It's this sort of thing that puts me off Android as a platform. Even my mother got sold a 2.2 handset recently (Samsung Galaxy Ace) that hasn't been patched for the best part of 3 years. You never know when you're going to end up with a lemon on your hands. Big jump to this conclusion but I'm more inclined to trust Microsoft at the moment as they have a better reputation for lifetime (unlike Android), have a very pub…
The continuing sales of the Galaxy Ace should be criminal. If you buy one and update all apps it comes with, bam: you're out of space. Not to mention even if you apply all updates available you're still a walking target for every Android exploit that's come out in the last 3 years. It is completely unfit for purpose, but even when replacements came out (Y, Ace 2) the shops near me were still pushing the Ace. Why??
Major Android Bug Is a Privacy Disaster (CVE-2014-6041)
221–230 of 232 posts
Re: Major Android Bug Is a Privacy Disaster (CVE-2014-6041)
#222Earlier quoted context omitted.
I think Google needs to change that as well. Android is seen as a second class OS by a large percentage of people, and these kinds of revelations only increase that percentage. Google can do better, but for whatever reason they aren't.
I think the large percentage of people that see Android as 2nd class don't know what an OS is, nor are they likely to become aware of this issue.
Re: Major Android Bug Is a Privacy Disaster (CVE-2014-6041)
#223Just an update from the Google side: As discussed below, any Android users on 4.4+ or running Chrome are not affected. For earlier versions of Android, we've shipped patches for AOSP: https://android.googlesource.com/platform/external/webkit/+/... https://android.googlesource.com/platform/external/webkit/+/... These are in the AOSP branches for jb-dev, jb-mr1-dev, jb-mr1.1-dev, and jb-mr2-dev.
is android kitkat 4.4.x safe from this bug regardless of whether chrome browser exists (not installed or uninstalled) in the phone or not? please enlighten. thanks.
Re: Major Android Bug Is a Privacy Disaster (CVE-2014-6041)
#224Just an update from the Google side: As discussed below, any Android users on 4.4+ or running Chrome are not affected. For earlier versions of Android, we've shipped patches for AOSP: https://android.googlesource.com/platform/external/webkit/+/... https://android.googlesource.com/platform/external/webkit/+/... These are in the AOSP branches for jb-dev, jb-mr1-dev, jb-mr1.1-dev, and jb-mr2-dev.
Re: Major Android Bug Is a Privacy Disaster (CVE-2014-6041)
#225Just an update from the Google side: As discussed below, any Android users on 4.4+ or running Chrome are not affected. For earlier versions of Android, we've shipped patches for AOSP: https://android.googlesource.com/platform/external/webkit/+/... https://android.googlesource.com/platform/external/webkit/+/... These are in the AOSP branches for jb-dev, jb-mr1-dev, jb-mr1.1-dev, and jb-mr2-dev.
Does this mean that there will be an update for the Galaxy Nexus?
Re: Major Android Bug Is a Privacy Disaster (CVE-2014-6041)
#226It's this sort of thing that puts me off Android as a platform. Even my mother got sold a 2.2 handset recently (Samsung Galaxy Ace) that hasn't been patched for the best part of 3 years. You never know when you're going to end up with a lemon on your hands. Big jump to this conclusion but I'm more inclined to trust Microsoft at the moment as they have a better reputation for lifetime (unlike Android), have a very pub…
Yes, this continues to be a problem that I hope Google addresses somehow. I got the Samsung Galaxy Nexus because I assumed it would be kept up to date with the latest Android version, since it's using the Google brand 'Nexus' name. I even asked the sales representative if it would be kept up to date (knowing I couldn't trust them, but was looking for any extra assurance), and they said yes. Right now it's at 4.3 and…
Re: Major Android Bug Is a Privacy Disaster (CVE-2014-6041)
#227If you aren't familiar with SOP, this is about the worst "stupid web vuln" that can happen. SOP is the glue that kind of almost makes the web secure. The attack DOES work if X-Frame-Options is enabled (thanks joev. The msfmodule says so clearly). ALL sites with or without XFrameOptions can be loaded in an iframe, and sent to a bad guy. If you would like to test on your device/browser, you can on ejj.io/SOP.php . If y…
What's the expected response when clicking the button in Chrome on Android 4.4.4? I'm on a Nexus 5, on 4.4.4 and I see an alert box in Chrome 37.0.2062.117.
Expected is no alert box
Re: Major Android Bug Is a Privacy Disaster (CVE-2014-6041)
#228Earlier quoted context omitted.
Does this mean that there will be an update for the Galaxy Nexus?
OS updates for $SPECIFIC_PHONE are generally reliant on the carrier to decide to push out a patch, even after AOSP itself is patched. So an answer "from the Google side" can't really answer your question.
Re: Major Android Bug Is a Privacy Disaster (CVE-2014-6041)
#229Earlier quoted context omitted.
is android kitkat 4.4.x safe from this bug regardless of whether chrome browser exists (not installed or uninstalled) in the phone or not? please enlighten. thanks.
My understanding is that Chrome replaced Webkit in WebView's internal implementation in 4.4, so the bug should never appear in 4.4.
Re: Major Android Bug Is a Privacy Disaster (CVE-2014-6041)
#230Earlier quoted context omitted.
both are chrome. just different versions. google ridicules microsoft with IE6, and the first offline platform they release they made the exact same mistake! bundle a integrated browser just so the use cant uninstall... and decide to not patch it.
not the exact same mistake, as you can install chrome...and now those can at least be disabled. Un-installable system apps...another place where the microsoft and apple default is a mistake.
your other arguments, maybe on your fancy phone. 99% of the phones still stuck on 2.3.3 or older, you
- can't disable system apps
- can't uninstall system apps
- usually have 60mb or less for apps.
- can use the SD card for apps.
that leaves ANY browser out of the option. chrome and firefox, both install on around 20 to 40mb... and then consumes an additional (non-configurable) 100+mb of cache on the app data partition. leaving any older phone crippled (you can't fetch background data when the low storage space warning is showing).