Live data from Hacker News

Malicious apps infect 25M Android devices with 'Agent Smith' malware

phys.org

211–220 of 222 posts

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#211
post #77
post #2

> Google already fixed at least one of the Android exploits used by "Agent Smith," nicknamed Janus, in 2017 but the fix hasn't made its way onto every Android phone. It's a potent reminder that millions of phones around the world are being used without the latest security measures. Because Samsung (or similar) or even more weirdly, Sprint (or similar) just doesn't fucking update our Android versions for months, or ev…

This seems to be getting a lot of attention, so as an Android Engineer with some security and framework experience let me try to explain. This is a side effect of Android's initial approach to it's open nature. Android allows a manufacturer to modify its framework for their own use case. Then the manufacturer can allow a specific carrier to input their own system applications and firmware on to the devices well (your…

> This can lead to multiple firmware variants for a specific device. It's not uncommon to see over 20 variants of a firmware for a specific Samsung device for example. This can be broken down by carrier, by region, by OS, etc.. for a number of different reasons.

You forgot to mention this was fixed about 2 years ago when Google pushed mandatory changes in the way customisation are added to the firmware image.

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#212
post #97
post #77

Earlier quoted context omitted.

This seems to be getting a lot of attention, so as an Android Engineer with some security and framework experience let me try to explain. This is a side effect of Android's initial approach to it's open nature. Android allows a manufacturer to modify its framework for their own use case. Then the manufacturer can allow a specific carrier to input their own system applications and firmware on to the devices well (your…

This is also solvable by Android taking a slightly different approach. Isolating the OS and security framework so that it can always just be updated. The carriers and and manufacturers are still free to install whatever bloatware they want and do what ever logo nonsense they want. We ran into nonsense issues creating a cross platform development toolchain when HTC phones just didn't implement certain functions of the…

Not to sound like a Google apologist, but all you ask is already in there.

And Google's extensive compatibility requirements aside, webview is now directly updated from the store.

Android Q will extend this to most system components via apex.

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#213

Earlier quoted context omitted.

I bought a new Android table from Samsung 3 years ago for more daughter - when bought it had a 2 year old version of Android on and enquiries from Samsung UK said it would not be updated. My daughter is still using it today, unupdated from 5 years ago. We tend to be an Apple household Edit - the Device, bought in September 2016 was a Samsung Galaxy TAB E 9.6 SM-T560 WI-FI - I will check the software level tonight.

I've had luck with official Google phones the past couple years, and in the past the Moto line of Android phones stayed up to date to a point.

My Moto phone hasn't had a security update in a year, and sale of the model was stopped 2 years ago, so that's 1 year support. Luckily it was cheap. I'll be ditching Android I think

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#214

Earlier quoted context omitted.

Don't make this about moral superiority of Apple over Google. Apple did it because they could , because when the iPhone came out it owned the smartphone market; any carrier that didn't play ball would be frozen out (as T-Mobile was initially - AT&T's exclusivity on the iPhone really helped their market share among high-end consumers). Google did not have that luxury.

That’s not an accurate representation of what happened. When Apple/Steve Jobs went into negotiations with Verizon and AT&T (then known as Cingular), it didn’t have any leverage. In fact, Verizon wouldn’t sign the deal in part because of the control Steve Jobs wanted over the devices. AT&T agreed to get the exclusive. BlackBerry was King when the iPhone launched and BlackBerry bent over backwards to do whatever the ca…

Is that because Android was a defensive move against ios to protect the search/advertising income, like Chrome, rather than something they make money from do you think ?

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#215

Earlier quoted context omitted.

> They gave the carriers a big middle finger when it comes to the usual bullshit of bloatware, sticking their logos on things or getting in the middle of updates Except, of course, the bloatware of their own making. Here's a novel idea: you, yourself can give the middle finger to the carriers and buy an unlocked phone from a provider that delivers timely updates to Android...just like Apple. > For this reason Apple w…

I buy unlocked Nexus devices to avoid mftr and carrier bloatware and update delays. Never again for a Samsung device, they churn through models absurdly quickly, delay updates for months, and shovel tons of crap on.

>I buy unlocked Nexus devices to avoid mftr and carrier bloatware and update delays.

Exactly. There is a whole series of phones offering bloat-less Android, from a variety of manufacturers:

https://www.android.com/one/

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#216

Earlier quoted context omitted.

A battery replacement is $79. No one is forcing you to buy a new phone.

A lithium ion battery doesn't cost anywhere near that much, its either poor design and/or profiteering on the device manufacturers part to charge that much for a $15 battery to be replaced.

I do about a dozen mobile repairs a year for family, and it really does seem like the new automobile.

Auto’s were not built for ease of repair, the repairs themselves can be quite easy if you know what to do, and often require components that are only 1 or 2 orders of magnitude in price. Paying someone who knows what to do with it, they also add an order (similar to screen repairs).

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#217
post #6

Earlier quoted context omitted.

Pi-hole or alike. Works very well for me, although I'm experiencing some problems with it. I'm a bad system administrator, though.

does that work when you are away from home wifi? (not sure what all pi-hole does)

Set up a VPN for that with Vultr. $5 a month, that's okay for me.

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#218

Earlier quoted context omitted.

That’s not an accurate representation of what happened. When Apple/Steve Jobs went into negotiations with Verizon and AT&T (then known as Cingular), it didn’t have any leverage. In fact, Verizon wouldn’t sign the deal in part because of the control Steve Jobs wanted over the devices. AT&T agreed to get the exclusive. BlackBerry was King when the iPhone launched and BlackBerry bent over backwards to do whatever the ca…

Is that because Android was a defensive move against ios to protect the search/advertising income, like Chrome, rather than something they make money from do you think ?

Yes. (Although it was originally a defensive move against Windows Mobile and BlackBerry and Symbian and it then pivoted as soon as they saw the iPhone.)

The big draw for Android for OEMs was that unlike Windows Mobile or Symbian, there was no licensing fee for the devices. HTC, which made the first Android phone, was a Windows Mobile device maker (fun fact, the XDA from XDA Developers, was an OG Windows Mobile forum — XDA was the name of an early series of Windows Mobile devices) — Samsung and LG and Motorola made Windows Mobile phones, Sony used Symbian and so on. Android was free and customizable, which made it enticing for OEMs and carriers to embrace. And unlike BlackBerry, carriers didn’t have to give a portion of the data charge (which was like $20 or $40 a month per BlackBerry device) to BlackBerry, they got to keep all the data fees to themselves.

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#219

Earlier quoted context omitted.

Question: my brother just got a used pixel 1 phone. Will it stop getting security updates soon/already?

FWIW, LineageOS has official nightlies for that phone now (typing this from one of those builds now, actually)

If the phone is from Verizon the bootloader is locked

Re: Malicious apps infect 25M Android devices with 'Agent Smith' malware

#220

Earlier quoted context omitted.

You can replace the battery by going to an apple store, giving them $49, and then picking it up a few hours later. That's not a terrific challenge.

What if you don't live near an apple store? Why not let the user manage their own battery, that is also not a terrific challenge.

How far do you live from an Apple store?

How far do you live from a phone repair store?

Stop concern-trolling just because you're a snowflake who wants every phone to be bulkier, heavier, and have a few more failure modes.

Post reply on HN