Live data from Hacker News

More Than 1M Google Accounts Breached by Gooligan

blog.checkpoint.com

171–180 of 183 posts

Re: More Than 1M Google Accounts Breached by Gooligan

#171
post #101

Earlier quoted context omitted.

UWP apps can't be run outside of the MS store. So that's the lock-in he was talking about. It would be nice if Microsoft enabled "mini-VMs" for legacy x86 apps at least. That way it could shoot two birds with one stone - make x86 apps a little slower and more resource intensive, and thus give both users and developers a reason to switch to UWP, while at the same time it would also make legacy x86 apps vastly more sec…

Windows 10 allows you to turn on sideloading. Going through the Windows Store is no longer a requirement.

but then again, how is that different from android of today?

Re: More Than 1M Google Accounts Breached by Gooligan

#172
post #133

Earlier quoted context omitted.

That is specifically a design flaw in the AOSP. Right now manufacturers have to integrate their custom device drivers into every new OS build, leading to long delays and fragmentation. The device drivers should be separate, and the OS should expose a stable API and integration points. That way OS upgrades could be pushed out without breaking everything, just like with desktop OSs.

That's not Google's policy, it's Linux. What you suggest would mean abandoning Linux as a kernel. I'd be all for it - the industry needs some more open source kernel competition.

Linux is a bad choice for a half-open environment. Either it's totally open (like most Linux distros) or everything is done by the manufacturer (like routers). But not this garbage with closed source drivers that will prevent you from recompiling eventually somewhere in the future.

Re: More Than 1M Google Accounts Breached by Gooligan

#173
post #60
post #40

We were just reading "Android security in 2016 is a mess"[1] 2 days ago and now we have another great example for it. https://news.ycombinator.com/item?id=13056288

"Windows is a mess because you can install a virus executable on it." "You can't install Windows software outside App Store anymore, MS is taking muh freedoms." You can't win.

Except Microsoft provides updates for Windows longer than any other popular desktop or mobile operating system. So if crap gets installed because of an OS vulnerability either you didn't update or it that flaw will be patched as soon as possible.

Re: More Than 1M Google Accounts Breached by Gooligan

#174
post #116
post #112

Earlier quoted context omitted.

It is just a text. How do you know ?

What is the downside of someone having your email address, especially with no other context. If they have other data on your email address, they don't need your email address to do anything with it. If they don't have other data, then there's no issue. You're not concerned about people having public access to your twitter handle, why would you be concerned about people having public access to your email address.

Twitter handle is public. Email addy can be private.

Re: More Than 1M Google Accounts Breached by Gooligan

#175
post #106

The difference between iOS and android could not be more clear in this regard. It's interesting to see the difference in security between the two. It's night and day. Google has some serious problems to address. But it seems like they don't care. Their track record is deplorable regarding android security. Is this really the best google can do?

Most android isn't stock and there are a ton of old versions out there so it's a little apple to oranges. I think if you would have a phone created by google and keep it up to date it would probably be pretty secure.

I didn't hear any customer beg for a customized version of Android. Rather "stock Android" seems to be a selling point nowadays.

It's just a bunch of marketing weenies looking for "an unique opportunity to put focus on the brand". Seldom I see things (like multitasking in some Samsung devices before it came to Android) that would really help the end user.

Re: More Than 1M Google Accounts Breached by Gooligan

#176
post #133

Earlier quoted context omitted.

That is specifically a design flaw in the AOSP. Right now manufacturers have to integrate their custom device drivers into every new OS build, leading to long delays and fragmentation. The device drivers should be separate, and the OS should expose a stable API and integration points. That way OS upgrades could be pushed out without breaking everything, just like with desktop OSs.

That's not Google's policy, it's Linux. What you suggest would mean abandoning Linux as a kernel. I'd be all for it - the industry needs some more open source kernel competition.

No one is stopping Google from forking Linux, or using a different OS kernel.

Re: More Than 1M Google Accounts Breached by Gooligan

#177

Earlier quoted context omitted.

> and in a mobile device OS and application SW are tightly coupled I call bullshit. There's no reason Google can't update everything AOSP-y in /system - libc, libart, libwebkit etc. > Google (and Apple and Microsoft) can totally do it for devices that manufactures and maintains on its own That's a low bar. When you buy a Dell laptop, you continue to receive updates from Microsoft. This is the bar we should hold Googl…

> and in a mobile device OS and application SW are tightly coupled I call bullshit. There's no reason Google can't update everything AOSP-y in /system - libc, libart, libwebkit etc. That's not the point. Even if it were so, it's still responsibility of the manufacturer to integrate it in its own firmware and push the update with the carrier's approval. You are comparing a laptop to a smartphone, which makes no sense,…

No that's not how it works. Apple can push any iPhone firmware updates they want to without carrier approval.

Re: More Than 1M Google Accounts Breached by Gooligan

#178
post #156
post #114

Earlier quoted context omitted.

> Being able to buy a new computing device from a store that will receive no security updates is terrible, and is fairly common in Android devices. This seems like the kind of problem the free market could solve. Just get one phone vendor to guarantee secruity updates for a few years and then some customers will start buying those phones. After a while other vendors will start promising it or losing sales.

No it doesn't, because most everyday users don't give a toss about security. It has to be something that is pushed as a best-practice by those who know better, not something that is demanded by an everyday user who doesn't. The invisible hand won't do shit here.

If this were entirely true then people wouldn't buy home security systems or safety deposit boxes.

Re: More Than 1M Google Accounts Breached by Gooligan

#179
post #177

Earlier quoted context omitted.

> and in a mobile device OS and application SW are tightly coupled I call bullshit. There's no reason Google can't update everything AOSP-y in /system - libc, libart, libwebkit etc. That's not the point. Even if it were so, it's still responsibility of the manufacturer to integrate it in its own firmware and push the update with the carrier's approval. You are comparing a laptop to a smartphone, which makes no sense,…

No that's not how it works. Apple can push any iPhone firmware updates they want to without carrier approval.

You are right in the case of Apple, but I don't think it is the normal process.

Although my experience in this matter is limited, this is was I was able to find:

https://www.quora.com/Why-is-it-that-Apple-can-push-out-upda...

Re: More Than 1M Google Accounts Breached by Gooligan

#180
post #131

Earlier quoted context omitted.

I never heard that about voting machines. Do you have a source for that? I'm not sure why that's more surprising than hearing that they run Windows XP...

These are the certified electronic voting machines (DREs) for Pennsylvania: http://www.dos.pa.gov/VotingElections/OtherServicesEvents/Pa... The Android device in use is the EA Tablet. The certification tests are listed in "EA TABLET FOR ANDROID WITH JELLYBEAN 4.2.1 ELECTRONIC Test Report," dating from 2013. To be fair, it's probably the best of the horrible lot in security, but that ain't saying much. For example, th…

Now I really want to post this to /r/politics or one of the jill stein subs, with a title like "PENN VOTING MACHINES COULD HAVE EASILY BEEN HACKED, THE VOTES ARE INVALID".

It would get upvoted, perhaps to the front page, and then news outlets would likely pick up the story.

Post reply on HN