Live data from Hacker News

No One Cares About the Security of Unlocked Android Phones

hackernoon.com

11–20 of 44 posts

Re: No One Cares About the Security of Unlocked Android Phones

#11
post #2

Which is exactly why we need to fix this problem. Consumer products don't have good security at all and it's making the world a worse place

It's more complicated than that. If Google just produced a standard version of Android with a standard kernel version that all vendors would write for, refreshing and wiping phones would be as easy as Windows/Linux laptops. I wrote a post on this a while back:

http://penguindreams.org/blog/android-fragmentation/

Since then, I've become more and more frustrated with other ARM boards. Android fragmentation is directly related to ARM fragments and it's a huge mess. Things like device trees help, but ARM is missing the standardized architecture that Intel, Power, et. al. have.

Re: No One Cares About the Security of Unlocked Android Phones

#12
Oh, great. My BLU R1 HD from Amazon is sitting next to me as I type this. Anyone know if this is patched in the latest software update, or how I can tell if I'm affected? I don't see anything "AdUps" in the applications or services list.

edit: Per an email from Amazon, http://www.bluproducts.com/security/ has instructions.

Re: No One Cares About the Security of Unlocked Android Phones

#15
post #7

Earlier quoted context omitted.

I guess a lot of people have moved to platforms which are essentially virus-proof, like the iPad. I have several members of my family who used windows computers before, now they use iPads exclusively for all their work and pleasure. Previously any of them would open anything that they got in an email, and I guess they still do - it's just that with some devices, it's not an issue. A zipped up virus won't do any harm…

Pretty much this, security isn't improving, its just those infected zip & doc files usually aren't targeted at Android or iOS.

From trivial to apply app and OS updates to code signing and disabled sideloading, the mobile platforms (either one) make it really much harder to fall prey than on desktop OSes, by design. Malware authors have to hit a homerun on 0-days to even begin to get a foothold on the mobile OSes† these days.

† on properly updated devices such as the Apple ones as well as Nexus+Pixel. Probably this is where some form of vertical integration starts to really matter in practice.

Re: No One Cares About the Security of Unlocked Android Phones

#16
post #4
post #2

Which is exactly why we need to fix this problem. Consumer products don't have good security at all and it's making the world a worse place

The strange thing is that I have less people around me with virus problems, stolen card problems, scam problems, etc than 10 years ago. Despite the fact that we deem those devices less secure. Something is off.

Maybe criminals are more subtle now. For example most people who own devices that are part of the Mirai botnet are not aware of it.

Re: No One Cares About the Security of Unlocked Android Phones

#17

Oh, great. My BLU R1 HD from Amazon is sitting next to me as I type this. Anyone know if this is patched in the latest software update, or how I can tell if I'm affected? I don't see anything "AdUps" in the applications or services list. edit: Per an email from Amazon, http://www.bluproducts.com/security/ has instructions.

The lack of corporate BS on that page really surprised me:

BLU Products has identified and has quickly removed a recent security issue caused by a 3rd party application which had been collecting unauthorized personal data in the form of text messages, call logs, and contacts from customers using a limited number of BLU mobile devices. ... The affected application has since been self-updated and the functionality verified to be no longer collecting or sending this information.

Re: No One Cares About the Security of Unlocked Android Phones

#18

As always the SoC manufacturers are to blame. Google could probably fix these problems by writing yet another layer of software to abstract the hardware even further but the simple solution would be to fix these problems at the root.

> at the root

While in theory everything could be made to work fine and the right people would be held accountable and dropped from any use, probably this is where some form of vertical integration starts to really matter in practice.

Re: No One Cares About the Security of Unlocked Android Phones

#19
post #2

Which is exactly why we need to fix this problem. Consumer products don't have good security at all and it's making the world a worse place

It's more complicated than that. If Google just produced a standard version of Android with a standard kernel version that all vendors would write for, refreshing and wiping phones would be as easy as Windows/Linux laptops. I wrote a post on this a while back: http://penguindreams.org/blog/android-fragmentation/ Since then, I've become more and more frustrated with other ARM boards. Android fragmentation is directly…

> If Google just produced a standard version of Android with a standard kernel version that all vendors would write for

Then you wouldn't get all location data, call logs, and application usage data sent to China, you'd get them sent to the US, via Google, for better user experience and more targeted ads.

The result would be literally the same.

Re: No One Cares About the Security of Unlocked Android Phones

#20

Oh, great. My BLU R1 HD from Amazon is sitting next to me as I type this. Anyone know if this is patched in the latest software update, or how I can tell if I'm affected? I don't see anything "AdUps" in the applications or services list. edit: Per an email from Amazon, http://www.bluproducts.com/security/ has instructions.

Well their website doesn't even have SSL so that hardly fills me with confidence in their security.
Post reply on HN