Live data from Hacker News

Malicious apps infect 25M Android devices with 'Agent Smith' malware

phys.org

71–80 of 222 posts

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#72
post #2

> Google already fixed at least one of the Android exploits used by "Agent Smith," nicknamed Janus, in 2017 but the fix hasn't made its way onto every Android phone. It's a potent reminder that millions of phones around the world are being used without the latest security measures. Because Samsung (or similar) or even more weirdly, Sprint (or similar) just doesn't fucking update our Android versions for months, or ev…

Question: my brother just got a used pixel 1 phone. Will it stop getting security updates soon/already?

I took 10 seconds to Google your question and found this link:

https://support.google.com/nexus/answer/4457705?hl=en#pixel_...

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#73
post #53

Earlier quoted context omitted.

The carrier wants your phone to work on their network. A software update could change brick the radio (or just disable the channel they are using) if done wrong.

Yet Apple has been able to do that for well over a decade and sells phones via carriers. Even if you buy an unlocked Android phone directly you can update it without carrier intervention.

OK, you're a carrier and have millions of Apple and Samsung devices on your network. 0.01% of your users know how to update the OS on their Samsung phones themselves, or jailbreak their iPhones. A software update from the manufacturer could brick millions of those phones on you network.

Which risk keeps you awake at night:

  A few Samsung phone users bricking their phones occasionally
  A few iPhone users bricking their phones occasionally
  50 million Galaxy phones being bricked by Samsung at once
  50 million iPhones being bricked by Apple at once
I'm not saying it's impossible Apple could do it, but in terms of ratios how much more or less likely is it versus Samsung?

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#74

Earlier quoted context omitted.

Is there really some expectation for a carrier to be more than that? I just want a fast, reliable service that connects my phone to the internet. Is there actually profit in providing more than that?

From the carrier: yes. The phone subsidies (in the US at least) are very reminiscent of the old leased phones of yore. But if you look at the actions of mobile phone carriers and ISPs they're desperate not to become dumb pipes. They design all kinds of clever mechanisms and marketing strategies to distinguish themselves. > Is there actually profit in providing more than that? Well, in a free market, competition is in…

Let's not be silly, there is no market in this case. It's an oligopoly and occasional cartel.

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#75

Earlier quoted context omitted.

better than ios updates making the phone unusable. happened to me on old ipod touch models, not even the battery thing.

> Not even the battery thing. That was an attempt at graceful degradation that wasn’t communicated well. The general belief was that having a phone that runs a bit more slowly, but consistently used it’s battery as the battery life naturally degrades is better than a phone suddenly dying with 40% battery remaining if the peak power draw exceeds what a several year old lithium ion battery can produce. I much prefer th…

Just make it so the batteries are easily replaceable. It's wasteful to buy a brand new phone when all you need is a new battery.

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#76

Earlier quoted context omitted.

Because carriers have a tremendous fear of being simple data pipes.

Apple pushed the carriers to allow it to update its own operating systems over a decade ago.

Yeah, I know this. I don't think anyone at any of the other phone manufacturers has the weight to throw around that Jobs did, though.

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#77
post #2

> Google already fixed at least one of the Android exploits used by "Agent Smith," nicknamed Janus, in 2017 but the fix hasn't made its way onto every Android phone. It's a potent reminder that millions of phones around the world are being used without the latest security measures. Because Samsung (or similar) or even more weirdly, Sprint (or similar) just doesn't fucking update our Android versions for months, or ev…

This seems to be getting a lot of attention, so as an Android Engineer with some security and framework experience let me try to explain.

This is a side effect of Android's initial approach to it's open nature. Android allows a manufacturer to modify its framework for their own use case. Then the manufacturer can allow a specific carrier to input their own system applications and firmware on to the devices well (your bloatware etc).

This can lead to multiple firmware variants for a specific device. It's not uncommon to see over 20 variants of a firmware for a specific Samsung device for example. This can be broken down by carrier, by region, by OS, etc.. for a number of different reasons.

This becomes a problem when Android needs to post an update. That update has to be pushed first to the Android framework, then to the manufacturer who decides if they are going to make modifications for the update, and if the manufacturer decides to make an update, they push it to the carrier who then has to make an update themselves.

This leads to a web with many broken ends, where a specific phone on one carrier may never see an OS upgrade after purchase, but on another carrier, the same phone might get them regularly.

Additionally some manufacturers take a greater degree of liberty in modifying the Android framework, making updates significantly more expensive to implement, so they don't.

The good news is Google over the past couple of years has been making a great effort under Project Trebel to simplify some of the APIs in the Android framework. What this is leading to is less friction when it comes to implementing core updates. Unfortunately not all manufacturers have opted in to adhering to the standards and Project Trebel yet.

This is all in stark contrast to iOS, which doesn't have the restriction of dealing with multiple manufacturers, and makes it harder for carriers to customize the device for their own business cases. This makes security and updates easier to push, but on the cost to the user of being an expensive single stream walled garden. Nothing against iOS in the statement, as a flagship device they're very nice. However, they don't have the adaptability that Android allows, making them prohibitive in some markets.

Sorry for any grammar issues, I'm on my phone (a regularly updated Pixel 3).

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#79

Earlier quoted context omitted.

Because carriers have a tremendous fear of being simple data pipes.

Is there really some expectation for a carrier to be more than that? I just want a fast, reliable service that connects my phone to the internet. Is there actually profit in providing more than that?

From the carrier perspective, sure. Being a dumb pipe is a race to the bottom market-wise.
Post reply on HN