Live data from Hacker News

Malicious apps infect 25M Android devices with 'Agent Smith' malware

phys.org

111–120 of 222 posts

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#111
post #2

> Google already fixed at least one of the Android exploits used by "Agent Smith," nicknamed Janus, in 2017 but the fix hasn't made its way onto every Android phone. It's a potent reminder that millions of phones around the world are being used without the latest security measures. Because Samsung (or similar) or even more weirdly, Sprint (or similar) just doesn't fucking update our Android versions for months, or ev…

From the start, Google cared enough about device makers potentially shipping a device running a fork of Android that they forbade doing so in their contracts with device makers. When it came to making sure consumers got timely software updates, Google sided with the device makers and carriers. Device makers wanted you to buy new hardware every couple of years, and carriers wanted to lock you into an additional two ye…

Google never forbid updating phones... They forbid forking Android.

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#112

Earlier quoted context omitted.

From the start, Google cared enough about device makers potentially shipping a device running a fork of Android that they forbade doing so in their contracts with device makers. When it came to making sure consumers got timely software updates, Google sided with the device makers and carriers. Device makers wanted you to buy new hardware every couple of years, and carriers wanted to lock you into an additional two ye…

Google never forbid updating phones... They forbid forking Android.

That's what he said. They didn't forbid it, but they also didn't mandate it be allowed.

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#113
post #2

> Google already fixed at least one of the Android exploits used by "Agent Smith," nicknamed Janus, in 2017 but the fix hasn't made its way onto every Android phone. It's a potent reminder that millions of phones around the world are being used without the latest security measures. Because Samsung (or similar) or even more weirdly, Sprint (or similar) just doesn't fucking update our Android versions for months, or ev…

I'm still on android 5.0.1 because at&t won't allow me to update my phone unless I'm on their network as a customer. But they don't have service where I live so I can't.

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#114
post #53

Earlier quoted context omitted.

The carrier wants your phone to work on their network. A software update could change brick the radio (or just disable the channel they are using) if done wrong.

Yet Apple has been able to do that for well over a decade and sells phones via carriers. Even if you buy an unlocked Android phone directly you can update it without carrier intervention.

Yes but apple only has ~10 phones that have to be updated at a time, and all share similar hardware with software specifically designed for that hardware. There are so many different hardware setups for android that getting software to work perfectly on all of them is exponentially harder

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#115
post #96

Earlier quoted context omitted.

Yes, looks like October 2019 is the end: https://support.google.com/nexus/answer/4457705?hl=en#pixel_...

What should he do if he finds out about a vulnerability then? Does he need a new phone?

Yes, but not necessarily Oct 2019. My Nexus 5X is running Android 8.1.0 with security patch level: December 5, 2018, so it's likely Pixel will also get updates after the guaranteed dates.

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#116
post #77

Earlier quoted context omitted.

This seems to be getting a lot of attention, so as an Android Engineer with some security and framework experience let me try to explain. This is a side effect of Android's initial approach to it's open nature. Android allows a manufacturer to modify its framework for their own use case. Then the manufacturer can allow a specific carrier to input their own system applications and firmware on to the devices well (your…

Sounds like an excuse for poor engineering on the part of Android. Microsoft also sells Windows to multiple OEMs and has done so for decades. OEMs also are free to add bloatware as well as the retailers (ie Best Buy adds its own bloat), but Microsoft doesn’t have this problem.

It’s quite different as windows is closed source. The OEMs don’t build their own flavour of windows from source.

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#117
post #2

> Google already fixed at least one of the Android exploits used by "Agent Smith," nicknamed Janus, in 2017 but the fix hasn't made its way onto every Android phone. It's a potent reminder that millions of phones around the world are being used without the latest security measures. Because Samsung (or similar) or even more weirdly, Sprint (or similar) just doesn't fucking update our Android versions for months, or ev…

That’s the problem. Why should your carrier have any say so in updating your operating system? If I buy a computer from Best Buy, I don’t have to wait for them to push an update to Windows.

This comment and most replies use "carrier" as shorthand for "carrier and/or manufacturer". This looks funny to me because my carrier is T-Mobile and doesn't add bloatware AFAICT. Using "manufacturer" as the shorthand would make more sense to me.

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#118
post #112

Earlier quoted context omitted.

Google never forbid updating phones... They forbid forking Android.

That's what he said. They didn't forbid it, but they also didn't mandate it be allowed.

In contrast, Apple did forbid carriers to block software updates in it's contracts with them.

It's a matter of who you think your customers are.

Google sides with advertisers, device makers, and carriers and not it's end users.

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#119

Earlier quoted context omitted.

Sounds like an excuse for poor engineering on the part of Android. Microsoft also sells Windows to multiple OEMs and has done so for decades. OEMs also are free to add bloatware as well as the retailers (ie Best Buy adds its own bloat), but Microsoft doesn’t have this problem.

It’s quite different as windows is closed source. The OEMs don’t build their own flavour of windows from source.

And almost everything that makes Android what it is outside of China is also closed source - Google Play Services and the drivers.

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#120

Earlier quoted context omitted.

That’s the problem. Why should your carrier have any say so in updating your operating system? If I buy a computer from Best Buy, I don’t have to wait for them to push an update to Windows.

This comment and most replies use "carrier" as shorthand for "carrier and/or manufacturer". This looks funny to me because my carrier is T-Mobile and doesn't add bloatware AFAICT. Using "manufacturer" as the shorthand would make more sense to me.

T-Mobile does add software to phones. Wi-Fi calling requires T-Mobile-specific OS-level modifications. You won't be able to use it on unbranded unlocked phones. It's definitely not bloatware though.
Post reply on HN