Live data from Hacker News

Malicious apps infect 25M Android devices with 'Agent Smith' malware

phys.org

81–90 of 222 posts

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#83
post #4

What ad blocking for Android to would recommend?

Adguard (paid) or Blokada (free) if you don't want to root.

You can use AdGuard's DNS servers for free. They also have the added benefit of supporting DoT and DoH. Click on "DNS Privacy" for their instructions:

https://adguard.com/en/adguard-dns/overview.html#instruction

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#84
post #2

> Google already fixed at least one of the Android exploits used by "Agent Smith," nicknamed Janus, in 2017 but the fix hasn't made its way onto every Android phone. It's a potent reminder that millions of phones around the world are being used without the latest security measures. Because Samsung (or similar) or even more weirdly, Sprint (or similar) just doesn't fucking update our Android versions for months, or ev…

That’s the problem. Why should your carrier have any say so in updating your operating system? If I buy a computer from Best Buy, I don’t have to wait for them to push an update to Windows.

I don't even buy my phones from the carrier, which makes it even more perplexing.

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#85
post #33

"Check Point is not identifying the company, because they are working with local law enforcement." Well that's dumb. "It appears that you are currently using Ad Blocking software. What are the consequences?" The consequences include avoiding situations just like in the story. When did Phys Org get into tech news? I thought they were just an unreliable source for science rumors.

The story is a reprint from San-Diego Mercury News, and as bad at making anything clear about how a user could find out whether the phone has been affected by Agent Smith or identifying the originating infection entry app.

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#86
post #63
post #13

Earlier quoted context omitted.

Firefox mobile + uBlockOrigin or uMatrix

Firefox Mobile is dropping extension support for awhile: https://github.com/mozilla-mobile/fenix/issues/574

Fenix is not the currently supported mainline Firefox Mobile browser, nor will it be for a bit.

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#87
post #77
post #2

> Google already fixed at least one of the Android exploits used by "Agent Smith," nicknamed Janus, in 2017 but the fix hasn't made its way onto every Android phone. It's a potent reminder that millions of phones around the world are being used without the latest security measures. Because Samsung (or similar) or even more weirdly, Sprint (or similar) just doesn't fucking update our Android versions for months, or ev…

This seems to be getting a lot of attention, so as an Android Engineer with some security and framework experience let me try to explain. This is a side effect of Android's initial approach to it's open nature. Android allows a manufacturer to modify its framework for their own use case. Then the manufacturer can allow a specific carrier to input their own system applications and firmware on to the devices well (your…

This is what I love about Apple. They gave the carriers a big middle finger when it comes to the usual bullshit of bloatware, sticking their logos on things or getting in the middle of updates. That’s because they cared about the end user experience. Google was happy to just grab market share at the expense of the users by allowing carriers to continue with their usual shenanigans. For this reason Apple will have my eternal gratitude, because I remember what a shitshow smartphones (and deploying apps for them) was before Apple flexed their muscles on this.

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#88
post #77
post #2

> Google already fixed at least one of the Android exploits used by "Agent Smith," nicknamed Janus, in 2017 but the fix hasn't made its way onto every Android phone. It's a potent reminder that millions of phones around the world are being used without the latest security measures. Because Samsung (or similar) or even more weirdly, Sprint (or similar) just doesn't fucking update our Android versions for months, or ev…

This seems to be getting a lot of attention, so as an Android Engineer with some security and framework experience let me try to explain. This is a side effect of Android's initial approach to it's open nature. Android allows a manufacturer to modify its framework for their own use case. Then the manufacturer can allow a specific carrier to input their own system applications and firmware on to the devices well (your…

Sounds like an excuse for poor engineering on the part of Android. Microsoft also sells Windows to multiple OEMs and has done so for decades. OEMs also are free to add bloatware as well as the retailers (ie Best Buy adds its own bloat), but Microsoft doesn’t have this problem.

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#89

Earlier quoted context omitted.

Good question. When a phone stops working, people want their money back. Guess where most people in most markets buy their phone from? Further, who do you think customer's call for support? Now you know why carriers are hesitant about frequently updating a product they've already made a sale on. If an update breaks something, guess who pays the price? Not defending them, and it's not the only reason, but it's a big o…

Which is why I prefer to buy my phone independently from the carrier service.

I’m able to buy a Windows computer from third parties and still get an update from Microsoft....

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#90
post #60

Earlier quoted context omitted.

> purposely throttling So that the phones don't randomly shut off because their lithium ion batteries were old. Yes, they should have told people but it wasn't done maliciously.

> it wasn't done maliciously. Depends on how you look at it. One alternative solution to the old battery problem would be to send it to a repair shop to install a new battery. But Apple doesn't want people to have the right to repair their own devices, so that's not even seen as an option. Throttling to extend battery life is a convenient explanation that both solves the problem and avoids hurting their extremely pro…

[deleted]
Post reply on HN