Live data from Hacker News

Major Android Bug Is a Privacy Disaster (CVE-2014-6041)

community.rapid7.com

31–40 of 232 posts

Re: Major Android Bug Is a Privacy Disaster (CVE-2014-6041)

#31
post #11

So the bug is only for a browser that isn't supported by Google? No surprise that it hasn't been patched. If security is such a big deal to a user they should use a browser that is supported by a strong development team. Firefox and Opera Mobile work fine on low end phones.

Even if we accept your dismissal of this issue, and I sure don't, this is indicative of Android's issues as a platform. Massive vulnerability affecting huge proportion of installed base is ignored by vendor.

Re: Major Android Bug Is a Privacy Disaster (CVE-2014-6041)

#34
post #21
post #16

Earlier quoted context omitted.

"a browser that isn't supported by Google" But still a browser that was created by Google and was bundled with the OS until 12 months ago, never mind how long it takes OEMs to roll it out. Android https://developer.android.com/about/dashboards/index.html?ut... Just because Google decided not to support it any more doesn't mean they shouldn't . Pointing out Firefox and Opera is all very well, but this is the default b…

Very few people explore other browsers? Alt browsers are often the first app that people download. Chrome is included in gapps.

Who, engineers? Certainly not my wife or anyone else I have ever met who isn't technical.

Re: Major Android Bug Is a Privacy Disaster (CVE-2014-6041)

#35
post #27
post #23

Earlier quoted context omitted.

Only 20% of mobile web traffic comes from ASOP browser.

That's because most web traffic comes from iOS. AOSP Browser represents about half of the Android traffic.

Well, not everywhere. Here in Brazil, Androids have the (by a huge margin) biggest share of the market and of the mobile traffic.

Re: Major Android Bug Is a Privacy Disaster (CVE-2014-6041)

#36
post #17

It's this sort of thing that puts me off Android as a platform. Even my mother got sold a 2.2 handset recently (Samsung Galaxy Ace) that hasn't been patched for the best part of 3 years. You never know when you're going to end up with a lemon on your hands. Big jump to this conclusion but I'm more inclined to trust Microsoft at the moment as they have a better reputation for lifetime (unlike Android), have a very pub…

Android One is meant to make it simple for lo-end OEMs to ship high quality implementations of up-to-date Android and keep up with new releases. It's hard to migrate a huge OEM ecosystem to that kind of program quickly.

I doubt that will happen. At $100 a handset where is the return and motivation for an OEM to bother pushing updates out for firmware/integration testing etc (that the telcos require)? Look at the aforementioned Galaxy Ace in my last comment which is exactly where this will end up, yet again.

Also, they say 2 years' support. If you look at the phone recycling business, there is 4-5 years life in a franken-handset shipped abroad.

Re: Major Android Bug Is a Privacy Disaster (CVE-2014-6041)

#37
I am a big Linux fan and appreciate the openness and control that I can get with Android as opposed to Apple and Microsoft products, but...

My Android experience has been shit, and I'm really getting sick of it.

Admittedly, much or even most of the problem for me is the OEMs screwing things up and not sending out updates.

Re: Major Android Bug Is a Privacy Disaster (CVE-2014-6041)

#39

If you aren't familiar with SOP, this is about the worst "stupid web vuln" that can happen. SOP is the glue that kind of almost makes the web secure. The attack DOES work if X-Frame-Options is enabled (thanks joev. The msfmodule says so clearly). ALL sites with or without XFrameOptions can be loaded in an iframe, and sent to a bad guy. If you would like to test on your device/browser, you can on ejj.io/SOP.php . If y…

Actually X-Frame-Options does not save you here. There is a BYPASS_XFO datastore option in the module that turns this into a one-click exploit. This allows the attack to work against sites with the XFO header.

Re: Major Android Bug Is a Privacy Disaster (CVE-2014-6041)

#40
post #11

So the bug is only for a browser that isn't supported by Google? No surprise that it hasn't been patched. If security is such a big deal to a user they should use a browser that is supported by a strong development team. Firefox and Opera Mobile work fine on low end phones.

Pretty much the tone-deaf reaction I was expecting. Thanks!

(Of course, these devices will still be counted by those touting Android's market share. Surprise surprise)

Post reply on HN