Live data from Hacker News

Malicious apps infect 25M Android devices with 'Agent Smith' malware

phys.org

191–200 of 222 posts

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#191

Earlier quoted context omitted.

That's easy... make the batteries easily replaceable... oh wait.

That would makes the phones considerably thicker and/or make the battery life significantly worse. I don't think replaceable batteries are really worth the tradeoffs given the constraints of a modern smartphone. Lithium batteries can be quite dangerous, so they need to be in a case to prevent damage that could cause them to catch fire. Then, the phone itself needs a battery door which adds even more thickness and pot…

> That would makes the phones considerably thicker and/or make the battery life significantly worse.

Would it? The Lumia 950 has a user replaceable battery:

Thickness - Lumia 950: 8.2mm; iPhone XR: 8.3mm

Battery - Lumia 950: 3000mAh; iPhone XR: 2942mAh

I remain unconvinced that other phones couldn't be engineered to have a user replaceable battery.

Water resistance is potentially a fair point, but iPhones have had non-user-replaceable batteries for far longer than they have been water resistant, and I'm not sure it would be impossible to do _both_ (Tile trackers have user replaceable batteries, and are water resistant up to IP55).

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#193
post #97
post #77

Earlier quoted context omitted.

This seems to be getting a lot of attention, so as an Android Engineer with some security and framework experience let me try to explain. This is a side effect of Android's initial approach to it's open nature. Android allows a manufacturer to modify its framework for their own use case. Then the manufacturer can allow a specific carrier to input their own system applications and firmware on to the devices well (your…

This is also solvable by Android taking a slightly different approach. Isolating the OS and security framework so that it can always just be updated. The carriers and and manufacturers are still free to install whatever bloatware they want and do what ever logo nonsense they want. We ran into nonsense issues creating a cross platform development toolchain when HTC phones just didn't implement certain functions of the…

> This is also solvable by Android taking a slightly different approach. Isolating the OS and security framework so that it can always just be updated.

I think that is the plan with Fuchsia.

The core of the OS is small. The drivers can be separated out more easily, and with a (hopefully) stable driver API, they may not need to get updated ever (baring security bugs in the driver code itself).

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#194
post #144

Earlier quoted context omitted.

> purposely throttling So that the phones don't randomly shut off because their lithium ion batteries were old. Yes, they should have told people but it wasn't done maliciously.

> So that the phones don't randomly shut off because their lithium ion batteries were old. Yes, they should have told people but it wasn't done maliciously. "old" - they were less than two years old. They were used up significantly faster than on other phones because Apple was pulling more power to get better benchmarks. This significantly lowered their lifetime and then "forced" them to make phones slower than adver…

You really think Apple cares about benchmarks against Android phones? People aren’t going to switch phones from iOS to Android because of benchmarks.

Besides that’s not the way phone manufacturers benchmark well. Android manufacturers have been caught detecting the benchmark and then running in a higher power mode - not running higher all of the time.

Batteries usually start losing their charge in two years.

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#195
post #77
post #2

> Google already fixed at least one of the Android exploits used by "Agent Smith," nicknamed Janus, in 2017 but the fix hasn't made its way onto every Android phone. It's a potent reminder that millions of phones around the world are being used without the latest security measures. Because Samsung (or similar) or even more weirdly, Sprint (or similar) just doesn't fucking update our Android versions for months, or ev…

This seems to be getting a lot of attention, so as an Android Engineer with some security and framework experience let me try to explain. This is a side effect of Android's initial approach to it's open nature. Android allows a manufacturer to modify its framework for their own use case. Then the manufacturer can allow a specific carrier to input their own system applications and firmware on to the devices well (your…

If Google put their foot down the manufacturers and carriers would tow the line.

Trying to sell a (non-Apple) smartphone without Android in 2019 would be like trying to sell a PC without Windows. Your market share could be counted on one hand.

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#196

Earlier quoted context omitted.

This comment and most replies use "carrier" as shorthand for "carrier and/or manufacturer". This looks funny to me because my carrier is T-Mobile and doesn't add bloatware AFAICT. Using "manufacturer" as the shorthand would make more sense to me.

T-Mobile does add software to phones. Wi-Fi calling requires T-Mobile-specific OS-level modifications. You won't be able to use it on unbranded unlocked phones. It's definitely not bloatware though.

It would not surprise me to see kind of an opposite thing - such as other carriers selling phones where they purposefully turned off or hid settings for wi-fi calling, turning on hotspot and similar.. in which case if tmobile sold the same phone, then it would be a matter of them not turning off / hiding.

Would be an interesting chart to show the things the various carriers had turned on / off... added / removed which similar phones.

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#197
post #77
post #2

> Google already fixed at least one of the Android exploits used by "Agent Smith," nicknamed Janus, in 2017 but the fix hasn't made its way onto every Android phone. It's a potent reminder that millions of phones around the world are being used without the latest security measures. Because Samsung (or similar) or even more weirdly, Sprint (or similar) just doesn't fucking update our Android versions for months, or ev…

This seems to be getting a lot of attention, so as an Android Engineer with some security and framework experience let me try to explain. This is a side effect of Android's initial approach to it's open nature. Android allows a manufacturer to modify its framework for their own use case. Then the manufacturer can allow a specific carrier to input their own system applications and firmware on to the devices well (your…

Sounds like getting phones with stock Android is the best option. I rarely see in the stores Android One being a major feature / selling point: https://www.android.com/one/

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#198
post #146

Earlier quoted context omitted.

> Steve Jobs famously cared a lot about user experience, security and reliability. Remember that Apple under his leadership took a firm stance and loudly and publicly refused to allow Flash on its devices, despite the fact that many websites back then relied on Flash. A less generous take on that would be that he/Apple also wanted to push their app store. At the time Flash was popular for publishing apps and games on…

You mean the same Flash that Adobe said they could have gotten to work on the original iPhone - with 128MB of RAM and a 400Mhz processor but barely worked on Android with minimum requirements of a 1Ghz processor and 1GB of RAM?

I wasn't claiming Flash was ideal in any sense -- just that it was popular back then.

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#199

Earlier quoted context omitted.

What if you don't live near an apple store? Why not let the user manage their own battery, that is also not a terrific challenge.

You can ship your phone to Apple and be without it for about a week. Or, take it to a 3rd party repair shop.

Exactly.

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#200
post #77

Earlier quoted context omitted.

This seems to be getting a lot of attention, so as an Android Engineer with some security and framework experience let me try to explain. This is a side effect of Android's initial approach to it's open nature. Android allows a manufacturer to modify its framework for their own use case. Then the manufacturer can allow a specific carrier to input their own system applications and firmware on to the devices well (your…

This is what I love about Apple. They gave the carriers a big middle finger when it comes to the usual bullshit of bloatware, sticking their logos on things or getting in the middle of updates. That’s because they cared about the end user experience. Google was happy to just grab market share at the expense of the users by allowing carriers to continue with their usual shenanigans. For this reason Apple will have my…

Yet another apple shill. All they care is making money by hyping their second-class tech to tech-illiterate rich fellows..
Post reply on HN