Live data from Hacker News

Android 10: Google Confirms 193 Security Vulnerabilities Need Fixing

forbes.com

31–40 of 70 posts

Re: Android 10: Google Confirms 193 Security Vulnerabilities Need Fixing

#31
post #22

This headline is grossly misleading - Android 10 has fixed those 193 vulnerabilities. The title as it is, implies they still need to be fixed. This kind of content is usually never worded like this for other products, can the moderators fix it?

Another crap Forbes contributor article. The fix is to ban these posts. These articles have basically zero credibility because they are written by ordinary dopes who pay to have their blogs published on forbes.com. There is no fact checking, no verification of the author’s background and expertise, nothing. You pay and get published and people get the impression it’s “news” because of the Forbes name.

Re: Android 10: Google Confirms 193 Security Vulnerabilities Need Fixing

#32
post #11

A revocable permission for network access on Android would be a great step towards giving users more control over which apps can transmit their personal data. An entire class of apps could be rendered safe by disallowing network access, especially the ones that do work offline, but are keen to phone home.

The problem is when an app finds a bullshit excuse to refuse to work unless they're provided all wanted permissions. even if they don't hard block their content that way, in practice, people are just going to flip the switch that makes the app work or make a dialog go away without reading. I just don't think pushing the choice of permissions to the end user is a good idea, not by itself. UX teaches us that people are…

LineageOS has the solution to this problem. You can revoke fine grained capabilities while letting the app still think it has the permissions.

Re: Android 10: Google Confirms 193 Security Vulnerabilities Need Fixing

#33
post #15

Do previous Android versions have these vulnerabilities?

The headline is misleading. These vulnerabilities are not in Android 10 but are fixed by Android 10. Which of course means they exist in versions prior to Android 10. Google provides security updates for prior versions so what is not clear from the article is whether these are only fixed by upgrading to Android 10 or whether they were identified during the Android 10 development process but fixes will also be availab…

> These vulnerabilities are not in Android 10 but are fixed by Android 10. Which of course means they exist in versions prior to Android 10.

That's not accurate. Android 10 is still in beta, so many of these vulnerabilities (just like many other bugs you'll see in a beta) are likely new to Android 10, and will be fixed before the final release.

Re: Android 10: Google Confirms 193 Security Vulnerabilities Need Fixing

#34

Earlier quoted context omitted.

The problem is when an app finds a bullshit excuse to refuse to work unless they're provided all wanted permissions. even if they don't hard block their content that way, in practice, people are just going to flip the switch that makes the app work or make a dialog go away without reading. I just don't think pushing the choice of permissions to the end user is a good idea, not by itself. UX teaches us that people are…

LineageOS has the solution to this problem. You can revoke fine grained capabilities while letting the app still think it has the permissions.

Indeed. On the desktop, this is also known as a firewall. All apps practically think they have "network permissions", but if they actually try to make a connection, it will either time out or return errors.

Re: Android 10: Google Confirms 193 Security Vulnerabilities Need Fixing

#35
post #11

A revocable permission for network access on Android would be a great step towards giving users more control over which apps can transmit their personal data. An entire class of apps could be rendered safe by disallowing network access, especially the ones that do work offline, but are keen to phone home.

This would make things so much safer for everyone but Google has so far refused to do this. (Android DOES have a network permission, but at some point Google decided it should always be allowed)

but at some point Google decided it should always be allowed

Not at all surprising, if you consider Google's motives; they both want to appear like they care about privacy and give you an illusion of control, but at the same time they are ultimately an ad company who profits from the lack thereof. A lot of the decisions they make about their products make a lot of sense from this perspective.

Re: Android 10: Google Confirms 193 Security Vulnerabilities Need Fixing

#36

Earlier quoted context omitted.

LineageOS has the solution to this problem. You can revoke fine grained capabilities while letting the app still think it has the permissions.

Indeed. On the desktop, this is also known as a firewall. All apps practically think they have "network permissions", but if they actually try to make a connection, it will either time out or return errors.

What operating systems have built in support for firewalling specific applications?

Re: Android 10: Google Confirms 193 Security Vulnerabilities Need Fixing

#37
post #36

Earlier quoted context omitted.

Indeed. On the desktop, this is also known as a firewall. All apps practically think they have "network permissions", but if they actually try to make a connection, it will either time out or return errors.

What operating systems have built in support for firewalling specific applications?

Windows has for over a decade, I assume Linux does too.

Re: Android 10: Google Confirms 193 Security Vulnerabilities Need Fixing

#38
post #36

Earlier quoted context omitted.

Indeed. On the desktop, this is also known as a firewall. All apps practically think they have "network permissions", but if they actually try to make a connection, it will either time out or return errors.

What operating systems have built in support for firewalling specific applications?

Depends what you mean by built-in. On Linux you can easily start something either in a namespace with no network, or filter out network calls by syscalls. Selinux/apparmor/tomoyo give you more fine grained control over what can be done over the network.

Re: Android 10: Google Confirms 193 Security Vulnerabilities Need Fixing

#39

Earlier quoted context omitted.

LineageOS has the solution to this problem. You can revoke fine grained capabilities while letting the app still think it has the permissions.

Indeed. On the desktop, this is also known as a firewall. All apps practically think they have "network permissions", but if they actually try to make a connection, it will either time out or return errors.

For Android users, there's the NoRoot Firewall app, which works via the VPN interface.

Re: Android 10: Google Confirms 193 Security Vulnerabilities Need Fixing

#40
post #31
post #22

This headline is grossly misleading - Android 10 has fixed those 193 vulnerabilities. The title as it is, implies they still need to be fixed. This kind of content is usually never worded like this for other products, can the moderators fix it?

Another crap Forbes contributor article. The fix is to ban these posts. These articles have basically zero credibility because they are written by ordinary dopes who pay to have their blogs published on forbes.com. There is no fact checking, no verification of the author’s background and expertise, nothing. You pay and get published and people get the impression it’s “news” because of the Forbes name.

The writing is extremely clumsy, I had to go to the linked post from Google to find out that the author meant that Android releases will no longer be named after desserts.
Post reply on HN