Live data from Hacker News

Malicious apps infect 25M Android devices with 'Agent Smith' malware

phys.org

161–170 of 222 posts

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#161

Earlier quoted context omitted.

This is what I love about Apple. They gave the carriers a big middle finger when it comes to the usual bullshit of bloatware, sticking their logos on things or getting in the middle of updates. That’s because they cared about the end user experience. Google was happy to just grab market share at the expense of the users by allowing carriers to continue with their usual shenanigans. For this reason Apple will have my…

But Apple software is proprietary, not friendly to open soure developers and you never know what that software is doing. Maybe they are streaming your data directly to "cloud" operated by NSA. Or iPhone doesn't upload anything to cloud?

All of the data collection functionality in Google Apps is closed source too.

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#162
post #37

Earlier quoted context omitted.

> comparatively ancient Android 7.0 7.0 is ancient? 5.1, or rather 4.4 is ancient.

The Android ver on my phone is 4.1. Still runs just fine, but then again all I use it for are calls/SMS, so there's little scope to be exploited.

> ...all I use it for are calls/SMS, so there's little scope to be exploited.

You mean little scope of exfiltration (I'm guessing it's not connected to the internet). There are a lot of vulnerabilities in text rendering that can be exploited via SMS.

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#163

Earlier quoted context omitted.

But Apple software is proprietary, not friendly to open soure developers and you never know what that software is doing. Maybe they are streaming your data directly to "cloud" operated by NSA. Or iPhone doesn't upload anything to cloud?

Most of the function users care about in their phone, if not implemented by third party, are proprietary apps from google. Without the app store and the google ecosystem, android experience is poor at best.

The Google ecosystem can drown in bleach for all I care. F-Droid is not bad at all. Downloading apps from the Google store is an awful experience because on that store it's the norm for damn near every application to spy on you to the fullest extent possible. On f-droid, applications the typical application is a good citizen. It's a lower stress experience and a better appstore than either Google or Apple, unless you desire specific closed source software in which case it's no longer an option.

Try this: On Google's Appstore, find a flashlight app that doesn't upload your contacts. Now on F-droid, try to find one that does. This is not an easy challenge!

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#164
post #77
post #2

> Google already fixed at least one of the Android exploits used by "Agent Smith," nicknamed Janus, in 2017 but the fix hasn't made its way onto every Android phone. It's a potent reminder that millions of phones around the world are being used without the latest security measures. Because Samsung (or similar) or even more weirdly, Sprint (or similar) just doesn't fucking update our Android versions for months, or ev…

This seems to be getting a lot of attention, so as an Android Engineer with some security and framework experience let me try to explain. This is a side effect of Android's initial approach to it's open nature. Android allows a manufacturer to modify its framework for their own use case. Then the manufacturer can allow a specific carrier to input their own system applications and firmware on to the devices well (your…

Arguably, it should not be legal to sell a device and not provide security updates for some guaranteed period of time, as a violation of the implied warranty for fitness for a particular use, or as an unfair or deceptive trade practice.

I wonder if the FTC has ever pushed this particular angle?

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#165

Earlier quoted context omitted.

This is what I love about Apple. They gave the carriers a big middle finger when it comes to the usual bullshit of bloatware, sticking their logos on things or getting in the middle of updates. That’s because they cared about the end user experience. Google was happy to just grab market share at the expense of the users by allowing carriers to continue with their usual shenanigans. For this reason Apple will have my…

But Apple software is proprietary, not friendly to open soure developers and you never know what that software is doing. Maybe they are streaming your data directly to "cloud" operated by NSA. Or iPhone doesn't upload anything to cloud?

The Google Play Store and related APIs are similarly locked down. Not that you couldn't distribute through something like fdroid.

I take your point but android is similar in some respects (Google probably has less interest in your privacy than Apple does).

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#166

Earlier quoted context omitted.

It may have, but I doubt it was the primary motivation. Steve Jobs famously cared a lot about user experience, security and reliability. Remember that Apple under his leadership took a firm stance and loudly and publicly refused to allow Flash on its devices, despite the fact that many websites back then relied on Flash.

the anti-flash stance was mainly there because of the abysmal performance a flash app would have on the device and the device's battery life.

Hence, user experience!

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#167

Earlier quoted context omitted.

This is what I love about Apple. They gave the carriers a big middle finger when it comes to the usual bullshit of bloatware, sticking their logos on things or getting in the middle of updates. That’s because they cared about the end user experience. Google was happy to just grab market share at the expense of the users by allowing carriers to continue with their usual shenanigans. For this reason Apple will have my…

But Apple software is proprietary, not friendly to open soure developers and you never know what that software is doing. Maybe they are streaming your data directly to "cloud" operated by NSA. Or iPhone doesn't upload anything to cloud?

And what makes Android what it is to most consumers - Google Play Services is also proprietary as well as all of the drivers. Not to mention whatever the OEMs and the carriers add.

Even if you have a completely “open” operating system on your phone, your communications is still going through a carrier that could be “operated by the NSA”.

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#168
post #146

Earlier quoted context omitted.

It may have, but I doubt it was the primary motivation. Steve Jobs famously cared a lot about user experience, security and reliability. Remember that Apple under his leadership took a firm stance and loudly and publicly refused to allow Flash on its devices, despite the fact that many websites back then relied on Flash.

> Steve Jobs famously cared a lot about user experience, security and reliability. Remember that Apple under his leadership took a firm stance and loudly and publicly refused to allow Flash on its devices, despite the fact that many websites back then relied on Flash. A less generous take on that would be that he/Apple also wanted to push their app store. At the time Flash was popular for publishing apps and games on…

You mean the same Flash that Adobe said they could have gotten to work on the original iPhone - with 128MB of RAM and a 400Mhz processor but barely worked on Android with minimum requirements of a 1Ghz processor and 1GB of RAM?

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#169
post #131

Earlier quoted context omitted.

It may have, but I doubt it was the primary motivation. Steve Jobs famously cared a lot about user experience, security and reliability. Remember that Apple under his leadership took a firm stance and loudly and publicly refused to allow Flash on its devices, despite the fact that many websites back then relied on Flash.

Apple also planned to sandbox all apps. But developers wanted bare metal performance.

Sandboxes apps has to do with the permissions not having “metal performance”. iOS apps compile down to ARM native code. Unlike most Android apps that run on top of a VM.

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#170

Earlier quoted context omitted.

From the carrier: yes. The phone subsidies (in the US at least) are very reminiscent of the old leased phones of yore. But if you look at the actions of mobile phone carriers and ISPs they're desperate not to become dumb pipes. They design all kinds of clever mechanisms and marketing strategies to distinguish themselves. > Is there actually profit in providing more than that? Well, in a free market, competition is in…

Let's not be silly, there is no market in this case. It's an oligopoly and occasional cartel.

There is only so much competition you can have in wireless. Different carriers have to have different bands of spectrum and only certain frequencies can be used for cellular.
Post reply on HN