Live data from Hacker News

Google confirms Android attacks; no fix for most Samsung users

forbes.com

121–130 of 177 posts

Re: Google confirms Android attacks; no fix for most Samsung users

#121
post #55

This requires user action, right? User needs to install the APK by hand? In other words - if I don't install any crap on my phone I am safe?

Both mentioned CVEs seem to be about local privilege escalation. So basically yes, if you don't install crap apps, there's a high chance that you are protected. Problem is that it might not seem to be a crap app, but a nice-looking game, etc. Also an attack can come in with an update of any app you have already installed on your phone.

Threat model is probably third party ad and tracking libraries that pay to get into apps. If I caught it, I'd expect it to be from an app to use a parking deck, a colorful desk lamp, an otoscope etc where the developers sold out years ago

Re: Google confirms Android attacks; no fix for most Samsung users

#123

Earlier quoted context omitted.

I'd suggest you to use GrapheneOS.

Is the patch already available for GrapheneOS?

According to above comments, it was added 3 days ago. I'm updating to the latest release now.

Re: Google confirms Android attacks; no fix for most Samsung users

#124
post #108

Earlier quoted context omitted.

Just because one layer of the security stack is compromised doesn't turn your device into a paperweight. I know many people who use out-of-support and vulnerable devices and I am not aware of a single one getting pwned by a system exploit, it is always some kind of phishing or scam. This is anecdotal evidence but I couldn't find actual data, as most don't distinguish between malware that rely on system-level vulnerab…

"I've never had someone steal from my car, so the fact that my car lock doesn't work is not a problem."

More like: "Every time someone stole from my car, that's because I forgot to lock the door, that the lock can be picked is not a problem".

Sure, a thief may pick your lock, but unless he knows there is something valuable in there, he will probably go find a car the owner forgot to lock, it less effort and there are plenty of them, or he may look for more valuable targets.

Re: Google confirms Android attacks; no fix for most Samsung users

#125
post #73

Earlier quoted context omitted.

> But "chs" is just nonsensical. The idea that it would sound like "sh" is baffling In the word "french" C H is pronounced sh and nobody bats an eye, I don't think it's that outlandish that someone once read it as fuch-sia, incorrectly splitting it compared to the original. In the language French, fuchsia is unequivocally read something more like few-shia, and I'd bet that even though it comes from German Fuchs-ia (f…

> In the word "french" C H is pronounced sh No, it's not. Unless you think the "n" in french is pronounced "nt".

Fine, and legit. I get what I deserve for not looking it up!

Scaramouch and crochet though.

Re: Google confirms Android attacks; no fix for most Samsung users

#126
post #98
post #68

Never mind the December security patches, Samsung haven't even released the November patches yet, the ones for the critical severity RCE. Unless you have a "major flagship model" [1], because apparently only the richest users deserve to be secure. [1] https://security.samsungmobile.com/securityUpdate.smsb

Why would you want security, if you get 'play integrity' for phones that received no updates since 2 years. Google's current security practices are more than dubious IMHO. Now they are not releasing any source for security patches for 3 month, to 'protect' vendors that are too slow updating. As if there is no chance for bad actors to reverse engineer those patch sets.

Play Integrity is just spyware - it does not provide any degree of security.

Re: Google confirms Android attacks; no fix for most Samsung users

#127
post #70
post #55

Earlier quoted context omitted.

Both mentioned CVEs seem to be about local privilege escalation. So basically yes, if you don't install crap apps, there's a high chance that you are protected. Problem is that it might not seem to be a crap app, but a nice-looking game, etc. Also an attack can come in with an update of any app you have already installed on your phone.

The point was surely more that apps being exploited via the Play Store can be mitigated there without client OS updates. The only hole here requiring the update needs a sideloaded attack.

Except the Play Store is a hot mess, and Google does little to no review of apps. Trusted repositories work best when the repository maintainers build and read the code themselves, like on f-droid or Debian. What Google and Apple are doing with their respective stores is security theater. I would not be surprised if they don't even run the app.

Re: Google confirms Android attacks; no fix for most Samsung users

#128

Earlier quoted context omitted.

Again, no sympathy as that’s the route they chose. Rely on Google for everything OS and make a phone whereas Apple made a phone and supplied an OS. Apple made a product. Google made a software revenue stream. Entirely different things and now the Android makers are crying foul that they too have to do product engineering support. Nah. This is what you get when you rely on out of house innovation. I hope they all clos…

Yeah, and I also hope that all the PC makers close up shop as well. They rely on Microsoft for everything OS. Listen, you can just enjoy your iPhone in peace. Let other people make things, even if you feel they don't meet your standards.

No, I use Android and the security nightmare on Android is absolutely unacceptable. There is zero reason phones should rely on as many proprietary bullshit blobs as they do, and that's the root cause of this.

Even just looking past the bugs that almost certainly exist in the firmware, it makes these devices extremely difficult to update. Whereas on desktop, I get kernel patches expeditiously. Many Android devices are still running kernel 5, and of the ones running recent kernels, we're still waiting months for system patches.

If everyone just upstreamed their shit, then we would live in a Utopia.

Re: Google confirms Android attacks; no fix for most Samsung users

#129
post #98

Earlier quoted context omitted.

Why would you want security, if you get 'play integrity' for phones that received no updates since 2 years. Google's current security practices are more than dubious IMHO. Now they are not releasing any source for security patches for 3 month, to 'protect' vendors that are too slow updating. As if there is no chance for bad actors to reverse engineer those patch sets.

Play Integrity is just spyware - it does not provide any degree of security.

Sorry for my irony. While I do not think it is spyware on itself, it sure is a way to force vendors to bundle spyware.

Re: Google confirms Android attacks; no fix for most Samsung users

#130
post #70

Earlier quoted context omitted.

The point was surely more that apps being exploited via the Play Store can be mitigated there without client OS updates. The only hole here requiring the update needs a sideloaded attack.

Except the Play Store is a hot mess, and Google does little to no review of apps. Trusted repositories work best when the repository maintainers build and read the code themselves, like on f-droid or Debian. What Google and Apple are doing with their respective stores is security theater. I would not be surprised if they don't even run the app.

Again though, that's mixing things up. The question is whether or not mitigating the exploit requires an OS patch be applied promptly.

And it seems like it doesn't. If there is a live exploit in the wild (as seems to be contended), then clearly the solution is to blacklist the app (if it exists on the store, which is not attested) and pull it off the store. And that will work regardless of whether or not Samsung got an update out. Nor does it require an "audit" process in the store, the security people get to short circuit that stuff.

Post reply on HN