Live data from Hacker News

Major Android Bug Is a Privacy Disaster (CVE-2014-6041)

community.rapid7.com

191–200 of 232 posts

Re: Major Android Bug Is a Privacy Disaster (CVE-2014-6041)

#191
post #186

Earlier quoted context omitted.

Note that this isn't an "incredibly serious system level issue." This is an issue with a browser that Google hasn't supported for several years, since they replaced it with Chrome. It also doesn't affect alternative browsers like Firefox or Opera. Note that if Apple had a similar vulnerability, you likely couldn't work around it by using an alternative browser, because all browsers are required to use Safari's render…

In addition to the Browser app that is still widely use in devices with less-than-latest Android versions, It's present in every app that uses WebView. And you only get fixes to WebView via OS updates. (x) (x) Maybe. Assuming someone bothers to incorporate them into to the OS update for your device and they make it through the hurdles between the engineer and OTA update certification.

Android 4.4 and up use Chrome in their webviews, rather than the AOSP browser.

Re: Major Android Bug Is a Privacy Disaster (CVE-2014-6041)

#192
post #186

Earlier quoted context omitted.

Note that this isn't an "incredibly serious system level issue." This is an issue with a browser that Google hasn't supported for several years, since they replaced it with Chrome. It also doesn't affect alternative browsers like Firefox or Opera. Note that if Apple had a similar vulnerability, you likely couldn't work around it by using an alternative browser, because all browsers are required to use Safari's render…

In addition to the Browser app that is still widely use in devices with less-than-latest Android versions, It's present in every app that uses WebView. And you only get fixes to WebView via OS updates. (x) (x) Maybe. Assuming someone bothers to incorporate them into to the OS update for your device and they make it through the hurdles between the engineer and OTA update certification.

WebView uses Chrome as of 4.4 as well. Also many apps that use WebView show only their own content in it. There are only a couple apps that show user specified content in app via WebView, like Reddit and HN.

Even if I were to go back to the old Internet app instead of Chrome, this bug is irrelevant to me since I use an app for GMail, Twitter, Facebook and anything else important. I can't remember the last time I used the mobile browser for anything that matters.

Re: Major Android Bug Is a Privacy Disaster (CVE-2014-6041)

#193
post #181

Earlier quoted context omitted.

Even if they do fast vuln updates, what about older devices? Even Google only offers 2y of support.

I think Google needs to change that as well. Android is seen as a second class OS by a large percentage of people, and these kinds of revelations only increase that percentage. Google can do better, but for whatever reason they aren't.

> Google can do better, but for whatever reason they aren't.

s/aren't/choose not to/

This is simply bad management – we're talking, what, a single engineer to backport critical fixes and some testing support. Contrast that against the damage this has done to Android's competitiveness – even the non-nerds I know talk about how they bought an iOS device because Android never gets updates – and increases the likelihood that they'll have a major security problem at some point when someone creates widespread exploit affecting all of those abandoned phones and the headlines talk about how many millions of people are at risk for a problem which was reported years ago.

The phone vendors and carriers had a large part in creating this problem but most of the reputation sticks to the platform and, as with the more general fragmentation problem, Google has been very slow to take it seriously.

Re: Major Android Bug Is a Privacy Disaster (CVE-2014-6041)

#194

Earlier quoted context omitted.

In addition to the Browser app that is still widely use in devices with less-than-latest Android versions, It's present in every app that uses WebView. And you only get fixes to WebView via OS updates. (x) (x) Maybe. Assuming someone bothers to incorporate them into to the OS update for your device and they make it through the hurdles between the engineer and OTA update certification.

WebView uses Chrome as of 4.4 as well. Also many apps that use WebView show only their own content in it. There are only a couple apps that show user specified content in app via WebView, like Reddit and HN. Even if I were to go back to the old Internet app instead of Chrome, this bug is irrelevant to me since I use an app for GMail, Twitter, Facebook and anything else important. I can't remember the last time I used…

It's still a copy of the browser code that comes with the base OS, even if it dodges the bullet on this bug. The Chromium-based WebView doesn't receive updates like the Chrome app so will generally contain unpatched vulnerabilities, so the system level issue remains.

(Note that the rare-to-nonexsistent OS updates are still a problem, this WebView issue nonwithstanding. They are running old vulnerable Linux kernels which compromises the app sandbox)

Re: Major Android Bug Is a Privacy Disaster (CVE-2014-6041)

#195
post #83

It's this sort of thing that puts me off Android as a platform. Even my mother got sold a 2.2 handset recently (Samsung Galaxy Ace) that hasn't been patched for the best part of 3 years. You never know when you're going to end up with a lemon on your hands. Big jump to this conclusion but I'm more inclined to trust Microsoft at the moment as they have a better reputation for lifetime (unlike Android), have a very pub…

Microsoft may update their older devices (well, once we moved to WP8 anyway, WP7 can go jump apparently), but my girlfriend's HTC 8X is half broken because her carrier refused to let the update go through. Absolutely frustrating... that's one thing I am happy about with my 4S, for sure. Screw carriers.

So Windows Phone is updated at the will of the carriers as well? Basically the only way to get updates to your smart phone is either -

1. iPhone 2. Custom Rom and you're on your own.

