I can't believe that somebody who is intelligent enough to write this application would miss such an obvious flaw. I literally can not conceive how it wouldn't have crossed their mind that any local app with network permissions would be able to connect to it. Were they just being lazy? Or were they forced to do it this way by some ignorant manager? I would love to hear how this happened.
Massive data stealing vulnerability found in many HTC Android phones
11–20 of 48 posts
Re: Massive data stealing vulnerability found in many HTC Android phones
#12This is an awesome reason to root your phone the second you get it. I've done so to both of my Android phones. You know that cyanogenmod is safe from this kind of blatant wiretapping, and on top of that, you don't have to worry about hassling with it when you need to tether, or when you want to install an application that requires root permissions to function well. :)
Re: Massive data stealing vulnerability found in many HTC Android phones
#13I can't believe that somebody who is intelligent enough to write this application would miss such an obvious flaw. I literally can not conceive how it wouldn't have crossed their mind that any local app with network permissions would be able to connect to it. Were they just being lazy? Or were they forced to do it this way by some ignorant manager? I would love to hear how this happened.
It's likely debugging utils that were missed when readying for release.
Re: Massive data stealing vulnerability found in many HTC Android phones
#14I'm going to guess either very few or none, as most people won't notice/care about this issue, and HTC isn't making any money off supplying updates.
Imagine if Microsoft forced Dell, HP, etc. to handle software security and updates on Windows for PC's they've already sold - it would either never happen or not happen correctly. Swap the players and that's where Android is today.
(yes, I know about alternate firmware - how many non-geeks are capable of using it and have devices that don't have technological blocks like signed bootloaders to prevent it?)
Re: Massive data stealing vulnerability found in many HTC Android phones
#15How many of these phones are going to get a patch or updated firmware to fix this problem? I'm going to guess either very few or none, as most people won't notice/care about this issue, and HTC isn't making any money off supplying updates. Imagine if Microsoft forced Dell, HP, etc. to handle software security and updates on Windows for PC's they've already sold - it would either never happen or not happen correctly.…
"Imagine if Dell, HP, etc forced Microsoft to let them handle software security and updates on Windows for PCs they've already sold..."
Re: Massive data stealing vulnerability found in many HTC Android phones
#16How many of these phones are going to get a patch or updated firmware to fix this problem? I'm going to guess either very few or none, as most people won't notice/care about this issue, and HTC isn't making any money off supplying updates. Imagine if Microsoft forced Dell, HP, etc. to handle software security and updates on Windows for PC's they've already sold - it would either never happen or not happen correctly.…
Given that it took it took HTC this long to get an update to an Android version that's been available in source since December and they still managed to mess it up, I don't have high hopes for something like this getting fixed.
Re: Massive data stealing vulnerability found in many HTC Android phones
#17How many of these phones are going to get a patch or updated firmware to fix this problem? I'm going to guess either very few or none, as most people won't notice/care about this issue, and HTC isn't making any money off supplying updates. Imagine if Microsoft forced Dell, HP, etc. to handle software security and updates on Windows for PC's they've already sold - it would either never happen or not happen correctly.…
Can we word that differently? "Imagine if Dell, HP, etc forced Microsoft to let them handle software security and updates on Windows for PCs they've already sold..."
Google would get nothing but more work and responsibility out of such an arrangement.
Yes, it would be better for security and end users, but who cares about them? Google is in it for the ad revenue, and the HW vendors are in it to sell units, not have old models with new software compete against their new hardware.
Re: Massive data stealing vulnerability found in many HTC Android phones
#18How many of these phones are going to get a patch or updated firmware to fix this problem? I'm going to guess either very few or none, as most people won't notice/care about this issue, and HTC isn't making any money off supplying updates. Imagine if Microsoft forced Dell, HP, etc. to handle software security and updates on Windows for PC's they've already sold - it would either never happen or not happen correctly.…
One of the affected models, the Thunderbolt, only now started getting updates to Gingerbread this week. That is, until Verizon halted it due to a major usability bug that should have been identified easily in carrier testing (voicemail notifications don't work). Given that it took it took HTC this long to get an update to an Android version that's been available in source since December and they still managed to mess…
Re: Massive data stealing vulnerability found in many HTC Android phones
#19Android is not having a good time with security this week. The Samsung Galaxy S II on AT&T is very easy to unlock without the PIN or password. http://www.bgr.com/2011/09/30/major-security-flaw-lets-anyon...
Re: Massive data stealing vulnerability found in many HTC Android phones
#20Earlier quoted context omitted.
One of the affected models, the Thunderbolt, only now started getting updates to Gingerbread this week. That is, until Verizon halted it due to a major usability bug that should have been identified easily in carrier testing (voicemail notifications don't work). Given that it took it took HTC this long to get an update to an Android version that's been available in source since December and they still managed to mess…
Surely the blame there is on Verizon. My aging, carrier-free HTC Nexus One gets regular updates.
For non-geeks the first option is the only viable one, IMHO.
You've obviously settled on the same conclusion.