Earlier quoted context omitted.
Most of the function users care about in their phone, if not implemented by third party, are proprietary apps from google. Without the app store and the google ecosystem, android experience is poor at best.
The Google ecosystem can drown in bleach for all I care. F-Droid is not bad at all. Downloading apps from the Google store is an awful experience because on that store it's the norm for damn near every application to spy on you to the fullest extent possible. On f-droid, applications the typical application is a good citizen. It's a lower stress experience and a better appstore than either Google or Apple, unless you…
Malicious apps infect 25M Android devices with 'Agent Smith' malware
201–210 of 222 posts
Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware
#202Earlier quoted context omitted.
It may have, but I doubt it was the primary motivation. Steve Jobs famously cared a lot about user experience, security and reliability. Remember that Apple under his leadership took a firm stance and loudly and publicly refused to allow Flash on its devices, despite the fact that many websites back then relied on Flash.
> Steve Jobs famously cared a lot about user experience, security and reliability. Remember that Apple under his leadership took a firm stance and loudly and publicly refused to allow Flash on its devices, despite the fact that many websites back then relied on Flash. A less generous take on that would be that he/Apple also wanted to push their app store. At the time Flash was popular for publishing apps and games on…
The App Store didn't exist at that time.
Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware
#203Earlier quoted context omitted.
This seems to be getting a lot of attention, so as an Android Engineer with some security and framework experience let me try to explain. This is a side effect of Android's initial approach to it's open nature. Android allows a manufacturer to modify its framework for their own use case. Then the manufacturer can allow a specific carrier to input their own system applications and firmware on to the devices well (your…
This is what I love about Apple. They gave the carriers a big middle finger when it comes to the usual bullshit of bloatware, sticking their logos on things or getting in the middle of updates. That’s because they cared about the end user experience. Google was happy to just grab market share at the expense of the users by allowing carriers to continue with their usual shenanigans. For this reason Apple will have my…
Apple did it because they could, because when the iPhone came out it owned the smartphone market; any carrier that didn't play ball would be frozen out (as T-Mobile was initially - AT&T's exclusivity on the iPhone really helped their market share among high-end consumers). Google did not have that luxury.
Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware
#204Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware
#205Earlier quoted context omitted.
Yes, looks like October 2019 is the end: https://support.google.com/nexus/answer/4457705?hl=en#pixel_...
What should he do if he finds out about a vulnerability then? Does he need a new phone?
There is a custom firmware card LineageOS but it's a community effort. It may get up to date security updates merged in but it could be vulnerable in other ways.
Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware
#206Earlier quoted context omitted.
This is what I love about Apple. They gave the carriers a big middle finger when it comes to the usual bullshit of bloatware, sticking their logos on things or getting in the middle of updates. That’s because they cared about the end user experience. Google was happy to just grab market share at the expense of the users by allowing carriers to continue with their usual shenanigans. For this reason Apple will have my…
Don't make this about moral superiority of Apple over Google. Apple did it because they could , because when the iPhone came out it owned the smartphone market; any carrier that didn't play ball would be frozen out (as T-Mobile was initially - AT&T's exclusivity on the iPhone really helped their market share among high-end consumers). Google did not have that luxury.
When Apple/Steve Jobs went into negotiations with Verizon and AT&T (then known as Cingular), it didn’t have any leverage. In fact, Verizon wouldn’t sign the deal in part because of the control Steve Jobs wanted over the devices. AT&T agreed to get the exclusive.
BlackBerry was King when the iPhone launched and BlackBerry bent over backwards to do whatever the carrier wanted (the book Losing the Signal has great details on this).
Google could have depended on similar provisions with Verizon when the Droid launched in 2009 or with T-Mobile when the G1 launched in 2008. Both carriers wanted an iPhone killer.
But Google didn’t do that. It did force Verizon not to put Bing as the default search engine on some of Verizon’s Android phones (like the Droid series), despite an early 2009 agreement Verizon made to make Bing its default search engine — and it also negotiated to NOT force consumers to pay for Android apps using the carrier stores (something many carriers had required for previous non-Apple App Stores), once paid apps launched.
