Live data from Hacker News

More Than 1M Google Accounts Breached by Gooligan

blog.checkpoint.com

121–130 of 183 posts

Re: More Than 1M Google Accounts Breached by Gooligan

#121
post #84
post #29

Earlier quoted context omitted.

Thanks for making this comment. This post is a wonderful example of the rampant marketing that has given the security industry a bad name. - The title is technically accurate, which is the best kind of accurate for clickbait. This is not a novel vulnerability representative of an application security flaw within Google - the malware campaign specifically targets older devices using previously known vulnerabilities.[1…

That's not to say Google has no responsibility in this. Google's OS has a terrible security-update policy. Being able to buy a new computing device from a store that will receive no security updates is terrible, and is fairly common in Android devices. Now, there are valid technical reasons that Google can't be as good as Microsoft at pushing out updates to every device running their OS, but still, it's hard to say t…

Right now, Google has no credible open competitor to Android, and not for lack of trying. If Android wants to be the Windows to iPhone's Mac, it will have to get serious about security, or be swept away by the competitors which will inevitably emerge.

I also want to say that voting machines run unsupported Android builds. If Google is derelict in that duty... well, that's a much bigger deal than some compromised Google accounts.

Re: More Than 1M Google Accounts Breached by Gooligan

#122
post #99
post #84

Earlier quoted context omitted.

That's not to say Google has no responsibility in this. Google's OS has a terrible security-update policy. Being able to buy a new computing device from a store that will receive no security updates is terrible, and is fairly common in Android devices. Now, there are valid technical reasons that Google can't be as good as Microsoft at pushing out updates to every device running their OS, but still, it's hard to say t…

Google in most cases is not the device's manufacturer, and in a mobile device OS and application SW are tightly coupled, so you cannot really have OS updates separate from firmware updates, bypassing the actual manufacturer's own updates. Google (and Apple and Microsoft) can totally do it for devices that manufactures and maintains on its own, and actually it is one of the selling points of their new phone. In additi…

> and in a mobile device OS and application SW are tightly coupled

I call bullshit. There's no reason Google can't update everything AOSP-y in /system - libc, libart, libwebkit etc.

> Google (and Apple and Microsoft) can totally do it for devices that manufactures and maintains on its own

That's a low bar. When you buy a Dell laptop, you continue to receive updates from Microsoft. This is the bar we should hold Google to.

As for the certification process, surely having one update that ships to N models is easier to test than N updates shipping to N models?

Re: More Than 1M Google Accounts Breached by Gooligan

#123
post #114
post #84

Earlier quoted context omitted.

That's not to say Google has no responsibility in this. Google's OS has a terrible security-update policy. Being able to buy a new computing device from a store that will receive no security updates is terrible, and is fairly common in Android devices. Now, there are valid technical reasons that Google can't be as good as Microsoft at pushing out updates to every device running their OS, but still, it's hard to say t…

> Being able to buy a new computing device from a store that will receive no security updates is terrible, and is fairly common in Android devices. This seems like the kind of problem the free market could solve. Just get one phone vendor to guarantee secruity updates for a few years and then some customers will start buying those phones. After a while other vendors will start promising it or losing sales.

> This seems like the kind of problem the free market could solve.

It's the kind of problem solved by perfect market where all actors were rational, had access to complete information, and correctly prioritized their long term and short term needs.

Alas, the world we live in is seven billion highly distracted primates who interact by wiggling their smallest appendages on grids of buttons and pushing streams of air over a weird blob of muscle located inside an organ also used for food consumption.

Re: More Than 1M Google Accounts Breached by Gooligan

#124
post #121
post #84

Earlier quoted context omitted.

That's not to say Google has no responsibility in this. Google's OS has a terrible security-update policy. Being able to buy a new computing device from a store that will receive no security updates is terrible, and is fairly common in Android devices. Now, there are valid technical reasons that Google can't be as good as Microsoft at pushing out updates to every device running their OS, but still, it's hard to say t…

Right now, Google has no credible open competitor to Android, and not for lack of trying. If Android wants to be the Windows to iPhone's Mac, it will have to get serious about security, or be swept away by the competitors which will inevitably emerge. I also want to say that voting machines run unsupported Android builds. If Google is derelict in that duty... well, that's a much bigger deal than some compromised Goog…

I never heard that about voting machines. Do you have a source for that? I'm not sure why that's more surprising than hearing that they run Windows XP...

Re: More Than 1M Google Accounts Breached by Gooligan

#125
post #119
post #116

Earlier quoted context omitted.

What is the downside of someone having your email address, especially with no other context. If they have other data on your email address, they don't need your email address to do anything with it. If they don't have other data, then there's no issue. You're not concerned about people having public access to your twitter handle, why would you be concerned about people having public access to your email address.

Well, they at least know my email address and my interest for android phones. Am I only one thinking that It is so easy to sell the whole list to a Chinese manufacturer ?

They also probably have the http://news.ycombinator.com referrer, among other things.

Re: More Than 1M Google Accounts Breached by Gooligan

#126
post #114

Earlier quoted context omitted.

> Being able to buy a new computing device from a store that will receive no security updates is terrible, and is fairly common in Android devices. This seems like the kind of problem the free market could solve. Just get one phone vendor to guarantee secruity updates for a few years and then some customers will start buying those phones. After a while other vendors will start promising it or losing sales.

The underlying assumption is that a multitude of users would switch to devices produced by such a manufacturer. This, I think, overestimates how much most users currently care about security. As it turns out, there are more secure devices in the marketplace than the affected phones, but they cost more. All other things equal, a contractual obligation for security policies would increase the cost (and thus price) of d…

I don't think everyone needs to be perfectly rational, but news of a big hack like this combined with a marketing campaign could reasonably help.

Re: More Than 1M Google Accounts Breached by Gooligan

#127
post #116
post #112

Earlier quoted context omitted.

It is just a text. How do you know ?

What is the downside of someone having your email address, especially with no other context. If they have other data on your email address, they don't need your email address to do anything with it. If they don't have other data, then there's no issue. You're not concerned about people having public access to your twitter handle, why would you be concerned about people having public access to your email address.

A list of emails + IP addresses would be valuable to web surveillance companies that already have trails of data for the IP addresses and emails separately.

Re: More Than 1M Google Accounts Breached by Gooligan

#128

Malware on your Android device picked up from third party app stores (FDroid? Amazon?) that steals email accounts and auth tokens. Looks like it only works on the older Android 4 Jellybean software (and some Android 5 Lollipop) and below, so mostly concentrated in Asia where there are lower-end phones. You can see if your account has been affected here: https://gooligan.checkpoint.com/

Is there some way to check without actually submitting our email address?

Re: More Than 1M Google Accounts Breached by Gooligan

#130
post #60
post #40

We were just reading "Android security in 2016 is a mess"[1] 2 days ago and now we have another great example for it. https://news.ycombinator.com/item?id=13056288

"Windows is a mess because you can install a virus executable on it." "You can't install Windows software outside App Store anymore, MS is taking muh freedoms." You can't win.

[deleted]
Post reply on HN