Live data from Hacker News

Google confirms Android attacks; no fix for most Samsung users

forbes.com

151–160 of 177 posts

Re: Google confirms Android attacks; no fix for most Samsung users

#151

Why anybody would buy a Samsung product at this point I don't understand. Every single Samsung product I've had to use is actively user hostile. Like a petty kind of hostile.

I've been Samsung since S3, but recently picked up a cheap Motorola as a secondary. Been pretty satisfied with it, clearly not as fancy as the S23 I got, but decent enough. However they only get 2 years of Android updates, and I'm getting spammed by Motorola at least once a week of not more to install some silly game or whatnot.

I've also not been terribly impressed by the UX changes Samsung has made recently, lots of questionable decisions there.

What other decent options are out there?

Re: Google confirms Android attacks; no fix for most Samsung users

#152
post #111

Earlier quoted context omitted.

> If you pronounce fuchsia like "fuksia" nobody will understand you. TIL and yet another case of "English is fucking weird".

Fuching weird, even.

:) Yeah, probably in this case English is doing the right thing, pronunciation wise. Anyway, checking in Google Translate the pronunciation it plays "fuksia", while Wikipedia has the right version.

Re: Google confirms Android attacks; no fix for most Samsung users

#153

Why anybody would buy a Samsung product at this point I don't understand. Every single Samsung product I've had to use is actively user hostile. Like a petty kind of hostile.

They're cheap

If the flaws were just about missing premium features, that'd be one thing.

But it's not. It's petty and abusive. For example, you can't see (I think it was) heart rate if you have a Samsung smart watch, but don't have a Samsung phone. They've gone out of their way to just not provide that, if you instead have a Pixel phone. And you need like 5 gigantic apps installed to manage it. Why is it not just one single Samsung wear app? Because they are abusive.

Re: Google confirms Android attacks; no fix for most Samsung users

#154

Why anybody would buy a Samsung product at this point I don't understand. Every single Samsung product I've had to use is actively user hostile. Like a petty kind of hostile.

I've been Samsung since S3, but recently picked up a cheap Motorola as a secondary. Been pretty satisfied with it, clearly not as fancy as the S23 I got, but decent enough. However they only get 2 years of Android updates, and I'm getting spammed by Motorola at least once a week of not more to install some silly game or whatnot. I've also not been terribly impressed by the UX changes Samsung has made recently, lots o…

https://www.androidauthority.com/phone-update-policies-16586... has summary of phone manufacturers update policy. It looks like for now the answer is: if you don't want an IPhone then grab Pixel and install GrapheneOS on it.

So no decent options for out-of-box experience.

Re: Google confirms Android attacks; no fix for most Samsung users

#155
post #101

Earlier quoted context omitted.

Search CVE numbers. https://www.cve.org/CVERecord?id=CVE-2025-48633 Basically, just like most things these days, its all just local privilege escalation. This means that you have to install/run an app that has these exploits built in. Soif you usage profile doesn't include downloading apps from untrusted sources, you don't need to worry.

What if an existing app gets an update that exploits the vulnerability? For sure that's not going to happen to an app released by a major company, but there are lots of less known app created by many different developers.

Turn off app updates. If it's working now, why do you need to update it? Does the update add something specific you want?

Re: Google confirms Android attacks; no fix for most Samsung users

#156
post #129

Earlier quoted context omitted.

Sorry for my irony. While I do not think it is spyware on itself, it sure is a way to force vendors to bundle spyware.

Elaborate please. PI on its own is just an insurance API for banking and similar apps to ensure that they can do secure compute on the device. It can also be used to check if the device that the app is running on is a genuine Android device, since no VMs or custom ROMs can pass hardware integrity.

Well, only it isn't.

Very old, unpatched and rooted devices can fairly easily pass device integrity check.

It primarily assures the software vendor that the phone is running Google buttplug in the privileged mode.

Remember, handsets running on ANCIENT versions of Android with no patches for years. Whilst seems to be important to raise under the Forbes article (rightly) fussing about a couple of zero-days.

"Custom roms" (whatever that means) can easily spoof the checks in the specific situation (mainly hardware that allows for several things).

Re: Google confirms Android attacks; no fix for most Samsung users

#157
post #130

Earlier quoted context omitted.

Except the Play Store is a hot mess, and Google does little to no review of apps. Trusted repositories work best when the repository maintainers build and read the code themselves, like on f-droid or Debian. What Google and Apple are doing with their respective stores is security theater. I would not be surprised if they don't even run the app.

Again though, that's mixing things up. The question is whether or not mitigating the exploit requires an OS patch be applied promptly . And it seems like it doesn't. If there is a live exploit in the wild (as seems to be contended), then clearly the solution is to blacklist the app (if it exists on the store, which is not attested) and pull it off the store. And that will work regardless of whether or not Samsung got…

I think it does - playing wack-a-mole with apps using frail heuristics is just not a reliable approach.

Re: Google confirms Android attacks; no fix for most Samsung users

#158
post #27
post #11

> This [update] was rushed out to all Pixel users. Pixel 8 here, still don't have the update. That's... not great.

Just go to the software update, touch the button, then touch it a second time, and that will give you all available updates immediately, regardless of your random position in the rollout process.

Thanks that worked, so weird that you have to do it twice...

Re: Google confirms Android attacks; no fix for most Samsung users

#159

Earlier quoted context omitted.

I'd suggest you to use GrapheneOS.

Is the patch already available for GrapheneOS?

It was made available in the end of OCTOBER in the special security preview channel.

GoS has already deployed patches to some of the vulnerabilities you'll read about in January.

All the partnering vendors have access to the same bulletins.

Multi-billion companies like Samsung or Google had access to that since AT LEAST October. They chose to release these patches late. Some will release these patches months form now. Some, perhaps never.

So, the tiny team wins.

Re: Google confirms Android attacks; no fix for most Samsung users

#160

This requires user action, right? User needs to install the APK by hand? In other words - if I don't install any crap on my phone I am safe?

Yes (with caveats) In todays world, web based exploits are pretty rare. The only time you really see this happen is with full proprietary systems like IPhones because the software stack on those is all intertwined between kernel code and user code, and things like sending a text message with some formatted characters can lead to reboots of phones. But even then, to gain a full command line shell or steal secrets is e…

Oh, but they will, given enough time.

Remember Kevin Mitnick's most successful approach, social engineering :)

Post reply on HN