Live data from Hacker News

Update from the CEO

googleblog.blogspot.com

211–216 of 216 posts

Re: Update from the CEO

#211
post #203
post #138

Earlier quoted context omitted.

You couldn't be more wrong and, unfortunately, I don't have the karma yet to enable downvoting :-). Easy example as long as we're on the topic, the Chrome browser or ChromeOS. I can think of a dozen things that could be done to Android to both mitigate against current threats and exploited weaknesses and either not interfere with or improve user experience. Unfortunately, we are long past the point where fundamental…

Please be humble, when you have the capability to down vote comments in the future and think of the humbleness from the HN Guidelines and this particular part: "When disagreeing, please reply to the argument instead of calling names." (Albeit, you're not calling names - but threatening to down vote is a little bit uneasing.) Thank you.

Sorry! It wasn't a threat, just pointing out my disagreement.

Re: Update from the CEO

#212
post #208

Earlier quoted context omitted.

>Android sits somewhere between "gift to hackers" and "Windows XP". It is hard to take you seriously. Let's be clear that the malware problem on Android aren't apps exploiting any weakness in the platform itself beyond the simplicity of pushing apps onto the market. They aren't exploiting that devices are running Gingerbread or anything like that. These are apps doing exactly what they are allowed to do by the system…

You clearly didn't read a single link that I posted. I did a comprehensive study of all malware targeting mobile devices between 2011 and 2012 and, yes, they are targeting the device itself and the design choices made while building it. EDIT: oh wait, there you go blaming the user again. "Grandma should have known the difference between THIS app that requested her contacts and THAT app that requests her contacts and…

EDIT: oh wait, there you go blaming the user again. "Grandma should have known the difference between THIS app that requested her contacts and THAT app that requests her contacts and stole them. Jeez Grandma! Get with it!"

No, I didn't blame the user. I pointed out that most of the problem with malware on Android, for the overwhelming majority of users (who don't sideload), was that the Play store is a wild west right now, where people pay $25 and make an account where they can instantly publish "Temp1e Run" that is actually nothing of the sort. This is the cause of the overwhelming majority of malware on Android.

Should apps be able to have those specific rights (such as sending pay SMS')? Yes, absolutely they should. The ability for apps to do more interesting things is exactly what differentiates it and makes it better. Simply saying "keep every app in a silo where it can't do anything" is not a choice users want.

EDIT: And just to loopback again, you again claim that malware needs to somehow break the bounds of the Android system to do its evil deed (exceeding permissions, cracking ASLR, etc). That is absolutely untrue in practice. Malware on Android, courtesy of the practically unmaintained primary market, is largely a study of social hacking.

Re: Update from the CEO

#213
post #119

Earlier quoted context omitted.

So iOS was adopted why...?

Because the iPhone was an obvious money printing machine, so the carriers were willing to accept the inability to put their garbage on it.

No, not really actually. They went to several carriers and Cingular was the only one that would deal with what apple wanted, and that was reluctant.

Google could have pushed harder, but they miscalculated.

Re: Update from the CEO

#214
post #194

Earlier quoted context omitted.

You manage to say a lot while saying absolutely nothing of value. That sounds harsh, but seriously thus far you've said that Andy Rubin is to blame for because , and Android has versus . I don't think I've ever read such an absolutely and completely unsupported comment chain that wasn't sitting deep in negative territory on HN. And seriously, the nonsense tweet by Schiller (who would have known that Apple would toss…

I linked to our research page, right? http://www.trailofbits.com/resources/mobile_eip_2.pdf http://techchannel.att.com/play-video.cfm/2013/1/8/Conferenc... http://techchannel.att.com/play-video.cfm/2011/7/14/Conferen... If you think that Android has a "deeply secure design", than then you probably want to start at the top. Android sits somewhere between "gift to hackers" and "Windows XP". Phil Schiller's tweet was po…

> First, Android hasn't solved the updating problem.

Sure it has - buy a nexus device, get updates. The rest isn't Google's problem as they aren't Google's devices.

> It lacks code-signing

Wrong.

> Apps have access to a shell.

So? The shell they can access can't do anything the app can't. That's like saying apps can run code - no shit, what's your point?

> App Permissions, though many people think they help with this problem, actually have nearly no effect whatsoever on the ability to root/jailbreak/privilege escalate on Android.

Of course they don't, because those are completely unrelated. iOS's code signing and other stuff hasn't stopped it from getting jailbroken. Complex systems have bugs, who'd have guessed it?

Also rooting is an actual feature on some Android phones (such as all Nexus ones) - not an exploit.

> Apps can dynamically update their own code at runtime.

Yup, and as a result Android users get to enjoy real web browsers, for example. And languages with JITs.

> If you wanted to develop a mobile/embedded platform to bring a new generation of users onto the web and into your customer base, you should have spent about 5 minutes figuring out how to do it without opening them up to harm. Android is the way it is because it wasn't believed these design features (aka safety) couldn't be included in the beginning.

Wrong. Android is easily the most securely designed OS out there that still allows side loading, period. Not claiming it is the most secure, as there are obviously bugs, but the most securely designed. Desktop OSes are incredibly bad here, and iOS only manages to prevent it by stripping you of all your freedom.

Re: Update from the CEO

#215
post #194

Earlier quoted context omitted.

I linked to our research page, right? http://www.trailofbits.com/resources/mobile_eip_2.pdf http://techchannel.att.com/play-video.cfm/2013/1/8/Conferenc... http://techchannel.att.com/play-video.cfm/2011/7/14/Conferen... If you think that Android has a "deeply secure design", than then you probably want to start at the top. Android sits somewhere between "gift to hackers" and "Windows XP". Phil Schiller's tweet was po…

> First, Android hasn't solved the updating problem. Sure it has - buy a nexus device, get updates. The rest isn't Google's problem as they aren't Google's devices. > It lacks code-signing Wrong. > Apps have access to a shell. So? The shell they can access can't do anything the app can't. That's like saying apps can run code - no shit, what's your point? > App Permissions, though many people think they help with this…

I'm getting tired of this. If you want to stick your head in the sand and ignore the data, then fine. Try and ignore this: 50% of all Android devices have unpatched vulnerabilities for which exploits exist.

https://blog.duosecurity.com/2012/09/early-results-from-x-ra...

Re: Update from the CEO

#216

Earlier quoted context omitted.

The usability of the browser is severely hampered by the security requirements. For one, it necessitates running code downloaded from the web in a sandbox, which prevents it from interacting with the rest of the computer in a meaningful way except through narrow channels designed painstakingly by committee. The web would be a much more interesting place if we could hook up arbitrary peripherals. It's holding back the…

>The web would be a much more interesting place if we could hook up >arbitrary peripherals. It's holding back the entire world from developing >better computer interfaces. Im enginering something, that was a spinoff of this thougths.. i 've go an answer balancing the good parts of the web with the good parts of the app platforms.. plus some concepts of biological cells.. it may be a party for google, apple samsung an…

I don't know Oscar :(
Post reply on HN