Live data from Hacker News

Major Android Bug Is a Privacy Disaster (CVE-2014-6041)

community.rapid7.com

201–210 of 232 posts

Re: Major Android Bug Is a Privacy Disaster (CVE-2014-6041)

#201
post #193

Earlier quoted context omitted.

I think Google needs to change that as well. Android is seen as a second class OS by a large percentage of people, and these kinds of revelations only increase that percentage. Google can do better, but for whatever reason they aren't.

> Google can do better, but for whatever reason they aren't. s/aren't/choose not to/ This is simply bad management – we're talking, what, a single engineer to backport critical fixes and some testing support. Contrast that against the damage this has done to Android's competitiveness – even the non-nerds I know talk about how they bought an iOS device because Android never gets updates – and increases the likelihood…

>> we're talking, what, a single engineer to backport critical fixes and some testing support.

Understatement of the day? :) There is absolutely no way a single developer will be able to support huge/complex codebases like web-browsers across platform versions.

Also keep in mind that most of the original developers would have moved on from the project - due to lack of interest, greener pastures etc. I am wondering what kind of engineer would be willing to babysit a project like this - and if somebody is willing (for whatever reasons), would they be competent enough?

Re: Major Android Bug Is a Privacy Disaster (CVE-2014-6041)

#202
It was a mistake to put Webkit as an operating system level component in the first place. It would be better if the solution wasn't to push Chromium but a storage framework style pluggable component, mainly since they can't get stuff like text sizing right.

Luckily since most vital user info is going to be in apps this doesn't have nearly the same impact as it would on desktop, but it does represent yet another demonstration that having the web as a sort of super-platform-on-a-platform doubles your attack surface.

Android really is comparable to 90s era Windows, in every possible sense. For better or worse Chrome OS is clearly being positioned as the NT equivalent as well, but it's hard to see how you can recreate the functionality of Android without adopting the flaws too.

Re: Major Android Bug Is a Privacy Disaster (CVE-2014-6041)

#203

If you aren't familiar with SOP, this is about the worst "stupid web vuln" that can happen. SOP is the glue that kind of almost makes the web secure. The attack DOES work if X-Frame-Options is enabled (thanks joev. The msfmodule says so clearly). ALL sites with or without XFrameOptions can be loaded in an iframe, and sent to a bad guy. If you would like to test on your device/browser, you can on ejj.io/SOP.php . If y…

What's the expected response when clicking the button in Chrome on Android 4.4.4? I'm on a Nexus 5, on 4.4.4 and I see an alert box in Chrome 37.0.2062.117.

Re: Major Android Bug Is a Privacy Disaster (CVE-2014-6041)

#204
post #67

If you haven't tried Firefox Fennec (android mobile) it is actually pretty good now. https://play.google.com/store/apps/details?id=org.mozilla.fi... https://www.mozilla.org/en-US/firefox/partners/#android They make it for arm and x86 android. They used to make a windows version but sadly stopped that build.

It crashes every time I hit the menu button. I sent in the crash report; I couldn't figure out where on mozilla's website to report mobile bugs though.

Re: Major Android Bug Is a Privacy Disaster (CVE-2014-6041)

#205

Earlier quoted context omitted.

WebView uses Chrome as of 4.4 as well. Also many apps that use WebView show only their own content in it. There are only a couple apps that show user specified content in app via WebView, like Reddit and HN. Even if I were to go back to the old Internet app instead of Chrome, this bug is irrelevant to me since I use an app for GMail, Twitter, Facebook and anything else important. I can't remember the last time I used…

It's still a copy of the browser code that comes with the base OS, even if it dodges the bullet on this bug. The Chromium-based WebView doesn't receive updates like the Chrome app so will generally contain unpatched vulnerabilities, so the system level issue remains. (Note that the rare-to-nonexsistent OS updates are still a problem, this WebView issue nonwithstanding. They are running old vulnerable Linux kernels wh…

> The Chromium-based WebView doesn't receive updates like the Chrome app

We hope to see that change very soon. http://thenextweb.com/google/2013/11/12/google-says-working-...

Re: Major Android Bug Is a Privacy Disaster (CVE-2014-6041)

#206
post #97

Earlier quoted context omitted.

People need to stop buying terrible phones. Consumers keep rewarding companies who don't keep up with their promises and thus no one ends up giving a crap. In my opinion if you're not going to buy a Nexus device or a Moto E/G/X then you might as well buy Apple. The Android One program will hopefully add more to that.

But the Nexus devices are just as bad as the others. If you had bought the latest model last year you'd be screwed on updates by now. I'd love to buy an iPhone but I want to run Android software so Android it is.

There's test builds of Android L for the Nexus 4 available, so it looks like it will also officially get that release. It's still got 2GB of RAM and a quad-core 32-bit ARM, so it's not too different from the Nexus 5 in that sense. It is really a question of how long Qualcomm will support the S4 Pro board support package. If we've all moved to 64-bit ARM cores, then that'll be a bigger problem for these older 32-bit phones.

Re: Major Android Bug Is a Privacy Disaster (CVE-2014-6041)

#207
The general lack of updates is exactly why I use/install/recommend Firefox. That and the automatic syncing w/ Desktop and the regular performance improvements. (Chrome isn't an option. I can't even turn off third-party cookies. In 2014.)

Too bad it uses quite a few resources and may be too heavy for low-end phones.

Re: Major Android Bug Is a Privacy Disaster (CVE-2014-6041)

#208

Earlier quoted context omitted.

> Font sizing is bizarre too. Web pages suddenly have font sizes increasing and decreasing seemingly at random, and to the point of illegibility I haven't tried Chrome, but I see this in CyanogenMod's stock browser (probably close to AOSP) and Firefox. In Firefox's case at least, my research pointed to "font boosting" being the cause of increasing/decreasing, but I haven't found a good fix.

Amazing! Now that I know the term to search for, I'm certain that this is the misfeature that aggravates me so. My AOSP browser (which is 4.0.3) doesn't have this problem. I like the comment in the webkit bug discussing it: "In terms of status, this is shipping in stable Chrome for Android with acceptable quality." Ugh.

I thought it was something wrong with my CM build, or maybe because I didn't install gapps (Google's proprietary apps). I'm amazed to find the developers call this acceptable.

Re: Major Android Bug Is a Privacy Disaster (CVE-2014-6041)

#209
post #197

Earlier quoted context omitted.

I believe only Chrome has built-in PDF viewing too, which can be nice. The page you linked has people saying there are Chromium plugins for it, or you can install a dedicated PDF viewer and it will probably embed itself in the browser when downloading PDFs.

No longer true. The PDF viewer's been open-sourced a couple months ago. Source: https://news.ycombinator.com/item?id=7781878

Cool! Thanks.

Re: Major Android Bug Is a Privacy Disaster (CVE-2014-6041)

#210
post #78

Earlier quoted context omitted.

Just switch to CyanogenMod or other custom compilation; there is a gain from Nexus brand in the ease of unlocking bootloader (;

I'm not convinced CyanogenMod (or any other variant) is actually that great; I have a Samsung Galaxy S2 (i9100 model), the last non-nightly CyanogenMod update was over a year ago now. There have been a number of CVEs issued for Android (and likely numerous others cover Android as a platform, covering OpenSSL for example) over that time period, so there's no way the phone is anywhere near up-to-date with security fixe…

Are you sure? My Galaxy S 1 (one) still gets updates, as does my S3. They're monthly milestones now.

Maybe you need to install CM 11 first, so the system has a base to work with.

I think you can see if your phone gets updates if it's listed as CM11-supported.

Post reply on HN