Live data from Hacker News

Malicious apps infect 25M Android devices with 'Agent Smith' malware

phys.org

21–30 of 222 posts

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#21
post #2

> Google already fixed at least one of the Android exploits used by "Agent Smith," nicknamed Janus, in 2017 but the fix hasn't made its way onto every Android phone. It's a potent reminder that millions of phones around the world are being used without the latest security measures. Because Samsung (or similar) or even more weirdly, Sprint (or similar) just doesn't fucking update our Android versions for months, or ev…

I bought a new Android table from Samsung 3 years ago for more daughter - when bought it had a 2 year old version of Android on and enquiries from Samsung UK said it would not be updated. My daughter is still using it today, unupdated from 5 years ago. We tend to be an Apple household Edit - the Device, bought in September 2016 was a Samsung Galaxy TAB E 9.6 SM-T560 WI-FI - I will check the software level tonight.

Yeah, I'm doubting that.

Go into settings, about device and check the Security Patch Level.

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#22
post #2

> Google already fixed at least one of the Android exploits used by "Agent Smith," nicknamed Janus, in 2017 but the fix hasn't made its way onto every Android phone. It's a potent reminder that millions of phones around the world are being used without the latest security measures. Because Samsung (or similar) or even more weirdly, Sprint (or similar) just doesn't fucking update our Android versions for months, or ev…

That’s the problem. Why should your carrier have any say so in updating your operating system? If I buy a computer from Best Buy, I don’t have to wait for them to push an update to Windows.

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#24

Earlier quoted context omitted.

better than ios updates making the phone unusable. happened to me on old ipod touch models, not even the battery thing.

> Not even the battery thing. That was an attempt at graceful degradation that wasn’t communicated well. The general belief was that having a phone that runs a bit more slowly, but consistently used it’s battery as the battery life naturally degrades is better than a phone suddenly dying with 40% battery remaining if the peak power draw exceeds what a several year old lithium ion battery can produce. I much prefer th…

It's probably true that this was more an image problem than an actual misdeed, but the outcry was symptomatic of consumers' deep mistrust of tech companies' intentions. Some of that is because, to most people, a computing device is a black box, but some of it is because they've been burned before.

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#25
post #2

> Google already fixed at least one of the Android exploits used by "Agent Smith," nicknamed Janus, in 2017 but the fix hasn't made its way onto every Android phone. It's a potent reminder that millions of phones around the world are being used without the latest security measures. Because Samsung (or similar) or even more weirdly, Sprint (or similar) just doesn't fucking update our Android versions for months, or ev…

I've never understood this as a design decision -- why does Google allow companies to block updating of Android?

Presumably the idea is 'block updates to force hardware sales'?

I can't update my Honor, I think it's the service provider (the phone was on contract) who block the update, but it was easy to update (both Android and EMUI) using an app in the Google Play store to a full version higher, but whoever created that update hasn't done further ones. It is a hack though, there should be a way to do it officially.

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#26

Earlier quoted context omitted.

better than ios updates making the phone unusable. happened to me on old ipod touch models, not even the battery thing.

> Not even the battery thing. That was an attempt at graceful degradation that wasn’t communicated well. The general belief was that having a phone that runs a bit more slowly, but consistently used it’s battery as the battery life naturally degrades is better than a phone suddenly dying with 40% battery remaining if the peak power draw exceeds what a several year old lithium ion battery can produce. I much prefer th…

I had a first or second gen iPod Touch and it became unusably slow right after updating it some time later.

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#29
post #19
post #13

Earlier quoted context omitted.

Firefox mobile + uBlockOrigin or uMatrix

Not rooted, and this is the best option. Tried Blokada and it was just frustrating to use.

You're absolutely right, thanks for catching this. Firefox' addon system is a real boon and the solution that works if you can't/don't want to root.

Before that I was getting frustrated by filtering pseudo-VPN apps and rooting is not an option anymore (sec-wise and because of Google SafetyNet).

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#30
post #2

> Google already fixed at least one of the Android exploits used by "Agent Smith," nicknamed Janus, in 2017 but the fix hasn't made its way onto every Android phone. It's a potent reminder that millions of phones around the world are being used without the latest security measures. Because Samsung (or similar) or even more weirdly, Sprint (or similar) just doesn't fucking update our Android versions for months, or ev…

That’s the problem. Why should your carrier have any say so in updating your operating system? If I buy a computer from Best Buy, I don’t have to wait for them to push an update to Windows.

Because carriers have a tremendous fear of being simple data pipes.
Post reply on HN