Live data from Hacker News

Major Android Bug Is a Privacy Disaster (CVE-2014-6041)

community.rapid7.com

81–90 of 232 posts

Re: Major Android Bug Is a Privacy Disaster (CVE-2014-6041)

#81
post #37

I am a big Linux fan and appreciate the openness and control that I can get with Android as opposed to Apple and Microsoft products, but... My Android experience has been shit, and I'm really getting sick of it. Admittedly, much or even most of the problem for me is the OEMs screwing things up and not sending out updates.

What does Android has to do with Linux? Do you also praise TiVo for the "openness and control" by using the Linux kernel?

Re: Major Android Bug Is a Privacy Disaster (CVE-2014-6041)

#82

Replaced by Chrome ("that giant hog"). I'm on a slightly older phone, but I actually removed Chrome from it not long ago. I started having problems with updating apps due to insufficient space, and while I have a fair amount of crap installed, I also have ~2.5GB of "Phone" storage for apps so I started investigating (this is separate from "sdcard" data storage which is ~8GB). Turns out Chrome, at least on the HTC Ama…

FWIW, on my Moto X running 4.4.3, Chrome takes only 65MB for the app itself. I would imagine the "bloat" comes from them including compatibility frameworks that allow Android apps to ship supporting features from newer Android releases and SDKs on older Android devices. But I also would have expected those frameworks to be handled by the Google Play Services app, rather than be bundled into every single app on your phone that needs them...

Re: Major Android Bug Is a Privacy Disaster (CVE-2014-6041)

#83

It's this sort of thing that puts me off Android as a platform. Even my mother got sold a 2.2 handset recently (Samsung Galaxy Ace) that hasn't been patched for the best part of 3 years. You never know when you're going to end up with a lemon on your hands. Big jump to this conclusion but I'm more inclined to trust Microsoft at the moment as they have a better reputation for lifetime (unlike Android), have a very pub…

Microsoft may update their older devices (well, once we moved to WP8 anyway, WP7 can go jump apparently), but my girlfriend's HTC 8X is half broken because her carrier refused to let the update go through. Absolutely frustrating... that's one thing I am happy about with my 4S, for sure. Screw carriers.

Re: Major Android Bug Is a Privacy Disaster (CVE-2014-6041)

#84
post #23

Earlier quoted context omitted.

Only 20% of mobile web traffic comes from ASOP browser.

That's 1 in 5 mobile users! How can you argue that 20% is small?

> How can you argue that 20% is small?

where did they argue that? They were just correcting the 90% claim above.

Re: Major Android Bug Is a Privacy Disaster (CVE-2014-6041)

#85
post #68

Earlier quoted context omitted.

"So the bug is only for a browser that isn't supported by Google?" Wait, what ? I'm not an android user, but I am a chrome user on all of my desktops ... can someone enlighten me ? How is chrome not a browser supported by google ?

AOSP Browser is the unsupported one. Google deprecated it in favor of Chrome.

But AOSP is still a core part of the android OS because it's used by every app that wishes to render a page.

Re: Major Android Bug Is a Privacy Disaster (CVE-2014-6041)

#86
post #65

Replaced by Chrome ("that giant hog"). I'm on a slightly older phone, but I actually removed Chrome from it not long ago. I started having problems with updating apps due to insufficient space, and while I have a fair amount of crap installed, I also have ~2.5GB of "Phone" storage for apps so I started investigating (this is separate from "sdcard" data storage which is ~8GB). Turns out Chrome, at least on the HTC Ama…

I am running out of space because Play Store and Google Framework get bigger and bigger. It fills me with rage how Google actively makes my old phone less capable over time for no benefit to me.

Yeah. I was using a Nexus One for a long time until I had to prune so many apps due to space that it wasn't worth using. I got a new phone, HTC One S (I needed a t-mobile branded phone for wifi calling) with several gigs of system partition space, and now I have to play that game again.

I recognize that there are a bunch of features now that I get to enjoy, but now I have to choose which ones I want to keep.

When I switched, 20MB was a big app. Now I have at least 30 apps that are bigger. Chrome in particular seems bogus. The desktop version isn't even this big.

