad name. - The title is technically accurate, which is the best kind of accurate for clickbait. This is not a novel vulnerability representative of an application security flaw within Google - the malware campaign specifically targets older devices using previously known vulnerabilities.[1…
You're drawing arbitrary lines around what Google is responsible for and what the user is responsible for, and ultimately blaming the user for having an "older device". But guess what? This problem doesn't affect iOS products anywhere nearly as much, even though there are hundreds of millions of older devices in use. That's because Apple took an approach that allowed them to ensure devices stay up to date. Google didn't. And that's as important to security as is UX design and all the other often-dismissed factors that go into achieving successful security outcomes.
Re: More Than 1M Google Accounts Breached by Gooligan
#160I used to work in an ad-tech company focused on mobile cpi offers that for several months paid the salaries of everyone involved by injecting malware in cracked apps on several third party app stores (they were making a profit out of it enough to dedicate a team only for this). They even managed to automate all the process of "selling" cracked apps on third party stores. It is amazing how easy it is to trick broke 13…
This is one of the reasons we may need to look into self-regulation. Name them?