Live data from Hacker News

Google urges Android phone users to switch off Wi-Fi calling

scrippsnews.com

161–170 of 178 posts

Re: Google urges Android phone users to switch off Wi-Fi calling

#161
post #98

Earlier quoted context omitted.

You're struggling to figure out where wifi calling is helpful, really? Maybe a house that doesn't get cell reception inside, especially older ones with thick walls. Or one that doesn't get cell reception outside either. ??? was that difficult?

Exactly. Cell reception at our house is terrible even though we're in the suburbs. When making a call I get next to the AP.

You're not alone:

>A Tech Mogul’s Castle Is His Home -- Unless There’s No Cell Signal

https://www.latimes.com/archives/la-xpm-2003-feb-13-fi-wozni...

Re: Google urges Android phone users to switch off Wi-Fi calling

#162
post #109
post #14

I am not sure I understand this. I have a S22 Galaxy Ultra. I do not see anywhere in my settings to turn on or off wifi-calling. Did we already get an update disabling this? I have googled this for about 10-15 minutes now and none of the results match anything to do with my screen settings.

The availability of this toggle is carrier dependant. Also S22 Ultra has already been patched.

Awesome. I didn't know this! Thanks.

Re: Google urges Android phone users to switch off Wi-Fi calling

#163
post #149

Earlier quoted context omitted.

There's not a single feature added to phones during that time worth replacing working device for average user.

security updates?

seems to still be maintained by Replicant

https://redmine.replicant.us/projects/replicant/wiki/GalaxyS...

which seems to be outdated by about 5 years now

https://redmine.replicant.us/projects/replicant/wiki/DeviceS...

i admire how long devices could be used, if they just were to receive security updates...

Re: Google urges Android phone users to switch off Wi-Fi calling

#164
post #160

Earlier quoted context omitted.

Not sure if you’re referring here to the BlackBerry era or right back to side-sliders and razr flips, but either way, both the stakes and the attack surface were way lower back when there were no apps and phones really were just for calling and texting.

Brew, Symbian, Java ME and Windows CE/ Pocket PC, Palm era. Plenty of apps and networking in Europe and Asia.

Fair, okay— as soon as email, payments, or banking is involved then you have a juicy target and you need a device that's secure end-to-end.

Re: Google urges Android phone users to switch off Wi-Fi calling

#165

Earlier quoted context omitted.

They only released the March update for my Pixel 6a this morning, I did breathe a sigh of relief once it was installed.

I'm in the same situation, but is there any way for us to know if our Pixel 6s were compromised before the patch became available?

Not if it was done well, unfortunately... I suppose there's always sending a text to a friend saying "I'll leave the money in a blue bag on the corner of 4th ave at 10am tomorrow" and hiding in the bushes (but sadly we'd expect an attacker who was halfway across the world, not across town). I am pretending everything is fine until I can't.

Re: Google urges Android phone users to switch off Wi-Fi calling

#166
post #118

Four things of note: 1. I've not seen anyone explain whether this could be exploited by anyone with access to phone lines (i.e. Twilio users) or not and if it would be trivial to try the vuln with every phone number you could find in any DB. If those things are the case, it seems like the chances would be very high that this would be or has already been exploited and affecting every unpatched phone. 2. It seems like…

> It seems like Project Zero mistakenly thought that Google devices were already patched when they made their announcement ("affected Pixel devices have received a fix"). Whoops! Thanks for giving attackers a heads up. Do you have a source for the fact that Pixel devices don't yet have a fix? The post we're commenting on is actually just blogspam, with its only real source being the initial project zero disclosure [0…

The blog post was published on the 16th.[0] Pixel 6 and 6a started the update rollout on the 20th.[1] The March security update was scheduled for earlier but was delayed for 6/a for some reason, and it seems like the Project Zero team didn't check on the actual status of the rollout.

[0] https://googleprojectzero.blogspot.com/2023/03/multiple-inte... [1] https://9to5google.com/2023/03/20/pixel-6-march-2023-update/

Re: Google urges Android phone users to switch off Wi-Fi calling

#167
post #141

Earlier quoted context omitted.

I read that as well, and either it's unclear or I lack the technical understandings to apply that to my question. What does "at the baseband level" mean in terms of remote attack vector? Do they need to be physically nearby with an antenna or could they be across the world connecting through VOIP? And why do they need to know a phone number? If it's that they need a nearby antenna + knowledge of a phone number, it so…

In effect, it means if they can call you, they can exploit you. The description given was what an attacker needs to hack you in particular, which means they need your phone number to determine which device to target. If they want to spam a million users they could do that too, although these kinds of things are typically not done this way because that is very noisy and reduces the effective life of the vulnerability.

> If they want to spam a million users they could do that too, although these kinds of things are typically not done this way

That seems like a convenient assertion not based on evidence.

Without trying to sound confrontational, it appears as if you are a current employee of Google, which might have colored your comment and should probably have been disclosed.

Re: Google urges Android phone users to switch off Wi-Fi calling

#168
post #107

Earlier quoted context omitted.

It's also not crystal clear which Exynos chipsets are affected. I have a Samsung Galaxy S10e and a Samsung Galaxy S2 which both have Exynos chipsets, but I can't tell if there's simply no mention of these being affected because they're older models, or if it's explicitly only the newer models that are affected.

Just to be sure. A Samsung Galaxy S2? This phone is like 15? years old and still in use?

I keep a few older phones updated for the purposes of travel, backup phones or in case a friend needs a phone temporarily etc.

Some older but popular models still have community maintained ROMs. I try save them from the scrap heap if I can. The main annoyance is battery life and having to keep Micro-USB chargers around.

Re: Google urges Android phone users to switch off Wi-Fi calling

#169
post #163

Earlier quoted context omitted.

security updates?

seems to still be maintained by Replicant https://redmine.replicant.us/projects/replicant/wiki/GalaxyS... which seems to be outdated by about 5 years now https://redmine.replicant.us/projects/replicant/wiki/DeviceS... i admire how long devices could be used, if they just were to receive security updates...

If I had more time, I would've liked to create my own ROMs for some of my old devices (more specifically, kernels).

If hardware manufacturers published a list of their own patches to the source tree (rather than the typical "single commit/zip file of the entire linux kernel") then it would make community maintenance of old devices much easier.

Re: Google urges Android phone users to switch off Wi-Fi calling

#170
post #156

Earlier quoted context omitted.

Google Play Protect has limited capabilities to protect against in-the-wild exploits of the kind Maddie described. It knows about certain packaged implementations, which means that it can offer some defense from off-the-shelf uses of an exploit, but it definitely does not reduce the risk to anywhere near zero. The only correct way to mitigate against exploits like this is a patch, end of story.

Absolutely, but like I mentioned in the prior post, these are local privescs. You basically need to go out and install malicious apps. If you can use Windows without it getting full of malware, you can handle unpatched Android LPEs too. Keep in mind, Webview, browsers, email clients, etc are patched via app update mechanisms.

GPU bugs are particularly concerning because they have significant power (the GPU can often map all of physical memory if convinced to do so) and widely exposed (lots of things need graphics). Turning one of these into a full chain can often require zero bugs if the buggy API is callable from JavaScript, or one to escape the VM and poke the driver.
Post reply on HN