Live data from Hacker News

Void captures over a million Android TV boxes

news.drweb.com

101–110 of 113 posts

Re: Void captures over a million Android TV boxes

#101
post #77
post #75

Earlier quoted context omitted.

The manufacturers do not have the problem. They created a problem for many users as a side effect of forced obsolescence making consumers in richer countries buy new hardware every few years. So it is not really "self created" in my book.

Didn't Google create the problem. They could have made the Android core updatable without the need for a manufacturer update

The original sin of Android was that it was made for phone manufacturers, not end-users. And phone manufacturers were in turn subservient to cellular companies. Back then cellular companies demanded network-specific devices, with network-specific software. Android was made to fit right into this relationship.

The continuing problem with Android, and a display of Google's lost interest in Android, is that they still stick to this paradigm in 2024. Nowadays phone manufacturers ship stock Android with add-ons, and cellular companies no longer have the power to demand anything. If Apple can ship iOS 18 worldwide next Monday, why can't Google?

Re: Void captures over a million Android TV boxes

#102
post #100

Some of my hard requirements for a media device are that it must not share any of my personal information with any third party and it must fully cache the full-resolution and complete media content prior to beginning playback. If it's going to be connected to the Internet it must receive regular security updates for anything that's not written in a memory- and type-safe language like Go or Rust. While Go and Rust are…

Learn to set up vlans. I use openwrt for my routers/switches, and when I first set up a "home jail" network, it was the best. next step was to set up privoxy, so I could point devices at a proxy for updates, and privoxy could whitelist the machines to proxy to.

I am running my own custom-built Debian-based router in a VM and architected an encapsulated networking infrastructure at a FAANG once, so I know perfectly well how to get the device securely connected to the Internet while isolating it from the rest of my network. While I may trust the CoreELEC image I downloaded and audited at one point in time, I won't trust the people-and/or-org that controls the servers it connects to and pulls down updates from in perpetuity. So long as it is stable and has all the features I want in it, it won't ever be talking to anything on the Internet and will be left alone. If a feature or bug ever comes along that I feel I absolutely must get an update for, I'll be pulling an updated image, auditing it, and then flashing it to the eMMC device from another trusted host. But so far I don't imagine that will ever be necessary.

Re: Void captures over a million Android TV boxes

#103
post #80

Earlier quoted context omitted.

Androids are less locked-down than iOS devices. The problem is that Google used to not have the ability to require long term support from device OEMs and now that it has the market power to demand long term support they seem reluctant to prioritize that in license agreements. Then there are devices, like in China, where Google Mobile Services is not on many phones so Google has no leverage at all re supporting update…

There is nothing in principle requiring Android phones be locked down, but its a de facto reality that manufacturers of almost all phones have made them locked down and you have to research to even know beforehand if you can even do something as little as a bootloader unlock or a rooting. Why is os and phone model so tightly integrated and locked together, when in the pc world you can generally install any os on any…

> There is nothing in principle requiring Android phones be locked down.

There is; it's called the Android Compatibility Commitment. If a phone manufacturer wants the Google Play Store, their phones need specific security requirements. Which includes measures to lock down the phone to prevent piracy of the store, which for most manufacturers is achieved through a locked bootloader.

https://assets.publishing.service.gov.uk/media/61b794d6d3bf7...

Re: Void captures over a million Android TV boxes

#104

Earlier quoted context omitted.

Its a self created problem of locked down user hostile devices. Operating system and software upgrades are not locked to the hardware manufacturer in the laptop world (not yet, for the most part). It is a pipe dream of mine that someday these attacks are used as an excuse by some government perhaps the EU to force opening up devices for install of other operating systems, maybe forced to open sourcing firmware etc.

Laptops work because the BIOS provides a universal abstraction layer and because support is upstreamed in the Linux kernel. Supporting phones for longer would require them to also upstream support.

BIOS has not shipped in a computer since 2019. UEFI is the new sheriff in town.

Re: Void captures over a million Android TV boxes

#105
post #60

Earlier quoted context omitted.

It is the reason why I have Windows tablets not Android ones. I know there are OS updates. And once they are dead I have options for Linux tablets now.

Windows 8 stopped receiving updates in January last year, which killed my Surface for me.

couldn't you install/upgrade win10 ( and possibly win11 ) on it?

Last time I checked you could totally use drivers built for windows 7 on a win 10 OS.

Re: Void captures over a million Android TV boxes

#106
post #34

Earlier quoted context omitted.

That makes me think, will we have car theft in the future where someone hacks your self driving car and it makes off on itself in the night? The next day you wake up to notice that your car has left you for someone else?

I think this is one of the reasons (among many) why self driving cars will largely be robo taxi's. I'd trust google to maintain the security in a fleet of robo taxi's where cars can be brought in, modified or replaced relatively quickly over Tesla trying to convince individual owners to do the same...

Only if cities remove all permanent parking space and it forces people to switch.

People are too attached with property and social status stuff.

Re: Void captures over a million Android TV boxes

#107
post #66

It's not Android TV boxes. It's TV boxes running Android.

So distressing to see this so far down. In fact "Android TV" is an OS product, and not related to this exploit. These are televisions that simply run "Android" as in an open source AOSP build unrelated to a Google product certification.

"Android TV" is also old enough for many unpatched and vulnerable TVs/appliances to be in the wild too though.

Re: Void captures over a million Android TV boxes

#108
post #67

Earlier quoted context omitted.

> Windows is way more stable than it was 20 years ago. The problem with Windows today is more that it wants to opaquely update itself all the time, and the user gets undesired mandatory "updates" such as ads in menus and sending "telemetry" home (ie user activity data for MS' machine learning ambitions). But of course the most important thing is to keep fucking web browsers up-to-date with laughable and undesired CSS…

This just reads as a grab bag of complaints about modern tech with little relevance to the topic at hand

Modern tech has everything to do with the topic at hand.

Re: Void captures over a million Android TV boxes

#109
post #34

Earlier quoted context omitted.

I think this is one of the reasons (among many) why self driving cars will largely be robo taxi's. I'd trust google to maintain the security in a fleet of robo taxi's where cars can be brought in, modified or replaced relatively quickly over Tesla trying to convince individual owners to do the same...

Only if cities remove all permanent parking space and it forces people to switch. People are too attached with property and social status stuff.

Existing people are, in a world where your teenager has been getting self driving robo taxi's to their friends house since the age of 13 I'm not sure if they'll magically want a car when they reach the legal age to drive, hell there's people now who uber everywhere over learning to drive.

Beyond that, it seems like the nature of self driving might be one of gradual incremental improvement, where in order to actually develop it you more or less have to run a fleet of robo taxi's in different places with different climates and different road conditions.

Finally, the people most likely to deliver it are google (waymo) and I think they have zero desire to sell cars to consumers but are literally running a taxi service as we speak.

Re: Void captures over a million Android TV boxes

#110
post #2

What's going to be even more fun is when the cars gets hacked, given that their are 100+ (200+) car makers, specially with ev cars (WSJ claimed 140+ makers in China) Bloomberg claimed 500+. I'm not dissing Chinese makers. I'm only sure that like everything there's an exponential curve of how serious companies take security. I'm guessing, of the car makers out there, Tesla and Rivan are near the top since they are new…

There's actually a strange tradeoff with automotive companies. Security requirements are a big forcing function driving vehicle electronics architectures to modernize and adopt similar security practices to consumer electronics, away from the traditionally developed and profoundly insecure embedded systems of yesteryear. That brings a lot of security features with secure communications, secure boot, signed updates, e…

Have any reading or publicly available resources on this?
Post reply on HN