Live data from Hacker News

Google confirms Android attacks; no fix for most Samsung users

forbes.com

111–120 of 177 posts

Re: Google confirms Android attacks; no fix for most Samsung users

#111

Earlier quoted context omitted.

The beginning of the English word "fuchsia" is not pronounced like the German word Fuchs, so indeed the spelling does not match the pronunciation. This is independent of the fact that it comes from that word. Plenty of things in English (and, in fact, loanwords in every language) sound different from the words they're derived from; that doesn't mean trying to imitate the source language is the "right" pronunciation.…

> If you pronounce fuchsia like "fuksia" nobody will understand you. TIL and yet another case of "English is fucking weird".

Fuching weird, even.

Re: Google confirms Android attacks; no fix for most Samsung users

#112
post #68

Never mind the December security patches, Samsung haven't even released the November patches yet, the ones for the critical severity RCE. Unless you have a "major flagship model" [1], because apparently only the richest users deserve to be secure. [1] https://security.samsungmobile.com/securityUpdate.smsb

Google Pixel 7 and Pixel 7 Pro are still stuck on the October patches.

You might be on a slow rollout group, I got the December patch on my Pixel 7.

Re: Google confirms Android attacks; no fix for most Samsung users

#113
post #100

Earlier quoted context omitted.

We have an OS security update that is only release to users of a specific hardware, once approved by their mobile operator. It may be added to vendor-specific OS versions some time later (weeks, month or never). The vendor-specific may not be approved by a telco if the vendor doesn't have a relationship with that telco. Now think that millions of people use the same OS on many different flavours, on different hardwar…

I never understood why a mobile operator has any say in when to apply security patches? Does it happen with iPhones?

iOS updates are not limited by the operator.

Re: Google confirms Android attacks; no fix for most Samsung users

#114
post #73

Earlier quoted context omitted.

> But "chs" is just nonsensical. The idea that it would sound like "sh" is baffling In the word "french" C H is pronounced sh and nobody bats an eye, I don't think it's that outlandish that someone once read it as fuch-sia, incorrectly splitting it compared to the original. In the language French, fuchsia is unequivocally read something more like few-shia, and I'd bet that even though it comes from German Fuchs-ia (f…

> In the word "french" C H is pronounced sh No, it's not. Unless you think the "n" in french is pronounced "nt".

[deleted]

Re: Google confirms Android attacks; no fix for most Samsung users

#115
post #108

Earlier quoted context omitted.

> Being reliant on the hardware manufacturer (or network operator?) for OS updates is the crazy world we live in. Being reliant on a single OS permanently nailed to the hardware is no less crazier. I'd like to be able to install another OS on a vulnerable device, it would help tremendously and not only with the security of that specific device. Now I've got some expensive paperweights that I can't even use as such be…

Just because one layer of the security stack is compromised doesn't turn your device into a paperweight. I know many people who use out-of-support and vulnerable devices and I am not aware of a single one getting pwned by a system exploit, it is always some kind of phishing or scam. This is anecdotal evidence but I couldn't find actual data, as most don't distinguish between malware that rely on system-level vulnerab…

It's not 1999 anymore. If you get RCEd today as a nobody you don't get a purple gorilla.

Just silently enlisted into a "Residential VPN" and a background script that checks for the SSID "Iranian Research Facility" every time you turn your wifi on for some reason.

Re: Google confirms Android attacks; no fix for most Samsung users

#117
I don't understand why Samsung, with all their money, does not make their own fork so it does not have to rely on Google. I guess that is how they get all their money though. I was inches away from buying a 25+ this week. Glad I did not.

But I mean, why do we only have two choices of OS for phones (I did not include GrapheneOS because it not easily available for the normie)? That is what is ridiculous. And why, in the US, do I only get three choices of flagship phones when in Asia they have like twenty? I hate this third world country I am living in.

Re: Google confirms Android attacks; no fix for most Samsung users

#118
post #73

Earlier quoted context omitted.

I vote to just change the spelling to what almost everyone already thinks it is anyways. It'll still be just as weird. But "chs" is just nonsensical . The idea that it would sound like "sh" is baffling. I mean, I know this is English spelling which is not known for its regularity, but this is just too much.

> But "chs" is just nonsensical. The idea that it would sound like "sh" is baffling In the word "french" C H is pronounced sh and nobody bats an eye, I don't think it's that outlandish that someone once read it as fuch-sia, incorrectly splitting it compared to the original. In the language French, fuchsia is unequivocally read something more like few-shia, and I'd bet that even though it comes from German Fuchs-ia (f…

> In the word "french" C H is pronounced sh

It's not, though.

Re: Google confirms Android attacks; no fix for most Samsung users

#119
post #98
post #68

Never mind the December security patches, Samsung haven't even released the November patches yet, the ones for the critical severity RCE. Unless you have a "major flagship model" [1], because apparently only the richest users deserve to be secure. [1] https://security.samsungmobile.com/securityUpdate.smsb

Why would you want security, if you get 'play integrity' for phones that received no updates since 2 years. Google's current security practices are more than dubious IMHO. Now they are not releasing any source for security patches for 3 month, to 'protect' vendors that are too slow updating. As if there is no chance for bad actors to reverse engineer those patch sets.

I have the strongest level of "Play Integrity" on a Xiaomi phone that hasn't received any updates since the beginning of 2020. Google Pay and co work fine. It makes sense when you remember that PI is not about security at all, that's just an excuse.

Re: Google confirms Android attacks; no fix for most Samsung users

#120
post #108

Earlier quoted context omitted.

> Being reliant on the hardware manufacturer (or network operator?) for OS updates is the crazy world we live in. Being reliant on a single OS permanently nailed to the hardware is no less crazier. I'd like to be able to install another OS on a vulnerable device, it would help tremendously and not only with the security of that specific device. Now I've got some expensive paperweights that I can't even use as such be…

Just because one layer of the security stack is compromised doesn't turn your device into a paperweight. I know many people who use out-of-support and vulnerable devices and I am not aware of a single one getting pwned by a system exploit, it is always some kind of phishing or scam. This is anecdotal evidence but I couldn't find actual data, as most don't distinguish between malware that rely on system-level vulnerab…

"I've never had someone steal from my car, so the fact that my car lock doesn't work is not a problem."
Post reply on HN