But it didn’t negotiate the update bit, even though the company had the leverage to do it.
I can only speculate the reasons why, but based on the number of books I’ve read, people I’ve talked to, and and other information, it strikes me that Google decided it was more advantageous to let any phone maker or carrier adopt its OS to gain marketshare, rather than worrying about device fragmentation or security update issues.
And that strategy worked beautifully and Android took over the world. The problem is getting carriers or device makers to update, especially when many have spent lots of time customizing Android as a way of differentiating themselves.
But it’s unfair to claim Google didn’t have the opportunity to make the deal Apple did. Google just didn’t want to do that and wasn’t willing to walk away from a partnership to have that level of control.
Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware
#207> Google already fixed at least one of the Android exploits used by "Agent Smith," nicknamed Janus, in 2017 but the fix hasn't made its way onto every Android phone. It's a potent reminder that millions of phones around the world are being used without the latest security measures. Because Samsung (or similar) or even more weirdly, Sprint (or similar) just doesn't fucking update our Android versions for months, or ev…
This seems to be getting a lot of attention, so as an Android Engineer with some security and framework experience let me try to explain. This is a side effect of Android's initial approach to it's open nature. Android allows a manufacturer to modify its framework for their own use case. Then the manufacturer can allow a specific carrier to input their own system applications and firmware on to the devices well (your…
Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware
#208"Oh boy! A whole bunch of people are going to be really boned by a malicious app, but we're not going to let you know any details. Hey, do you bank on your phone? Ooooo you might be realllllly screwed. The competing platform is better and/or worse for thee pedantic reasons, says some random person you've never heard of and will probably never hear from again."
If you're not reporting the name of the company or apps involved, don't waste everyone's fucking time. It's even more egregious than the news doing the whole, "Something in your pantry could kill everyone you ever loved. Details after these commercials."
Sure it puts pressure on device makers to be on the ball with security updates, but at the end of the day there's nothing anyone can do. They don't tell you the symptoms of being infected, how to prevent becoming infected (don't click ads to prevent activating the virus, but do I just never install another app from here on out), or even what to do if you are infected (will a factory wipe work, or does it install to recovery, too?).
I submit the following similarly useful mini-article:
Something in 500,000 grocery stores is causing customers to experience explosive diarrhea. Local law enforcement is investigating, so we're not going to tell you what the item was. Oops! We mean itemS. I mean, there were a LOT of them. Dr. Flabenpoop of the Central Alabama Subcommittee for Safety of Food and Other Eatin' Things reminds consumers that eating is essential to remain among the living and excessive diarrhea can lead to dehydration and death. He recommends NOT experiencing excessive diarrhea while maintaining a balanced diet. He also notes that the two-fingered spotted wallaby cannot get diarrhea, which begs the question: Is it better to be a wallaby or a human? Or a stick? I mean, sticks don't poop at all, so they must feel lucky. Or sticky. But not sticky from poop.
That is the linked article. Both reports provide the same level of actionable information, the same who cares commentary, and same less than half-heartedly rehash of some inane comparison to pad the word count.
tl;dr - Zero useful information released by the research team, zero useful information in the article.
Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware
#209> Google already fixed at least one of the Android exploits used by "Agent Smith," nicknamed Janus, in 2017 but the fix hasn't made its way onto every Android phone. It's a potent reminder that millions of phones around the world are being used without the latest security measures. Because Samsung (or similar) or even more weirdly, Sprint (or similar) just doesn't fucking update our Android versions for months, or ev…
This seems to be getting a lot of attention, so as an Android Engineer with some security and framework experience let me try to explain. This is a side effect of Android's initial approach to it's open nature. Android allows a manufacturer to modify its framework for their own use case. Then the manufacturer can allow a specific carrier to input their own system applications and firmware on to the devices well (your…
It has helped the frequency and speed of updates a bit. Not a fan of carrier customisation.