Live data from Hacker News

Major Android Bug Is a Privacy Disaster (CVE-2014-6041)

community.rapid7.com

41–50 of 232 posts

Re: Major Android Bug Is a Privacy Disaster (CVE-2014-6041)

#41
post #23
post #20

Earlier quoted context omitted.

So on 90% of phones when someone opens "the web" using the browser installed on their device, they are using an unsupported browser. How would they know this?

Only 20% of mobile web traffic comes from ASOP browser.

This just keeps getting better. "Only 20% of mobile web traffic", wow.

Re: Major Android Bug Is a Privacy Disaster (CVE-2014-6041)

#42
post #16
post #11

So the bug is only for a browser that isn't supported by Google? No surprise that it hasn't been patched. If security is such a big deal to a user they should use a browser that is supported by a strong development team. Firefox and Opera Mobile work fine on low end phones.

"a browser that isn't supported by Google" But still a browser that was created by Google and was bundled with the OS until 12 months ago, never mind how long it takes OEMs to roll it out. Android https://developer.android.com/about/dashboards/index.html?ut... Just because Google decided not to support it any more doesn't mean they shouldn't . Pointing out Firefox and Opera is all very well, but this is the default b…

Could they update it, though? I thought part of the reason they went to Chrome is that the AOSP browser is baked into the OS and so not updateable without updating the whole OS. So to patch it, they'd have to update the OS, but if you're doing that, then why not just move to the latest OS, which is already fixed?

Re: Major Android Bug Is a Privacy Disaster (CVE-2014-6041)

#43
post #23
post #20

Earlier quoted context omitted.

So on 90% of phones when someone opens "the web" using the browser installed on their device, they are using an unsupported browser. How would they know this?

Only 20% of mobile web traffic comes from ASOP browser.

According to these people, Chrome and Safari also have ~20% each.

http://gs.statcounter.com/#mobile_browser-ww-monthly-201308-...

Re: Major Android Bug Is a Privacy Disaster (CVE-2014-6041)

#44
post #39

If you aren't familiar with SOP, this is about the worst "stupid web vuln" that can happen. SOP is the glue that kind of almost makes the web secure. The attack DOES work if X-Frame-Options is enabled (thanks joev. The msfmodule says so clearly). ALL sites with or without XFrameOptions can be loaded in an iframe, and sent to a bad guy. If you would like to test on your device/browser, you can on ejj.io/SOP.php . If y…

Actually X-Frame-Options does not save you here. There is a BYPASS_XFO datastore option in the module that turns this into a one-click exploit. This allows the attack to work against sites with the XFO header.

Absolutely critical to know. Thanks joev_. I see that now after reading the msfmodule. This is a good one!

Re: Major Android Bug Is a Privacy Disaster (CVE-2014-6041)

#45
post #34
post #21

Earlier quoted context omitted.

Very few people explore other browsers? Alt browsers are often the first app that people download. Chrome is included in gapps.

Who, engineers? Certainly not my wife or anyone else I have ever met who isn't technical.

Haha, I'm sure we've all had tunnel vision moments at one point or another.

Re: Major Android Bug Is a Privacy Disaster (CVE-2014-6041)

#46
post #27

Earlier quoted context omitted.

That's because most web traffic comes from iOS. AOSP Browser represents about half of the Android traffic.

Well, not everywhere. Here in Brazil, Androids have the (by a huge margin) biggest share of the market and of the mobile traffic.

They are clearly talking about normalized global metrics.

Obviously things aren't the same everywhere...

Re: Major Android Bug Is a Privacy Disaster (CVE-2014-6041)

#47
post #23
post #20

Earlier quoted context omitted.

So on 90% of phones when someone opens "the web" using the browser installed on their device, they are using an unsupported browser. How would they know this?

Only 20% of mobile web traffic comes from ASOP browser.

Back in my times browsers would kill for a 20% market share...

Re: Major Android Bug Is a Privacy Disaster (CVE-2014-6041)

#48

It's this sort of thing that puts me off Android as a platform. Even my mother got sold a 2.2 handset recently (Samsung Galaxy Ace) that hasn't been patched for the best part of 3 years. You never know when you're going to end up with a lemon on your hands. Big jump to this conclusion but I'm more inclined to trust Microsoft at the moment as they have a better reputation for lifetime (unlike Android), have a very pub…

I don't understand why people are surprised they might be sold an inferior product if they don't do a minimum of research.

Re: Major Android Bug Is a Privacy Disaster (CVE-2014-6041)

#50
post #34
post #21

Earlier quoted context omitted.

Very few people explore other browsers? Alt browsers are often the first app that people download. Chrome is included in gapps.

Who, engineers? Certainly not my wife or anyone else I have ever met who isn't technical.

My grandmother managed to switch entirely to Chrome on her PC without the help of anyone in our family. Anecdotal evidence works both ways. It isn't 1998. Most people know what a browser is and which one they are using on their desktop. Making the leap to a second browser on a phone (where they can easily get it from Google Play) isn't that ridiculous.
Post reply on HN