Earlier quoted context omitted.
The strange thing is that I have less people around me with virus problems, stolen card problems, scam problems, etc than 10 years ago. Despite the fact that we deem those devices less secure. Something is off.
Maybe criminals are more subtle now. For example most people who own devices that are part of the Mirai botnet are not aware of it.
No One Cares About the Security of Unlocked Android Phones
21–30 of 44 posts
Re: No One Cares About the Security of Unlocked Android Phones
#22But who cares about security of your locked Android phone either?
Sounds like they're talking more about disreputable or negligent OEMs than anything to do with having an unlocked bootloader or unlocked SIM.
Past phones I've owned that weren't as good with security updates depended on me being able to unlock the bootloader so I could keep them as up to date as was feasible. No timely security update from Samsung or HTC? Find a patched version of the ROM image built by some helpful developer on XDA and flash the phone.
Even today, as I only buy Nexus/Pixel/etc Android phones, they're still sold as "unlocked" in terms of SIM because I don't have any desire to give a carrier more influence over my device than I have to. Again, not an issue with security as even my older Nexus devices are getting security patches (if not the big, hardware-dependent OS updates).
Re: No One Cares About the Security of Unlocked Android Phones
#23Oh, great. My BLU R1 HD from Amazon is sitting next to me as I type this. Anyone know if this is patched in the latest software update, or how I can tell if I'm affected? I don't see anything "AdUps" in the applications or services list. edit: Per an email from Amazon, http://www.bluproducts.com/security/ has instructions.
The lack of corporate BS on that page really surprised me: BLU Products has identified and has quickly removed a recent security issue caused by a 3rd party application which had been collecting unauthorized personal data in the form of text messages, call logs, and contacts from customers using a limited number of BLU mobile devices. ... The affected application has since been self-updated and the functionality veri…
Re: No One Cares About the Security of Unlocked Android Phones
#24Earlier quoted context omitted.
The lack of corporate BS on that page really surprised me: BLU Products has identified and has quickly removed a recent security issue caused by a 3rd party application which had been collecting unauthorized personal data in the form of text messages, call logs, and contacts from customers using a limited number of BLU mobile devices. ... The affected application has since been self-updated and the functionality veri…
Similarly, their phones are refreshingly free from carrier-lock or (obvious) crapware.
Re: No One Cares About the Security of Unlocked Android Phones
#25Which is exactly why we need to fix this problem. Consumer products don't have good security at all and it's making the world a worse place
The strange thing is that I have less people around me with virus problems, stolen card problems, scam problems, etc than 10 years ago. Despite the fact that we deem those devices less secure. Something is off.
Usually, the underlying issue is complex enough that it takes years or decades to make the problem like 95% better. But the community around the issue has become entrenched, and won't go away just because the problem is basically solved. There's plenty of excuses at hand to justify the continued existence of the group - the problem is never 100% gone, so there's always something new to address, and they can always say that we have to be on guard for the problem coming back. But the effect is the same - the noise gets louder as the signal gets weaker.
If you're paying attention, you can see this pattern play out for all sorts of things.
In this case, we have both made the computers and browsers a lot more secure, and a lot of consumer-level computing activity has, for a bunch of reasons of which security is certainly one, moved to drastically more locked-down devices. Good luck building a botnet of iPads and Android phones. Many of the hacks that get the most publicity are super-complex one-offs that are in theory highly dangerous, but in practice are so valuable that they would only ever be used by state-level actors against handpicked national security targets, because you have to spend millions to find them, and they will become worthless about a week after the appropriate companies become aware of them.
Re: No One Cares About the Security of Unlocked Android Phones
#26Earlier quoted context omitted.
It's more complicated than that. If Google just produced a standard version of Android with a standard kernel version that all vendors would write for, refreshing and wiping phones would be as easy as Windows/Linux laptops. I wrote a post on this a while back: http://penguindreams.org/blog/android-fragmentation/ Since then, I've become more and more frustrated with other ARM boards. Android fragmentation is directly…
> If Google just produced a standard version of Android with a standard kernel version that all vendors would write for Then you wouldn't get all location data, call logs, and application usage data sent to China, you'd get them sent to the US, via Google, for better user experience and more targeted ads. The result would be literally the same.
Re: No One Cares About the Security of Unlocked Android Phones
#27Re: No One Cares About the Security of Unlocked Android Phones
#28Oh, great. My BLU R1 HD from Amazon is sitting next to me as I type this. Anyone know if this is patched in the latest software update, or how I can tell if I'm affected? I don't see anything "AdUps" in the applications or services list. edit: Per an email from Amazon, http://www.bluproducts.com/security/ has instructions.
Re: No One Cares About the Security of Unlocked Android Phones
#29Personally, I purchased a BlackBerry Priv (which runs Android) and couldn't be happier. Phone is/was very cheap compared with the other flagship devices and it runs really fast. Came factory unlocked direct from BlackBerry and has zero bloatware on it. I get frequent O/S updates for security patches as well, which is far more than I can say about my previous phone (Galaxy S3 from AT&T).
Despite most people's apathy, or even hatred, of BlackBerry, they have always done security very well. The Priv is no exception - secure boot, hardware keystore, modified Linux kernel, FDE enabled by default, work/personal account separation, external SD card protection, their DTEK software, etc. Some of their security features are included as part of the base Android OS, yes, but their security model as a whole from start to finish is far ahead of all competitors.
Re: No One Cares About the Security of Unlocked Android Phones
#30Earlier quoted context omitted.
> If Google just produced a standard version of Android with a standard kernel version that all vendors would write for Then you wouldn't get all location data, call logs, and application usage data sent to China, you'd get them sent to the US, via Google, for better user experience and more targeted ads. The result would be literally the same.
If you are in the US, at least your data isn't being sent to another country. Outside the US, I think your comment stands on its own.
EDIT: At the time, it was at -3