Live data from Hacker News

Google confirms Android attacks; no fix for most Samsung users

forbes.com

161–170 of 177 posts

Re: Google confirms Android attacks; no fix for most Samsung users

#161
post #23

Earlier quoted context omitted.

I hoped with a move to Fuschia, Google would attempt to fix this, but unfortunately Fuschia on mobile is dead.

It’s “Fuchsia” with a “chs” not a “sch”. Where do you get your information that it’s dead?

Fuchsia isn't dead. People just like to spread random misinformation on the internet. Source: I work on fuchsia.

The intention is to have a stable driver abi which should allow you to build an arbitrary OS on top (fuchsia itself is exceptionally modular and doesn't have a lot of opinions it imposes on products built above it). Of course similar to a Linux BSP not helping Fuchsia run, such a layer wouldn't enable you to run other OS on top that are not built on top of fuchsia. There is also a limit to what you can generalize in the OS layers as some products may implement private apis between themselves and specific hardware drivers. A stable ABI also implies that the drivers won't necessarily need to be open source, but if the goal is to keep the rest of the OS updatable even if drivers themselves are not updated, that is a necessary concession. There are also many other practical benefits to keeping drivers open source regardless of license obligations to do so. That all said I'm very optimistic about this direction regardless of these caveats.

Re: Google confirms Android attacks; no fix for most Samsung users

#162
post #100

Earlier quoted context omitted.

I never understood why a mobile operator has any say in when to apply security patches? Does it happen with iPhones?

iOS updates are not limited by the operator.

Is this true for updates that might affect the way it interacts with the network (eg baseband firmware updates)? I assume it's much easier for iPhones to decouple that layer from the rest of the OS, which isn't the case for Android/Linux.

Re: Google confirms Android attacks; no fix for most Samsung users

#163
post #129

Earlier quoted context omitted.

Sorry for my irony. While I do not think it is spyware on itself, it sure is a way to force vendors to bundle spyware.

Elaborate please. PI on its own is just an insurance API for banking and similar apps to ensure that they can do secure compute on the device. It can also be used to check if the device that the app is running on is a genuine Android device, since no VMs or custom ROMs can pass hardware integrity.

What sense is does it make to certify an insecure device that may be subject to all kinds of remote exploits and elevated code execution as 'unmodified'. The argument of the banks is: the device is insecure (even with the latest patches). We all know the whole compliance is a bit more complex, so it might make sense on that level...

Re: Google confirms Android attacks; no fix for most Samsung users

#165
post #144

Earlier quoted context omitted.

My point is that with macOS, Apple writes the drivers which means at least as long as the hardware is supported you can be pretty sure that there will be prompt fixes for any issue. With Android, Windows or closed-source Linux drivers (cough NVIDIA) you're left entirely at the mercy of whoever made the tiny little component controlled by the driver to provide a fix, which then has to bubble up through the ODM/OEM unt…

I can't see how the situation with apple is any better considering what you've said, you're still beholden to apple to provide a fix. Even if that fix might be quicker coming IF apple is currently supporting the device; not at all otherwise.

> I can't see how the situation with apple is any better

Because in the Windows world, there often are no updates after maybe 1, 2 years. Chances are high, if you look in Device Manager of any reasonably new system, you'll find a lot of drivers dating back to before Covid and that's 5 years ago. Chances are even higher that if you look close enough, you'll find something being exploitable.

With Apple? Their track record for support is around 7 years.

Re: Google confirms Android attacks; no fix for most Samsung users

#166
post #125

Earlier quoted context omitted.

> In the word "french" C H is pronounced sh No, it's not. Unless you think the "n" in french is pronounced "nt".

Fine, and legit. I get what I deserve for not looking it up! Scaramouch and crochet though.

Sure, and cache and cloche.

But the question here is chs, not ch. Which though rare, is widely understood to be a kind of guttural sound or "k" sound followed by an s. In -uchs or -ichs coming from German.

Not the "sh" sound in fuchsia.

Re: Google confirms Android attacks; no fix for most Samsung users

#167
post #116
post #105

Earlier quoted context omitted.

That doesn't answer the question.

There are two kinds of people: 1. Those who can extrapolate from incomplete information

Please, feel free to extrapolate for me whether the "unspecified vulnerability" referenced in the article was introduced more or less than five years ago.

Re: Google confirms Android attacks; no fix for most Samsung users

#169

Earlier quoted context omitted.

They're cheap

If the flaws were just about missing premium features, that'd be one thing. But it's not. It's petty and abusive. For example, you can't see (I think it was) heart rate if you have a Samsung smart watch, but don't have a Samsung phone. They've gone out of their way to just not provide that, if you instead have a Pixel phone. And you need like 5 gigantic apps installed to manage it. Why is it not just one single Samsu…

I mean that people buy it cause it's cheap, not that it's a good idea. They don't even look at the rest. It's like an Altima.

Personally have no reason to consider anything but an iPhone, even if it has to be used.

Re: Google confirms Android attacks; no fix for most Samsung users

#170

I choose not to install any banking app and do my banking in incognito mode so that any malefactor who somehow gets into my device can't see where I bank. Of course that leaves security in the hands of the browser.

Good news, they’re expecting and ready for that burden!
Post reply on HN