Live data from Hacker News

OEMpocalypse: Unprivileged Android app to root on Samsung, Xiaomi, others

calif.io

11–20 of 62 posts

Re: OEMpocalypse: Unprivileged Android app to root on Samsung, Xiaomi, others

#11

A good security track record must be the most valuable company asset in history. Apple makes $200B per year from selling the iPhone alone. Plus the services they sell on it, plus deals like the one with Google, plus app store ads, plus cross-selling of other hardware ... I have one too. Not because I like the hardware too much. Pixel phones are much nicer, they don't wobble when you put them on a table. Not because I…

https://mashable.com/article/high-sierra-password-fix-apple-... > In the simplest of terms, with the bug, if you created a new APFS (Apple File System) encrypted volume on High Sierra, and set anything at all as the password hint, then your password was stored as the hint. In plain text.

I know Apple phones had bugs. Even worse bugs than the one you linked to.

But Google phones had those too.

That's why I said I "feel" like Apple takes security more seriously. And that I wish there were hard facts. Statistics of number of bugs by severity. Independently verified.

Re: OEMpocalypse: Unprivileged Android app to root on Samsung, Xiaomi, others

#12

Earlier quoted context omitted.

https://mashable.com/article/high-sierra-password-fix-apple-... > In the simplest of terms, with the bug, if you created a new APFS (Apple File System) encrypted volume on High Sierra, and set anything at all as the password hint, then your password was stored as the hint. In plain text.

I know Apple phones had bugs. Even worse bugs than the one you linked to. But Google phones had those too. That's why I said I "feel" like Apple takes security more seriously. And that I wish there were hard facts. Statistics of number of bugs by severity. Independently verified.

Your post is essentially admitting that you're ignoring the bugs from the company you love and taking seriously form the company you don't.

So the difference isn't about taking things "more seriously", but in the fact that you take marketing from Apple more seriously.

That's not the same.

(Note: There's plenty of proof that Apple does take security more seriously than Samsung, Xiaomi & Co. in the article, but your feelings aren't it.)

Re: OEMpocalypse: Unprivileged Android app to root on Samsung, Xiaomi, others

#13
post #12

Earlier quoted context omitted.

I know Apple phones had bugs. Even worse bugs than the one you linked to. But Google phones had those too. That's why I said I "feel" like Apple takes security more seriously. And that I wish there were hard facts. Statistics of number of bugs by severity. Independently verified.

Your post is essentially admitting that you're ignoring the bugs from the company you love and taking seriously form the company you don't. So the difference isn't about taking things "more seriously", but in the fact that you take marketing from Apple more seriously. That's not the same. (Note: There's plenty of proof that Apple does take security more seriously than Samsung, Xiaomi & Co. in the article, but your fe…

Good thing they never claimed their feelings were proof of anything.

Re: OEMpocalypse: Unprivileged Android app to root on Samsung, Xiaomi, others

#14

A good security track record must be the most valuable company asset in history. Apple makes $200B per year from selling the iPhone alone. Plus the services they sell on it, plus deals like the one with Google, plus app store ads, plus cross-selling of other hardware ... I have one too. Not because I like the hardware too much. Pixel phones are much nicer, they don't wobble when you put them on a table. Not because I…

Doesn't make a difference if Apple takes security more seriously if they bend like a rubber pole when the government comes asking...

Re: OEMpocalypse: Unprivileged Android app to root on Samsung, Xiaomi, others

#15
Slightly unrelated: is it relatively safe to root android phones nowadays or should I stick to the unrooted standard android? The reason I'm asking is that I'm stuck with authy as a MFA code app, and would like to move to something that has both desktop and phone support, and my conclusion is I'd need to root my phone to get access to the actual MFA seeds (they don't allow exports to keep you stuck in their app).

Re: OEMpocalypse: Unprivileged Android app to root on Samsung, Xiaomi, others

#17
post #15

Slightly unrelated: is it relatively safe to root android phones nowadays or should I stick to the unrooted standard android? The reason I'm asking is that I'm stuck with authy as a MFA code app, and would like to move to something that has both desktop and phone support, and my conclusion is I'd need to root my phone to get access to the actual MFA seeds (they don't allow exports to keep you stuck in their app).

The main issue is that many apps will block rooted phones (banks, state apps and the like). Usually more trouble than it's worth.

Re: OEMpocalypse: Unprivileged Android app to root on Samsung, Xiaomi, others

#18
post #15

Slightly unrelated: is it relatively safe to root android phones nowadays or should I stick to the unrooted standard android? The reason I'm asking is that I'm stuck with authy as a MFA code app, and would like to move to something that has both desktop and phone support, and my conclusion is I'd need to root my phone to get access to the actual MFA seeds (they don't allow exports to keep you stuck in their app).

Some apps such as Aegis allow exporting the MFA secrets.

Re: OEMpocalypse: Unprivileged Android app to root on Samsung, Xiaomi, others

#19
post #7

will the "exploit" app be available? asking for a friend :D

would you install such a app (without compiling from source)? I would not trust it to not come with "friends" (but would love to verify and use)

On an isolated test device for this purpose, yes. But otherwise, I would decompile it to look at it.

Re: OEMpocalypse: Unprivileged Android app to root on Samsung, Xiaomi, others

#20

A good security track record must be the most valuable company asset in history. Apple makes $200B per year from selling the iPhone alone. Plus the services they sell on it, plus deals like the one with Google, plus app store ads, plus cross-selling of other hardware ... I have one too. Not because I like the hardware too much. Pixel phones are much nicer, they don't wobble when you put them on a table. Not because I…

The issue is that Android is open while Apple seldom talks about their security issues.

This might make Apple look like the more secure option but the reality may be different because Android is more scrutinised.

If you are sceptical consider these examples: (1) some versions of Apple silicon have unpatchable security defects, (2) Apple at one point decided to not contact up to 500M users affected by a supply chain attack in China due to "language difficulties".

Post reply on HN