   Chrome : 211MB
   Facebook: 116MB
   Google search: 70MB
   Google+: 65MB
   Amazon: 60MB
   Mantano Reader: 54MB
   Dropbox: 50MB
   Google Play services: 50MB
   Google Text-to-speach engine: 45MB
   Hangouts: 35MB
   t-mobile my account: 33MB
   SwitftKey: 33MB
   Kindle: 30MB
   Evernote: 30MB
   BaconReader: 28MB
   twitter: 25MB
   Hulu: 25MB
   Google Maps: 24MB
   Google Drive: 24MB
    

I do recognize that these apps balance the data differently. Chrome is 189MB app, and facebook is 80MB data.

Re: Major Android Bug Is a Privacy Disaster (CVE-2014-6041)

#87
post #74
post #62

Earlier quoted context omitted.

> If you care about running only open source software, that's going to be very hard to do in the Android/Google-Play ecosystem. yet, the main advertisement google trhows for android is "open source" "community driven" yadda yadda

Main advertisement? I just went to android.com and developer.android.com; android.com advertises "Google built in" and lots of platforms, with a very small link to AOSP at the bottom of the page; developer.android.com has an AOSP link buried in its menus.

It's been years since Google switched away from that claim.

Re: Major Android Bug Is a Privacy Disaster (CVE-2014-6041)

#88
post #17

It's this sort of thing that puts me off Android as a platform. Even my mother got sold a 2.2 handset recently (Samsung Galaxy Ace) that hasn't been patched for the best part of 3 years. You never know when you're going to end up with a lemon on your hands. Big jump to this conclusion but I'm more inclined to trust Microsoft at the moment as they have a better reputation for lifetime (unlike Android), have a very pub…

Android One is meant to make it simple for lo-end OEMs to ship high quality implementations of up-to-date Android and keep up with new releases. It's hard to migrate a huge OEM ecosystem to that kind of program quickly.

And Nexus was meant to make it simpler for Google to ship updates directly to users, rather than having to go through OEMs. If Google can't keep their own phones up to date, do you expect Android One to be any different?

Re: Major Android Bug Is a Privacy Disaster (CVE-2014-6041)

#89
post #78

Earlier quoted context omitted.

Yes, this continues to be a problem that I hope Google addresses somehow. I got the Samsung Galaxy Nexus because I assumed it would be kept up to date with the latest Android version, since it's using the Google brand 'Nexus' name. I even asked the sales representative if it would be kept up to date (knowing I couldn't trust them, but was looking for any extra assurance), and they said yes. Right now it's at 4.3 and…

Just switch to CyanogenMod or other custom compilation; there is a gain from Nexus brand in the ease of unlocking bootloader (;

I'm not convinced CyanogenMod (or any other variant) is actually that great; I have a Samsung Galaxy S2 (i9100 model), the last non-nightly CyanogenMod update was over a year ago now. There have been a number of CVEs issued for Android (and likely numerous others cover Android as a platform, covering OpenSSL for example) over that time period, so there's no way the phone is anywhere near up-to-date with security fixes.

CyanogenMod doesn't have any way to distinguish which phones are currently receiving security fixes in a timely manner and which are not; nor do they have any list of security advisories covering packages they distribute (go look at any notable desktop/server Linux distro — they all have public lists of security advisories and documentation of what release fixes them).

To my knowledge there is no Android distribution that has anywhere near the cohesive security story — and they're all miles behind any desktop OS.

Re: Major Android Bug Is a Privacy Disaster (CVE-2014-6041)

#90
post #65

Replaced by Chrome ("that giant hog"). I'm on a slightly older phone, but I actually removed Chrome from it not long ago. I started having problems with updating apps due to insufficient space, and while I have a fair amount of crap installed, I also have ~2.5GB of "Phone" storage for apps so I started investigating (this is separate from "sdcard" data storage which is ~8GB). Turns out Chrome, at least on the HTC Ama…

I am running out of space because Play Store and Google Framework get bigger and bigger. It fills me with rage how Google actively makes my old phone less capable over time for no benefit to me.

I lost the ability to write to my external sdcard when I got the kitkat upgrade. Of course rooting allowed me write access again. This is why the "rooting voids the warrant" policies are bullshit. When an upgrade is forced on a user, and removes critical functionality for no good reason, what is the user to do? I, for one, am never buying a locked down phone again. I'd rather not even have a phone.
Post reply on HN