Live data from Hacker News

Void captures over a million Android TV boxes

news.drweb.com

71–80 of 113 posts

Re: Void captures over a million Android TV boxes

#71

There’s always one thread where we are discussing how everything needs to auto-update for security/stability forever, and another thread (currently crowdstrike) where that approach has caused the problem we wanted to avoid. Would be nice to see more discussion of this basic tension in the abstract since $current_issue is often just a distraction. Auto updates also have a reputation for harming the user at least as of…

The problem with Crowdstrike was that they DID NOT TEST before release.

Sure, but again the specifics are a distraction. The problem with pushing any release onto users who have no ability to opt out is that those users never have any guarantee that vendors tested things, or that the vendor is even hoping to help rather than hurt users.

it’s pretty safe to assume that most companies spend money trying to make money, which usually involves exfiltrating my data, turning off things I need but they don’t want to support, general rent seeking, ads injection.

Trusting any small manufacturer of anything to spend time/money on fixing problems with security or quality control is a hilariously naive idea these days, when crowdstrike and Boeing are showing that even big companies don’t care. We all know the security update is enhanced spyware, planned obsolescence / a slow push to force me to buy a new device, or something else that’s going to make things worse.

Re: Void captures over a million Android TV boxes

#73
post #50

> such devices often run on outdated Android versions, Ah the new economical divide. Most "real people" also have phones which aren't receiving updates for a few years by now. In south america the median android version is 8. And phones are not optional as most countries already jumped into both digital government and money transfer.

Updates for Android continue to be a huge problem. Android OEMs have historically been terrible at releasing timely updates (it can take months), releasing updates at all (particularly cheap Android phones get EOLed long before an admittedly way more expensive iPhone would) and such updates aren't typically pushed in the same way. One big problem with Android is the way driver updates work. It's a nontrivial process…

> Updates for Android continue to be a huge problem.

As is being pointed out elsewhere, this isn't a vulnerability in an "Android" product. These are TVs running vendor-maintained AOSP builds. They get updates when and how the vendor decides to do it. It's not related to the (fairly reasonable, though often spun) arguments about updates in the phone licensee ecosystem.

Re: Void captures over a million Android TV boxes

#74
post #50

> such devices often run on outdated Android versions, Ah the new economical divide. Most "real people" also have phones which aren't receiving updates for a few years by now. In south america the median android version is 8. And phones are not optional as most countries already jumped into both digital government and money transfer.

Updates for Android continue to be a huge problem. Android OEMs have historically been terrible at releasing timely updates (it can take months), releasing updates at all (particularly cheap Android phones get EOLed long before an admittedly way more expensive iPhone would) and such updates aren't typically pushed in the same way. One big problem with Android is the way driver updates work. It's a nontrivial process…

I am using an Android phone which gets timely updates. However the vendor does not seem to do enough testing for major versions and has ended up with at least one significant bug upon release twice. I could do with less timely updates that come with less bugs.

Re: Void captures over a million Android TV boxes

#75
post #65

Earlier quoted context omitted.

The problem is that the “self” in that statement is not the consumer. They have no choice, yet the bear the burden. The people who made these choices benefit from it.

By "self" I meant the manufacturers of the device, not the end user.

The manufacturers do not have the problem. They created a problem for many users as a side effect of forced obsolescence making consumers in richer countries buy new hardware every few years.

So it is not really "self created" in my book.

Re: Void captures over a million Android TV boxes

#77
post #75

Earlier quoted context omitted.

By "self" I meant the manufacturers of the device, not the end user.

The manufacturers do not have the problem. They created a problem for many users as a side effect of forced obsolescence making consumers in richer countries buy new hardware every few years. So it is not really "self created" in my book.

Didn't Google create the problem. They could have made the Android core updatable without the need for a manufacturer update

Re: Void captures over a million Android TV boxes

#78
post #50

Earlier quoted context omitted.

Updates for Android continue to be a huge problem. Android OEMs have historically been terrible at releasing timely updates (it can take months), releasing updates at all (particularly cheap Android phones get EOLed long before an admittedly way more expensive iPhone would) and such updates aren't typically pushed in the same way. One big problem with Android is the way driver updates work. It's a nontrivial process…

Fuchsia was a backup plan. Google is now the only option for phone manufacturers. No backup needed. Plan A worked.

I'm not sure I understand how having a second OS would hedge against people not wanting to use their first OS, but Fuschia being some sort of backup plan would at least explain why it didn't really ever get used. My guess was always that it just didn't ever have full support as a replacement due to turf wars with people in charge of Android-related things.

Re: Void captures over a million Android TV boxes

#79
post #36

How does this work? Are those TV boxes not running behind routers with firewalls?

Firewall? No. Everyone just trust nat. And You'd be surprised how trivial it is to bypass modem nat and reach inside.

I'm not aware of even a single consumer-marketed router that ships without a firewall (often ip/nftables) configured to drop all unsolicited incoming packets by default. If an attacker can create outbound connections from inside the network then they can get around this of course, but you have to already be inside.

Re: Void captures over a million Android TV boxes

#80

> such devices often run on outdated Android versions, Ah the new economical divide. Most "real people" also have phones which aren't receiving updates for a few years by now. In south america the median android version is 8. And phones are not optional as most countries already jumped into both digital government and money transfer.

Its a self created problem of locked down user hostile devices. Operating system and software upgrades are not locked to the hardware manufacturer in the laptop world (not yet, for the most part). It is a pipe dream of mine that someday these attacks are used as an excuse by some government perhaps the EU to force opening up devices for install of other operating systems, maybe forced to open sourcing firmware etc.

Androids are less locked-down than iOS devices. The problem is that Google used to not have the ability to require long term support from device OEMs and now that it has the market power to demand long term support they seem reluctant to prioritize that in license agreements.

Then there are devices, like in China, where Google Mobile Services is not on many phones so Google has no leverage at all re supporting updates.

Post reply on HN