Live data from Hacker News

Malicious apps infect 25M Android devices with 'Agent Smith' malware

phys.org

131–140 of 222 posts

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#131

Earlier quoted context omitted.

> That’s because they cared about the end user experience. I'm sure 100% of any revenue going to Apple and not shared with anyone had nothing to do with that.

It may have, but I doubt it was the primary motivation. Steve Jobs famously cared a lot about user experience, security and reliability. Remember that Apple under his leadership took a firm stance and loudly and publicly refused to allow Flash on its devices, despite the fact that many websites back then relied on Flash.

Apple also planned to sandbox all apps. But developers wanted bare metal performance.

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#132

Earlier quoted context omitted.

Apple pushed the carriers to allow it to update its own operating systems over a decade ago.

Apple's situation is completely different from Android. Demand for iphone devices was the leverage Apple had over carriers to do this, and it's not a fragmented ecosystem in the first place.

Apple created that demand. They were exclusively on AT&T at first, and aggressively negotiated that contract so they wouldn't have to have carriers' horrible bloatware. Then the exclusivity made negotiating with other carriers easier.

Google didn't even make any phones until much later. Instead they gave phone manufacturers the green light to do whatever they wanted. They ended up designing phones later because of how crappy the Android phone ecosystem had become. Google could have made Nexuses from the get-go.

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#133
post #33

"Check Point is not identifying the company, because they are working with local law enforcement." Well that's dumb. "It appears that you are currently using Ad Blocking software. What are the consequences?" The consequences include avoiding situations just like in the story. When did Phys Org get into tech news? I thought they were just an unreliable source for science rumors.

Perhaps you would like to share your feedback with them https://sciencex.com/help/feedback/

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#134

Earlier quoted context omitted.

Good question. When a phone stops working, people want their money back. Guess where most people in most markets buy their phone from? Further, who do you think customer's call for support? Now you know why carriers are hesitant about frequently updating a product they've already made a sale on. If an update breaks something, guess who pays the price? Not defending them, and it's not the only reason, but it's a big o…

Which is why I prefer to buy my phone independently from the carrier service.

The parent is pointing out one possible motive for a large carrier, who has to deal with what I call the "general public".

> Which is why I prefer to buy my phone independently from the carrier service.

You're clearly a tech literate person, which is great! But I've worked at a phone/computer repair/resell store for 2 years, and let me tell you, the "general public" can be very interesting.

It's common for many people to not know that their "phone runs android". Let alone the which version LOL!

What I'm trying to say is, it's great that you buy your phone that way, and that's the smart way to do it. We've had plenty of customers looking for unlocked phones too, but even then many don't understand how there's different radios in the phones that work with different carriers, some didn't actually know what being "unlocked" means, etc.

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#135

Earlier quoted context omitted.

> purposely throttling So that the phones don't randomly shut off because their lithium ion batteries were old. Yes, they should have told people but it wasn't done maliciously.

That's easy... make the batteries easily replaceable... oh wait.

That would makes the phones considerably thicker and/or make the battery life significantly worse. I don't think replaceable batteries are really worth the tradeoffs given the constraints of a modern smartphone.

Lithium batteries can be quite dangerous, so they need to be in a case to prevent damage that could cause them to catch fire. Then, the phone itself needs a battery door which adds even more thickness and potential failure points.

Finally, once you have replaceable batteries, you give up water and dust resistance. I would bet that more phones have died of water or dust ingress than phones with dead batteries.

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#136

Earlier quoted context omitted.

> purposely throttling So that the phones don't randomly shut off because their lithium ion batteries were old. Yes, they should have told people but it wasn't done maliciously.

>but it wasn't done maliciously. You are certainly entitled to your opinion.

Would you rather your phone suddenly die rather than just run slower? Phones are critical safety devices nowadays.

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#137

Earlier quoted context omitted.

You can replace the battery by going to an apple store, giving them $49, and then picking it up a few hours later. That's not a terrific challenge.

What if you don't live near an apple store? Why not let the user manage their own battery, that is also not a terrific challenge.

You can ship your phone to Apple and be without it for about a week. Or, take it to a 3rd party repair shop.

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#138

Earlier quoted context omitted.

I've never understood this as a design decision -- why does Google allow companies to block updating of Android? Presumably the idea is 'block updates to force hardware sales'? I can't update my Honor, I think it's the service provider (the phone was on contract) who block the update, but it was easy to update (both Android and EMUI) using an app in the Google Play store to a full version higher, but whoever created…

It hasn't made any sense to buy phones from the company that provides your mobile phone service for years, especially now that a "phone" isn't in any meaningful sense a phone at all with many people never making or receiving any calls. They shouldn't be any more involved in what phone you use than your ISP gets to pick whether you use a Mac or PC. Sure if you want to use a 15 year old phone you're going to need to fi…

Crunching the numbers, it was much much cheaper for me getting this phone on contract then any other route. I did look at buying a phone separately and having SIM-only or PAYGo. (UK, about 3 years ago, low-mid range). With 18 month contract I basically got a 'free' phone with 13MP camera.

I actually use a SIM only by swapping sims with my wife whose phone we bought outright (but it's low end - camera and screen are poor).

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#139
post #77

Earlier quoted context omitted.

This seems to be getting a lot of attention, so as an Android Engineer with some security and framework experience let me try to explain. This is a side effect of Android's initial approach to it's open nature. Android allows a manufacturer to modify its framework for their own use case. Then the manufacturer can allow a specific carrier to input their own system applications and firmware on to the devices well (your…

Sounds like an excuse for poor engineering on the part of Android. Microsoft also sells Windows to multiple OEMs and has done so for decades. OEMs also are free to add bloatware as well as the retailers (ie Best Buy adds its own bloat), but Microsoft doesn’t have this problem.

Yeah but Windows was created for existing hardware, in fact at first even running on an existing OS. IBM PC compatibles were a thing since the 80s on which DOS flavour from various vendor were running which in turn ran on x86.

Microsoft actually waited really long until they combined normal end user Windows with NT which was it's own OS since early 90s but also had a lot of restrictions when it came to drivers, end user Apps, Games in particular.

Google bootstrapped it all at once, that's quite an effort. That said, some phones like those of OnePlus or FairPhone have really long support times.

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#140
post #91

Earlier quoted context omitted.

Sounds like an excuse for poor engineering on the part of Android. Microsoft also sells Windows to multiple OEMs and has done so for decades. OEMs also are free to add bloatware as well as the retailers (ie Best Buy adds its own bloat), but Microsoft doesn’t have this problem.

probably cost you more money than you'd make writing malware for windows phones

no one is talking about windows phones. they're talking about windows.
Post reply on HN