Live data from Hacker News

Google confirms Android attacks; no fix for most Samsung users

forbes.com

141–150 of 177 posts

Re: Google confirms Android attacks; no fix for most Samsung users

#141

Earlier quoted context omitted.

Google Pixel 7 and Pixel 7 Pro are still stuck on the October patches.

The December updates for Pixel 7 and Pixel 7 Pro are available to manually download on Google's website [0], so the updates do exist, although Google might not be rolling them out to the general public quite yet. But the December update for Pixel 7a are completely missing from that website, and trying to update from the Settings app also shows no updates available. [0]: https://developers.google.com/android/ota

Is there a way to apply one of these manually (without getting into dev tools and wiping & flashing with the new image)?

Re: Google confirms Android attacks; no fix for most Samsung users

#142

Earlier quoted context omitted.

The December updates for Pixel 7 and Pixel 7 Pro are available to manually download on Google's website [0], so the updates do exist, although Google might not be rolling them out to the general public quite yet. But the December update for Pixel 7a are completely missing from that website, and trying to update from the Settings app also shows no updates available. [0]: https://developers.google.com/android/ota

Is there a way to apply one of these manually (without getting into dev tools and wiping & flashing with the new image)?

There are instructions at the top of the link. You need to use "adb" from the command-line on a computer, but it won't wipe any of your data, so it shouldn't cause any data loss. If you don't want to use "adb", you might be able to use [0], but I haven't tested it myself.

[0]: https://flash.android.com/welcome

Re: Google confirms Android attacks; no fix for most Samsung users

#144

Earlier quoted context omitted.

No. Which is why "the only exception is macOS" is also false. At some point Apple drops support for that model and then that hardware not only gets no more driver updates, because the whole system is tied to the rest of it, it gets no more updates at all. So the only exception is systems with open source drivers. Those are basically supported as long as the hardware architecture is and enthusiasts even have the optio…

My point is that with macOS, Apple writes the drivers which means at least as long as the hardware is supported you can be pretty sure that there will be prompt fixes for any issue. With Android, Windows or closed-source Linux drivers (cough NVIDIA) you're left entirely at the mercy of whoever made the tiny little component controlled by the driver to provide a fix, which then has to bubble up through the ODM/OEM unt…

I can't see how the situation with apple is any better considering what you've said, you're still beholden to apple to provide a fix. Even if that fix might be quicker coming IF apple is currently supporting the device; not at all otherwise.

Re: Google confirms Android attacks; no fix for most Samsung users

#145
post #102

Earlier quoted context omitted.

Whilst the play store supposedly scans all apps for malicious behaviour, it's pretty easy to detect the test environment they use for testing and make malicious behaviour only trigger in situations Google doesn't test - eg. 5 days after installation, only if the device IP address changes at least once.

I'd imagine the dalvik part to be pretty open to static analysis? On the desktop JVM, I've seen bytecode that decompiled to a form more readable than the original source I got access to later...

Yes, but the JVM allows so much use of reflection that it's easy to hide an interpreter and then hide everything else from any static analysis.

Re: Google confirms Android attacks; no fix for most Samsung users

#146

Earlier quoted context omitted.

As Randall Munroe pointed out in https://blog.xkcd.com/2010/05/03/color-survey-results/ , almost nobody knows how to spell "fuchsia" correctly. I only remember it by the mnemonic of it's fuck, but with an s.

It’s helps if you know that the flower the fuchsia, was discovered by Dr Fuchs

Named after, apparently. https://en.wikipedia.org/wiki/Fuchsia#Taxonomy

> The first to be scientifically described, Fuchsia triphylla, was discovered on the Caribbean island of Hispaniola (Haiti and the Dominican Republic) about 1696–1697 by the French Minim friar and botanist, Charles Plumier, during his third expedition to the Greater Antilles. He named the new genus after German botanist Leonhart Fuchs

See also https://en.wikipedia.org/wiki/Fuchsia_triphylla .

Re: Google confirms Android attacks; no fix for most Samsung users

#147
post #68

Never mind the December security patches, Samsung haven't even released the November patches yet, the ones for the critical severity RCE. Unless you have a "major flagship model" [1], because apparently only the richest users deserve to be secure. [1] https://security.samsungmobile.com/securityUpdate.smsb

> Samsung haven't even released the November patches yet.

My fold 6 has the November "security patch level" or what does that refer to?

Re: Google confirms Android attacks; no fix for most Samsung users

#148
post #129

Earlier quoted context omitted.

Play Integrity is just spyware - it does not provide any degree of security.

Sorry for my irony. While I do not think it is spyware on itself, it sure is a way to force vendors to bundle spyware.

Elaborate please. PI on its own is just an insurance API for banking and similar apps to ensure that they can do secure compute on the device. It can also be used to check if the device that the app is running on is a genuine Android device, since no VMs or custom ROMs can pass hardware integrity.

Re: Google confirms Android attacks; no fix for most Samsung users

#150
post #117

I don't understand why Samsung, with all their money, does not make their own fork so it does not have to rely on Google. I guess that is how they get all their money though. I was inches away from buying a 25+ this week. Glad I did not. But I mean, why do we only have two choices of OS for phones (I did not include GrapheneOS because it not easily available for the normie)? That is what is ridiculous. And why, in th…

They do have their own fork, they just don't have any of the security infra that google does. So they "rely" on Google for that.
Post reply on HN