Live data from Hacker News

Malicious apps infect 25M Android devices with 'Agent Smith' malware

phys.org

51–60 of 222 posts

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#51

Earlier quoted context omitted.

I've never understood this as a design decision -- why does Google allow companies to block updating of Android? Presumably the idea is 'block updates to force hardware sales'? I can't update my Honor, I think it's the service provider (the phone was on contract) who block the update, but it was easy to update (both Android and EMUI) using an app in the Google Play store to a full version higher, but whoever created…

It hasn't made any sense to buy phones from the company that provides your mobile phone service for years, especially now that a "phone" isn't in any meaningful sense a phone at all with many people never making or receiving any calls. They shouldn't be any more involved in what phone you use than your ISP gets to pick whether you use a Mac or PC. Sure if you want to use a 15 year old phone you're going to need to fi…

A cellular phone is also a network terminal.

A misbehaving device can cause unreasonable load on the network, a disruption to other users, or at least interruption of the service on your device.

When Apple does screw up and iOS update will leave you with no data, the operators will attempt to make it work; they won't do that for every random manufacturer though.

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#52

Earlier quoted context omitted.

>which extends the life of old phones. Except they were caught purposely throttling older phones with those updates, not exactly what i'd call extending life.

> purposely throttling So that the phones don't randomly shut off because their lithium ion batteries were old. Yes, they should have told people but it wasn't done maliciously.

That's easy... make the batteries easily replaceable... oh wait.

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#53
post #2

> Google already fixed at least one of the Android exploits used by "Agent Smith," nicknamed Janus, in 2017 but the fix hasn't made its way onto every Android phone. It's a potent reminder that millions of phones around the world are being used without the latest security measures. Because Samsung (or similar) or even more weirdly, Sprint (or similar) just doesn't fucking update our Android versions for months, or ev…

That’s the problem. Why should your carrier have any say so in updating your operating system? If I buy a computer from Best Buy, I don’t have to wait for them to push an update to Windows.

The carrier wants your phone to work on their network. A software update could change brick the radio (or just disable the channel they are using) if done wrong.

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#54

Earlier quoted context omitted.

That’s the problem. Why should your carrier have any say so in updating your operating system? If I buy a computer from Best Buy, I don’t have to wait for them to push an update to Windows.

Good question. When a phone stops working, people want their money back. Guess where most people in most markets buy their phone from? Further, who do you think customer's call for support? Now you know why carriers are hesitant about frequently updating a product they've already made a sale on. If an update breaks something, guess who pays the price? Not defending them, and it's not the only reason, but it's a big o…

Which is why I prefer to buy my phone independently from the carrier service.

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#55
post #38

Earlier quoted context omitted.

> Not even the battery thing. That was an attempt at graceful degradation that wasn’t communicated well. The general belief was that having a phone that runs a bit more slowly, but consistently used it’s battery as the battery life naturally degrades is better than a phone suddenly dying with 40% battery remaining if the peak power draw exceeds what a several year old lithium ion battery can produce. I much prefer th…

> That was an attempt at graceful degradation that wasn’t communicated well. That was nearly outright fraud which went swimmingly well. The big issue wasn't so much the unannouced throttling. It was that Apple knew that a lot of customers had battery issues but misled them (by denying the entire issue) so that they'll buy a new device. Instead, the debate turned on slightly more defencible for Apple. Slightly more de…

Apple has had a battery replacement option for quite a few years. Apple Store employees don't work on commission, so a customer coming in with a battery problem would most likely be offered the battery replacement option before being sold a new phone.

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#56
post #37
post #10

Earlier quoted context omitted.

Which device? That doesn't sound right. We're in a more or less identical situation, with Galaxy Tab S2's for the kids that we bought three years ago. And indeed, they're running comparatively ancient Android 7.0 images and will never see a version bump again. They do, however, continue to see security updates. And in particular they've been patched against the vulnerability in the linked article. I'd be very surpris…

> comparatively ancient Android 7.0 7.0 is ancient? 5.1, or rather 4.4 is ancient.

Android with a version number is ancient; current Androids have single letters in their name.

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#57

Whenever I read about Greenpeace attacking apple for their phones I laugh. The number of Android models, made with far more toxic materials, never updated and so obsoleted much earlier (check out secondary market for 4 year old phones to see this) is far higher and with a much bigger enviro impact than iphones. Despite claims apple purposely obsoletes its phones, it actually has a FAR FAR better record of updating ol…

Android is an open platform relative to iOS so naturally you'll see a large range of manufacturing strategies since Apple prohibits the use of its operating system on hardware it does not sell.

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#58
post #53

Earlier quoted context omitted.

That’s the problem. Why should your carrier have any say so in updating your operating system? If I buy a computer from Best Buy, I don’t have to wait for them to push an update to Windows.

The carrier wants your phone to work on their network. A software update could change brick the radio (or just disable the channel they are using) if done wrong.

Yet Apple has been able to do that for well over a decade and sells phones via carriers. Even if you buy an unlocked Android phone directly you can update it without carrier intervention.

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#60

Earlier quoted context omitted.

>which extends the life of old phones. Except they were caught purposely throttling older phones with those updates, not exactly what i'd call extending life.

> purposely throttling So that the phones don't randomly shut off because their lithium ion batteries were old. Yes, they should have told people but it wasn't done maliciously.

> it wasn't done maliciously.

Depends on how you look at it. One alternative solution to the old battery problem would be to send it to a repair shop to install a new battery.

But Apple doesn't want people to have the right to repair their own devices, so that's not even seen as an option. Throttling to extend battery life is a convenient explanation that both solves the problem and avoids hurting their extremely profitable repair program (where they'd charge maybe $50 less than the cost of a new phone for a battery replacement).

Post reply on HN