Live data from Hacker News

UC Browser for Android, Desktop Exposes 500M Users to MiTM Attacks

bleepingcomputer.com

11–20 of 62 posts

Re: UC Browser for Android, Desktop Exposes 500M Users to MiTM Attacks

#12
post #8
post #4

People really use this browser?

I think that I have read that it is really famous in India.

Yes. The userbase has grown bigger more recently due to the browser's free in-built VPN being used to circumvent the government's ban on ~800 porn sites[1].

[1] https://timesofindia.indiatimes.com/india/govt-plays-net-nan...

Re: UC Browser for Android, Desktop Exposes 500M Users to MiTM Attacks

#13
I really hope this substantially reduces the number of users, or Google takes the app down completely. The browser is ridiculously terrible: both from the user and the developer point of view.

The browser constantly spams the phone with irrelevant, clickbait news articles/ads (and yet it's so popular). The developers (especially in India) cannot ignore the browser because of its large userbase, and then that's one more browser you have to look after.

Re: UC Browser for Android, Desktop Exposes 500M Users to MiTM Attacks

#14

> using unprotected channels It's not man in the middle. I have seen this mistake a lot lately. Man in the middle only involves encryption. Otherwise it is just injection or redirection. It is not a man in the middle attack merely because something happened in the middle of a transmission. There is always stuff that happens in the middle of transmission if you want to get technical about packet switching ARP resoluti…

What are you talking about... It is man in the middle. This attack is a lot older than encryption, so if you think encryption is required then you've made a big mistake. It refers to literally a person intercepting your message before (or instead of) it reaching the intended audience.

Re: UC Browser for Android, Desktop Exposes 500M Users to MiTM Attacks

#15

> Android apps "distributed via Google Play may not modify, replace, or update itself using any method other than Google Play's update mechanism. Likewise, an app may not download executable code (e.g. dex, JAR, .so files) from a source other than Google Play." Obvious question: why did this get approved, and will Google amend their process to close this loophole?

Fwiw, Firefox Mobile lets you download add-ons and plugins, as well, that modify behaviour of the app. Not sure what justification UCWeb might have given here to Google, though, it is more likely that with certain apps, external install, command, and control is a valid and exceptional use-case.

Firefox extensions are just JS executed in a sandboxed runtime though..

By that logic you could argue webpage's JS are downloadable plugins that modify the behavior of the browser while it displays HTML content :)

Re: UC Browser for Android, Desktop Exposes 500M Users to MiTM Attacks

#18
post #8

Earlier quoted context omitted.

I think that I have read that it is really famous in India.

Yes. The userbase has grown bigger more recently due to the browser's free in-built VPN being used to circumvent the government's ban on ~800 porn sites[1]. [1] https://timesofindia.indiatimes.com/india/govt-plays-net-nan...

Well that's one way to grow...

Re: UC Browser for Android, Desktop Exposes 500M Users to MiTM Attacks

#19

> using unprotected channels It's not man in the middle. I have seen this mistake a lot lately. Man in the middle only involves encryption. Otherwise it is just injection or redirection. It is not a man in the middle attack merely because something happened in the middle of a transmission. There is always stuff that happens in the middle of transmission if you want to get technical about packet switching ARP resoluti…

Not going to down-vote just because you’re wrong, since you bring up a cogent argument. But it’s still wrong nevertheless. I’ve skimmed the linked Wikipedia article. Could you quote from that article that MITM requires intercepting a certificate or key request?

Re: UC Browser for Android, Desktop Exposes 500M Users to MiTM Attacks

#20
post #14

> using unprotected channels It's not man in the middle. I have seen this mistake a lot lately. Man in the middle only involves encryption. Otherwise it is just injection or redirection. It is not a man in the middle attack merely because something happened in the middle of a transmission. There is always stuff that happens in the middle of transmission if you want to get technical about packet switching ARP resoluti…

What are you talking about... It is man in the middle. This attack is a lot older than encryption, so if you think encryption is required then you've made a big mistake. It refers to literally a person intercepting your message before (or instead of) it reaching the intended audience.

Older than encryption? Encryption has existed since before the Roman empire.

> It refers to literally a person intercepting your message before (or instead of) it reaching the intended audience.

Every time somebody has pointed that out they have extracted that definition from the term opposed to referencing the term from a definition. It is similar to answering a question with only a restatement of the question.

Post reply on HN