Live data from Hacker News

Latest Android phones hijacked with one-shot Chrome exploit

theregister.co.uk

41–46 of 46 posts

Re: Latest Android phones hijacked with one-shot Chrome exploit

#41

Am I alone being amazed that we still have not experienced an Android worm or virus shutting down all mobile networks globally for a few days? I remember Slammer, which brought down many corporate networks and severely impacted all internet traffic. With all these unpatched phones and so many vulnerabilities it seems a matter of time before something like this happens on a grander scale in mobile networks. Would it b…

I think it makes sense. Let's pretend that I find an iOS exploit. I can brick 50% of Apple devices or I can sell it for a million dollars. I'd rather be a millionaire than risk prison.

Re: Latest Android phones hijacked with one-shot Chrome exploit

#42
post #18

This is why you should use Firefox for Android: it's a great browser (even offering extensions such as uBlock Origin), but it has very little marketshare and is thus unlikely to be attacked. This is also part of the reason a frequently updated Android distribution (Nexus or CyanogenMod) might in fact be more secure than iOS, where you are forced to be vulnerable to Apple's Webkit engine. The same reasoning also appli…

[deleted]

Re: Latest Android phones hijacked with one-shot Chrome exploit

#43

Happy Android and Firefox user calling in. My Nexus is still safe :)

What is the logic to responding to security disclosures like this? In the reddit world this is called shit posting. Security bug A affects product B (or c-f) someone always responds at least I use g or h on z! Thus, I am immune from this particular security issue! Genuinely interested in why anyone bothers posting this non-sense.

Re: Latest Android phones hijacked with one-shot Chrome exploit

#44
post #43

Happy Android and Firefox user calling in. My Nexus is still safe :)

What is the logic to responding to security disclosures like this? In the reddit world this is called shit posting. Security bug A affects product B (or c-f) someone always responds at least I use g or h on z! Thus, I am immune from this particular security issue! Genuinely interested in why anyone bothers posting this non-sense.

It may come off as shit-posting, but I decided to reply as I did to highlight something important:

On Android anyone can implement a browser, have users download it, and make it the system default. On Android you don't need to end up with a Google monoculture, like you on iOS do have to accept the Apple monoculture.

The bug report says "all Android devices affected", which is factually incorrect. Mine never was, because mine never ran Chrome in the first place. And this was a Chrome bug.

On Android users have a choice. Whoever wrote this article does not seem understand that, nor the implications of it.

Thus my post. Does that sound more reasonable?

Re: Latest Android phones hijacked with one-shot Chrome exploit

#45
post #43

Earlier quoted context omitted.

What is the logic to responding to security disclosures like this? In the reddit world this is called shit posting. Security bug A affects product B (or c-f) someone always responds at least I use g or h on z! Thus, I am immune from this particular security issue! Genuinely interested in why anyone bothers posting this non-sense.

It may come off as shit-posting, but I decided to reply as I did to highlight something important: On Android anyone can implement a browser, have users download it, and make it the system default. On Android you don't need to end up with a Google monoculture, like you on iOS do have to accept the Apple monoculture. The bug report says "all Android devices affected", which is factually incorrect. Mine never was, beca…

Can you cite "all Android devices affected"? Cannot find this particular quote in this or any other article. Also what bug report? I found this article and other articles cited, but no bug report from Google or the researcher as of yet.

The article does state "The vuln being in recent version of Chrome should work on all Android phones;" which is factually correct.

This is a "Chrome" bug in so much as the Chrome browser uses the V8 Javascript engine. However, this particular bug could have other consequences as it is stated in this article and others that the bug in fact occurs in the V8 Javascript Engine which is used in Nodejs, Mongo and others.

So, no, none of your comments sound reasonable.

Re: Latest Android phones hijacked with one-shot Chrome exploit

#46
post #35

Earlier quoted context omitted.

Do you know people who actually do this? I'm deeply uncomfortable when I get a new phone that doesn't have a CM / custom ROM out yet, because I need to be able to lock everything down myself. I assumed other tech literates did the same.

Really? I am the exact opposite. Few years ago I would always run a custom firmware on my android phone, now I wouldn't touch a rooted phone with a bargepole. Mostly because none of my bank apps work on rooted phones, but also because CM was always an unstable affair for me - fantastic at the beginning, more and more annoying the longer I use it. The "customization"(which I used once to change some icons) is simply n…

you run your devices without any care for all the background datamining, constant analytics, access to your PII, facebook social graph etc.? you oughta'be ashamed of yourself.
Post reply on HN