Re: Major Android Bug Is a Privacy Disaster (CVE-2014-6041)

#196
post #186

Android has its merits, but more and more I am reminded of this aptly titled article (proudly mentioned by Tim Cook during the WWDC keynote): " Android Fragmentation Turning Devices Into a Toxic Hellstew of Vulnerabilities " [1]. These kinds of incredibly serious, system level issues are a significant competitive disadvantage, and they keep happening. Google needs to build fast security update requirements into their…

Note that this isn't an "incredibly serious system level issue." This is an issue with a browser that Google hasn't supported for several years, since they replaced it with Chrome. It also doesn't affect alternative browsers like Firefox or Opera. Note that if Apple had a similar vulnerability, you likely couldn't work around it by using an alternative browser, because all browsers are required to use Safari's render…

My LG G2 (12 months old) shipped with an App called "Browser" and no Chrome.

Is this not the app you're talking about?

I would guess a great many Android users (if not the majority of Android users) are not using Chrome.

In fact, that's exactly the case according to this: http://www.netmarketshare.com

Chrome has made some strides this year, but the Android Browser still leads by a point. That'll probably change next month or two I'd guess. But unless I'm entirely off base and talking about the wrong thing, I think your comment is very misleading.

If this happened with Safari, you'd likely see a patch pretty quickly, and it would be available to almost everyone at the same time.

Re: Major Android Bug Is a Privacy Disaster (CVE-2014-6041)

#197
post #53

Earlier quoted context omitted.

It is very very close: https://code.google.com/p/chromium/wiki/ChromiumBrowserVsGoo... tl;dr: Chromium is Chrome minus: 1. Crash/usage reporting to Google. 2. Proprietary video format support 3. Embedded Flash implementation (which doesn't exist on mobile anyway). 4. Google API keys. If what you care about is security auditability, that's pretty good. If you care about running only open source software, that's going…

I believe only Chrome has built-in PDF viewing too, which can be nice. The page you linked has people saying there are Chromium plugins for it, or you can install a dedicated PDF viewer and it will probably embed itself in the browser when downloading PDFs.

No longer true. The PDF viewer's been open-sourced a couple months ago. Source: https://news.ycombinator.com/item?id=7781878

Re: Major Android Bug Is a Privacy Disaster (CVE-2014-6041)

#198
post #186

Android has its merits, but more and more I am reminded of this aptly titled article (proudly mentioned by Tim Cook during the WWDC keynote): " Android Fragmentation Turning Devices Into a Toxic Hellstew of Vulnerabilities " [1]. These kinds of incredibly serious, system level issues are a significant competitive disadvantage, and they keep happening. Google needs to build fast security update requirements into their…

Note that this isn't an "incredibly serious system level issue." This is an issue with a browser that Google hasn't supported for several years, since they replaced it with Chrome. It also doesn't affect alternative browsers like Firefox or Opera. Note that if Apple had a similar vulnerability, you likely couldn't work around it by using an alternative browser, because all browsers are required to use Safari's render…

Think of it the way Apple abandoned Safari for Windows without letting the users know. They're still using Safari for Windows, it's just completely insecure and they have no idea.

Re: Major Android Bug Is a Privacy Disaster (CVE-2014-6041)

#199
post #167

Earlier quoted context omitted.

The OSX "show info" dialog block shows the file size in disk blocks, as opposed to the actual bytes of file content. There might be a misunderstanding between people because the "real" file size is different than the "actually occupied" disk size. This is of course aggravated by lots of small files.

Just to be sure: $ du -h -d 0 /Applications/Google\ Chrome.app 317M /Applications/Google Chrome.app $ tar -c -f - /Applications/Google\ Chrome.app | wc -c tar: Removing leading '/' from member names 331683840 $ find /Applications/Google\ Chrome.app -type f -print0 | xargs -0 cat | wc -c 331010107

On win8, the total Chrome dir is 450MB, but that includes two versions, and a backup of the installer of the latest. Excluding those and the flash plugin, the running Chrome's (37.0.2062.120) contents are 115MB.

Re: Major Android Bug Is a Privacy Disaster (CVE-2014-6041)

#200

Earlier quoted context omitted.

I'm reinstalling right now to test, it shows as a ~28MB download. I feel pretty confident it's not cached data in my case, as I don't use the Chrome browser on my phone (I prefer Dolphin with gestures & LastPass integration), and on a tablet I only use it for logging into wifi hotspots. .... And after the reinstall it shows up as 65MB of app.

Dolphin is affected too.

Checking.... Dolphin is a little weird on its own with the separate browser and "Dolphin Jetpack" (basically its own custom-built webkit engine).

Looking before removing Dolphin, Dolphin is showing 13.82MB of App plus 42MB of Data (which I believe could mostly be moved to phone storage). Also 2.3MB of cache. Jetpack is showing 18.67MB of App, 4k of Data.

After reinstalling both and a first run of Dolphin (and restoring a slightly out of date backup for bookmarks, etc.), Dolphin is using 13.80MB of App and 4.66MB of Data, while Jetpack is using 18.67MB of App.

I'm not seeing the same thing happening with Dolphin as with Chrome.

Post reply on HN