Live data from Hacker News

Latest Android phones hijacked with one-shot Chrome exploit

theregister.co.uk

21–30 of 46 posts

Re: Latest Android phones hijacked with one-shot Chrome exploit

#21

Happy Android and Firefox user calling in. My Nexus is still safe :)

I'm also using Firefox on Android (because it is the only mobile browser that supports extensions).

However, the desktop Firefox regularly tops my 'Apps using significant energy' list, even when idling.

Re: Latest Android phones hijacked with one-shot Chrome exploit

#22
i never understood why even tech ppl are OK using phones like clueless people used computers in the 90s.

vendor toolbars and bundled applications? check. saved logins on banks and everything else? check. no firewall? check. ads everywhere? check.

get your crap together, everyone.

Re: Latest Android phones hijacked with one-shot Chrome exploit

#23
post #18

This is why you should use Firefox for Android: it's a great browser (even offering extensions such as uBlock Origin), but it has very little marketshare and is thus unlikely to be attacked. This is also part of the reason a frequently updated Android distribution (Nexus or CyanogenMod) might in fact be more secure than iOS, where you are forced to be vulnerable to Apple's Webkit engine. The same reasoning also appli…

So, are there more exploits for iOS out there? I had the impression that Android has more. Also, this particular one is a browser JavaScript problem that affects multiple android versions, is it not?

Android has more if you're on the bleeding edge and installing fart apps.

if you're on 4.4 with Firefox+no script you're fine. IOS won't let you have a setup like that...

Re: Latest Android phones hijacked with one-shot Chrome exploit

#24
post #16

Earlier quoted context omitted.

>Google doesn't want to force OEMs and providers to provide updates I think you're assuming a lot about the relationship's power dynamics and what contracts are at play that may have been written quite a while ago. Also forgetting that more often than not it's the telco that's blocking or bottlenecking updates. The reason Apple was able to do what it did is because they provided the software and hardware and were abl…

I used to work for a famous Finn company with seat in Espoo.

Wink, wink. I suppose that's about my first point though. What about the second?

Re: Latest Android phones hijacked with one-shot Chrome exploit

#25
post #18

This is why you should use Firefox for Android: it's a great browser (even offering extensions such as uBlock Origin), but it has very little marketshare and is thus unlikely to be attacked. This is also part of the reason a frequently updated Android distribution (Nexus or CyanogenMod) might in fact be more secure than iOS, where you are forced to be vulnerable to Apple's Webkit engine. The same reasoning also appli…

So, are there more exploits for iOS out there? I had the impression that Android has more. Also, this particular one is a browser JavaScript problem that affects multiple android versions, is it not?

> So, are there more exploits for iOS out there? I had the impression that Android has more.

But that was his point - he was referring to Nexus-only (or CyanogenMod), not "Android", where 87% of the devices are vulnerable to least one of the 11 vulnerabilities tested below, because of their lack of (fast) updates:

http://androidvulnerabilities.org/

Re: Latest Android phones hijacked with one-shot Chrome exploit

#26
post #16

Earlier quoted context omitted.

I used to work for a famous Finn company with seat in Espoo.

Wink, wink. I suppose that's about my first point though. What about the second?

They just needed to change the license how licensees are allowed to use Android.

If OEMs or Telcos would loose the legal right to ship phones with Android if the updates weren't provided within a specific SLA, then they surely would comply.

As an example how to put telcos in line, in the early days that mobiles started shipping with wlan support, Vodafone tried to sell N95 with wlan and VoIP support disabled on their firmware. Eventually they had to provide a full working N95, if I remember correctly.

I doubt that nowadays they would go back to develop their own OSes.

Re: Latest Android phones hijacked with one-shot Chrome exploit

#27
post #18

This is why you should use Firefox for Android: it's a great browser (even offering extensions such as uBlock Origin), but it has very little marketshare and is thus unlikely to be attacked. This is also part of the reason a frequently updated Android distribution (Nexus or CyanogenMod) might in fact be more secure than iOS, where you are forced to be vulnerable to Apple's Webkit engine. The same reasoning also appli…

I tried it on my Android phone a while ago, and my (unscientific) conclusions are that it's slower, more resource intensive, and drains the battery faster than using the default Chrome browser.

Re: Latest Android phones hijacked with one-shot Chrome exploit

#28

Am I alone being amazed that we still have not experienced an Android worm or virus shutting down all mobile networks globally for a few days? I remember Slammer, which brought down many corporate networks and severely impacted all internet traffic. With all these unpatched phones and so many vulnerabilities it seems a matter of time before something like this happens on a grander scale in mobile networks. Would it b…

Corporate Networks 10-15 years ago are like the Canadian US border, where as today they're more akin to the North Korean South Korean border.

10-15 years ago everything was on the same LAN except for the handful of web servers you might have plugged into the DMZ port of your firewall and every client was implicitly trusted. Today we have VLANs for everything and segmentation is done purely for organization aesthetics. Switches can dynamically provision ports based on the client connected. Wired clients and wireless clients reside in different segments with different restrictions. Open network ports in unsecured areas, like conference rooms, are on highly restricted VLANs. I've even seen segmentation based on client MAC addresses where unknown devices were just routed back to themselves for everything.

Back then Email servers accepted connections from anyone and would relay just about anything no questions asked, today email servers are locked down and very suspicious of one another with DNS records (SPF, PTR) for verification.

There are security appliances sitting on the edges of network monitoring all inbound and outbound traffic as well as appliances in the network watching the too and fro. We have software clients sitting on desktops monitoring traffic and blocking malicious or harmful requests as well. Software firewalls are now standard and turned on by default.

On top of all that, Mobile Networks are distributed with each cell tower being it's own insular network with a secure WAN connection over an ISP back into the central network with all manner of port filtering in place.

Re: Latest Android phones hijacked with one-shot Chrome exploit

#29
post #18

This is why you should use Firefox for Android: it's a great browser (even offering extensions such as uBlock Origin), but it has very little marketshare and is thus unlikely to be attacked. This is also part of the reason a frequently updated Android distribution (Nexus or CyanogenMod) might in fact be more secure than iOS, where you are forced to be vulnerable to Apple's Webkit engine. The same reasoning also appli…

The article made it sound as though the vulnerability was in Javascript V8 itself. In which case, if Firefox supports it, wouldn't it be just as vulnerable?

Re: Latest Android phones hijacked with one-shot Chrome exploit

#30
post #18

This is why you should use Firefox for Android: it's a great browser (even offering extensions such as uBlock Origin), but it has very little marketshare and is thus unlikely to be attacked. This is also part of the reason a frequently updated Android distribution (Nexus or CyanogenMod) might in fact be more secure than iOS, where you are forced to be vulnerable to Apple's Webkit engine. The same reasoning also appli…

The article made it sound as though the vulnerability was in Javascript V8 itself. In which case, if Firefox supports it, wouldn't it be just as vulnerable?

AFAIK Firefox on Android doesn't run on V8, it uses the usual Firefox JS engine
Post reply on HN