This requires user action, right? User needs to install the APK by hand? In other words - if I don't install any crap on my phone I am safe?
Both mentioned CVEs seem to be about local privilege escalation. So basically yes, if you don't install crap apps, there's a high chance that you are protected. Problem is that it might not seem to be a crap app, but a nice-looking game, etc. Also an attack can come in with an update of any app you have already installed on your phone.
Google confirms Android attacks; no fix for most Samsung users
121–130 of 177 posts
Re: Google confirms Android attacks; no fix for most Samsung users
#122Every single Samsung product I've had to use is actively user hostile. Like a petty kind of hostile.
Re: Google confirms Android attacks; no fix for most Samsung users
#123Re: Google confirms Android attacks; no fix for most Samsung users
#124Earlier quoted context omitted.
Just because one layer of the security stack is compromised doesn't turn your device into a paperweight. I know many people who use out-of-support and vulnerable devices and I am not aware of a single one getting pwned by a system exploit, it is always some kind of phishing or scam. This is anecdotal evidence but I couldn't find actual data, as most don't distinguish between malware that rely on system-level vulnerab…
"I've never had someone steal from my car, so the fact that my car lock doesn't work is not a problem."
Sure, a thief may pick your lock, but unless he knows there is something valuable in there, he will probably go find a car the owner forgot to lock, it less effort and there are plenty of them, or he may look for more valuable targets.
Re: Google confirms Android attacks; no fix for most Samsung users
#125Earlier quoted context omitted.
> But "chs" is just nonsensical. The idea that it would sound like "sh" is baffling In the word "french" C H is pronounced sh and nobody bats an eye, I don't think it's that outlandish that someone once read it as fuch-sia, incorrectly splitting it compared to the original. In the language French, fuchsia is unequivocally read something more like few-shia, and I'd bet that even though it comes from German Fuchs-ia (f…
> In the word "french" C H is pronounced sh No, it's not. Unless you think the "n" in french is pronounced "nt".
Scaramouch and crochet though.
Re: Google confirms Android attacks; no fix for most Samsung users
#126Never mind the December security patches, Samsung haven't even released the November patches yet, the ones for the critical severity RCE. Unless you have a "major flagship model" [1], because apparently only the richest users deserve to be secure. [1] https://security.samsungmobile.com/securityUpdate.smsb
Why would you want security, if you get 'play integrity' for phones that received no updates since 2 years. Google's current security practices are more than dubious IMHO. Now they are not releasing any source for security patches for 3 month, to 'protect' vendors that are too slow updating. As if there is no chance for bad actors to reverse engineer those patch sets.
Re: Google confirms Android attacks; no fix for most Samsung users
#127Earlier quoted context omitted.
Both mentioned CVEs seem to be about local privilege escalation. So basically yes, if you don't install crap apps, there's a high chance that you are protected. Problem is that it might not seem to be a crap app, but a nice-looking game, etc. Also an attack can come in with an update of any app you have already installed on your phone.
The point was surely more that apps being exploited via the Play Store can be mitigated there without client OS updates. The only hole here requiring the update needs a sideloaded attack.
Re: Google confirms Android attacks; no fix for most Samsung users
#128Earlier quoted context omitted.
Again, no sympathy as that’s the route they chose. Rely on Google for everything OS and make a phone whereas Apple made a phone and supplied an OS. Apple made a product. Google made a software revenue stream. Entirely different things and now the Android makers are crying foul that they too have to do product engineering support. Nah. This is what you get when you rely on out of house innovation. I hope they all clos…
Yeah, and I also hope that all the PC makers close up shop as well. They rely on Microsoft for everything OS. Listen, you can just enjoy your iPhone in peace. Let other people make things, even if you feel they don't meet your standards.
Even just looking past the bugs that almost certainly exist in the firmware, it makes these devices extremely difficult to update. Whereas on desktop, I get kernel patches expeditiously. Many Android devices are still running kernel 5, and of the ones running recent kernels, we're still waiting months for system patches.
If everyone just upstreamed their shit, then we would live in a Utopia.
Re: Google confirms Android attacks; no fix for most Samsung users
#129Earlier quoted context omitted.
Why would you want security, if you get 'play integrity' for phones that received no updates since 2 years. Google's current security practices are more than dubious IMHO. Now they are not releasing any source for security patches for 3 month, to 'protect' vendors that are too slow updating. As if there is no chance for bad actors to reverse engineer those patch sets.
Play Integrity is just spyware - it does not provide any degree of security.
Re: Google confirms Android attacks; no fix for most Samsung users
#130Earlier quoted context omitted.
The point was surely more that apps being exploited via the Play Store can be mitigated there without client OS updates. The only hole here requiring the update needs a sideloaded attack.
Except the Play Store is a hot mess, and Google does little to no review of apps. Trusted repositories work best when the repository maintainers build and read the code themselves, like on f-droid or Debian. What Google and Apple are doing with their respective stores is security theater. I would not be surprised if they don't even run the app.
And it seems like it doesn't. If there is a live exploit in the wild (as seems to be contended), then clearly the solution is to blacklist the app (if it exists on the store, which is not attested) and pull it off the store. And that will work regardless of whether or not Samsung got an update out. Nor does it require an "audit" process in the store, the security people get to short circuit that stuff.