Live data from Hacker News

Malicious apps infect 25M Android devices with 'Agent Smith' malware

phys.org

151–160 of 222 posts

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#151
post #77

Earlier quoted context omitted.

This seems to be getting a lot of attention, so as an Android Engineer with some security and framework experience let me try to explain. This is a side effect of Android's initial approach to it's open nature. Android allows a manufacturer to modify its framework for their own use case. Then the manufacturer can allow a specific carrier to input their own system applications and firmware on to the devices well (your…

This is what I love about Apple. They gave the carriers a big middle finger when it comes to the usual bullshit of bloatware, sticking their logos on things or getting in the middle of updates. That’s because they cared about the end user experience. Google was happy to just grab market share at the expense of the users by allowing carriers to continue with their usual shenanigans. For this reason Apple will have my…

Having a closed ecosystem has costs too, though, especially in terms of user freedom and choice.

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#152
post #77

Earlier quoted context omitted.

This seems to be getting a lot of attention, so as an Android Engineer with some security and framework experience let me try to explain. This is a side effect of Android's initial approach to it's open nature. Android allows a manufacturer to modify its framework for their own use case. Then the manufacturer can allow a specific carrier to input their own system applications and firmware on to the devices well (your…

This is what I love about Apple. They gave the carriers a big middle finger when it comes to the usual bullshit of bloatware, sticking their logos on things or getting in the middle of updates. That’s because they cared about the end user experience. Google was happy to just grab market share at the expense of the users by allowing carriers to continue with their usual shenanigans. For this reason Apple will have my…

>They gave the carriers a big middle finger when it comes to the usual bullshit of bloatware, sticking their logos on things or getting in the middle of updates

Except, of course, the bloatware of their own making.

Here's a novel idea: you, yourself can give the middle finger to the carriers and buy an unlocked phone from a provider that delivers timely updates to Android...just like Apple.

>For this reason Apple will have my eternal gratitude

I'll take freedom of choice, thanks.

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#153
post #2

> Google already fixed at least one of the Android exploits used by "Agent Smith," nicknamed Janus, in 2017 but the fix hasn't made its way onto every Android phone. It's a potent reminder that millions of phones around the world are being used without the latest security measures. Because Samsung (or similar) or even more weirdly, Sprint (or similar) just doesn't fucking update our Android versions for months, or ev…

That’s the problem. Why should your carrier have any say so in updating your operating system? If I buy a computer from Best Buy, I don’t have to wait for them to push an update to Windows.

>Why should your carrier have any say so in updating your operating system?

You made that choice when you decided you wanted a carrier subsidized phone.

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#154

Earlier quoted context omitted.

A battery replacement is $79. No one is forcing you to buy a new phone.

A lithium ion battery doesn't cost anywhere near that much, its either poor design and/or profiteering on the device manufacturers part to charge that much for a $15 battery to be replaced.

You could say that about all pricing everywhere. Seems like a waste of breath.

Also doesn't change the upstream clarification that you don't need to buy a new device to get a new battery.

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#155

Earlier quoted context omitted.

> That’s because they cared about the end user experience. I'm sure 100% of any revenue going to Apple and not shared with anyone had nothing to do with that.

It may have, but I doubt it was the primary motivation. Steve Jobs famously cared a lot about user experience, security and reliability. Remember that Apple under his leadership took a firm stance and loudly and publicly refused to allow Flash on its devices, despite the fact that many websites back then relied on Flash.

the anti-flash stance was mainly there because of the abysmal performance a flash app would have on the device and the device's battery life.

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#156
post #53

Earlier quoted context omitted.

That’s the problem. Why should your carrier have any say so in updating your operating system? If I buy a computer from Best Buy, I don’t have to wait for them to push an update to Windows.

The carrier wants your phone to work on their network. A software update could change brick the radio (or just disable the channel they are using) if done wrong.

Could, would, are known as 'weasel words' for a reason.

What the carrier actually wants is to force some applications to always be installed in the customer devices, because of shady business deals, a.k.a. 'partnerships'.

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#158

Earlier quoted context omitted.

That’s the problem. Why should your carrier have any say so in updating your operating system? If I buy a computer from Best Buy, I don’t have to wait for them to push an update to Windows.

Because carriers have a tremendous fear of being simple data pipes.

Exactly. Contracts, identification, phone numbers are not necessary for this. It could be dead simple: the application on your phone generates a pair of private and public keys. You pay some satoshis to a carrier and get some amount of Internet traffic, using your private key for authentication. If you want to switch to other carrier, you just generate a new key and send some satoshis to its account, and your modem generates a new random IMEI. You generate a new key and new IMEI for every new payment so it becomes difficult to track you and sell data about your location. And you can switch between different providers any time. You can even switch depending on who has a better signal in your current location. No need for identification, making a contract, getting a phone number, selling data about you (because carrier doesn't have it) or reporting your location to the government or courts.

This is ten times better than what any provider offers today. If someone implements this, nobody will want to use old scheme anymore.

Also this should promote competition between carriers.

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#159

Earlier quoted context omitted.

This comment and most replies use "carrier" as shorthand for "carrier and/or manufacturer". This looks funny to me because my carrier is T-Mobile and doesn't add bloatware AFAICT. Using "manufacturer" as the shorthand would make more sense to me.

T-Mobile does add software to phones. Wi-Fi calling requires T-Mobile-specific OS-level modifications. You won't be able to use it on unbranded unlocked phones. It's definitely not bloatware though.

This has been somewhat fixed in recent years as my latest unlocked Sony phone has working Wi-Fi calling on T-Mobile.

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#160

Earlier quoted context omitted.

This is what I love about Apple. They gave the carriers a big middle finger when it comes to the usual bullshit of bloatware, sticking their logos on things or getting in the middle of updates. That’s because they cared about the end user experience. Google was happy to just grab market share at the expense of the users by allowing carriers to continue with their usual shenanigans. For this reason Apple will have my…

But Apple software is proprietary, not friendly to open soure developers and you never know what that software is doing. Maybe they are streaming your data directly to "cloud" operated by NSA. Or iPhone doesn't upload anything to cloud?

Most of the function users care about in their phone, if not implemented by third party, are proprietary apps from google.

Without the app store and the google ecosystem, android experience is poor at best.

Post reply on HN