Live data from Hacker News

Samsung's Tizen is riddled with security flaws, amateurishly written

arstechnica.com

41–50 of 69 posts

Re: Samsung's Tizen is riddled with security flaws, amateurishly written

#41
post #19

Is it that big industrial corporations are bad at creating code? Toyota, samsung, synaptic. I'm really beggining to think that code should be left to smaller and medium sized outfits. i.e samsung should buy or hire a small startup to independently develop and grow their next ecosystem. Large enterprises just seem too clumsy pull pull it off unless they wholly dedicate themselves to developing that one piece of techno…

Hardware manufacturers have always been bad at writing software. Especially in certain Far East cultures where software engineering is traditionally not even considered "real engineering".

Re: Samsung's Tizen is riddled with security flaws, amateurishly written

#44
post #14
post #7

Should not come as a surprise... https://what.thedailywtf.com/topic/15687/code-review-maledic... https://what.thedailywtf.com/topic/15001/enlightened

> https://what.thedailywtf.com/topic/15001/enlightened Actually it's the author of the rant that comes of as totally uninformed and with unwarranted snark to boot. https://what.thedailywtf.com/topic/15001/enlightened/242

As bad as the author comes off in that exchange, Mr. Haitzler comes off worse. Nobody should respond to their customers like that, least of all in a public forum, regardless of the provocation.

Re: Samsung's Tizen is riddled with security flaws, amateurishly written

#45
post #24
post #14

Earlier quoted context omitted.

> https://what.thedailywtf.com/topic/15001/enlightened Actually it's the author of the rant that comes of as totally uninformed and with unwarranted snark to boot. https://what.thedailywtf.com/topic/15001/enlightened/242

Not when I read the replies to that reply. @Carsten_Haitzler said: as for the "you bitch" comment. that does not appear anywhere inside efl at asll. i can only assume you are full of bullshit here as with a lot of the prior "facts" you have disclosed, as a grep through our codebase for efl and elementary shows no such string: core/efl.git - EFL core libraries evas - change error out from bitch to complain - cosmetic…

[deleted]

Re: Samsung's Tizen is riddled with security flaws, amateurishly written

#46

I'm very tempted to buy a Samsung TV (primarily for the the low input lag times which makes them good for gaming) and I plan to keep it offline (no WiFi or Ethernet connection), using a Chromecast and a HTPC+Kodi instead for streaming. With that in mind, should I be worried about security flaws?

Depends on your threat model.

From TFA: Another attack on Samsung Smart TVs was published last week that used malicious commands embedded in broadcast TV signals.

So, even if it's airgapped, a tv that's been compromised in this way is effectively a hostile general-purpose computer with a wifi card running inside your house.

If this is something you would do for a Klondike bar, then go ahead. I'll keep my dumb TV and my Kodi box, though.

Re: Samsung's Tizen is riddled with security flaws, amateurishly written

#47
post #14

Earlier quoted context omitted.

> https://what.thedailywtf.com/topic/15001/enlightened Actually it's the author of the rant that comes of as totally uninformed and with unwarranted snark to boot. https://what.thedailywtf.com/topic/15001/enlightened/242

As bad as the author comes off in that exchange, Mr. Haitzler comes off worse. Nobody should respond to their customers like that, least of all in a public forum, regardless of the provocation.

EFL is open source software, BSD licenced. The original author of the comment is not a customer. It's some uninformed person trashing the good work someone has made available to them for free. This attitude makes me want to stop writing open source, it's disgusting to see.

Re: Samsung's Tizen is riddled with security flaws, amateurishly written

#48

I'm very tempted to buy a Samsung TV (primarily for the the low input lag times which makes them good for gaming) and I plan to keep it offline (no WiFi or Ethernet connection), using a Chromecast and a HTPC+Kodi instead for streaming. With that in mind, should I be worried about security flaws?

Depends on your threat model. From TFA: Another attack on Samsung Smart TVs was published last week that used malicious commands embedded in broadcast TV signals. So, even if it's airgapped, a tv that's been compromised in this way is effectively a hostile general-purpose computer with a wifi card running inside your house. If this is something you would do for a Klondike bar, then go ahead. I'll keep my dumb TV and…

Agreed. These "smart" TVs mostly run outdated and buggy software which are difficult if not impossible to update either because of technical limitations or because the manufacturer doesn't care enough after getting your money.

So why bother with a "smart" TV if you're going to be using an external computer anyway. Saving a few hundred dollars to spend on that external computer seems like a better investment. I run a "dumb" big LG TV hooked up to a raspberry pi running Kodi via LibreElec. I'm very happy with the set up in terms of functionality and price.

Edit: the attack via signal is linked from the article, reading now.

Re: Samsung's Tizen is riddled with security flaws, amateurishly written

#49

I can't believe there are still string overflow bugs. Might be a good idea to invest sometime in Rust. On a side note, I have been looking for a good doc on how I can slowly migrate my existing code base step-by-step to Rust. A total rewrite is out of question, we would rather ship our product step by step. Does anyone know of such a doc?

https://github.com/carols10cents/rust-out-your-c-talk http://blog.adamperry.me/rust/2016/06/11/baby-steps-porting-...

Thanks!

Re: Samsung's Tizen is riddled with security flaws, amateurishly written

#50
post #13

Earlier quoted context omitted.

...Yes? I mean, Samsung is a big enough company with big enough profits to attract talented candidates and also be selective: https://www.quora.com/How-would-you-prepare-for-the-Samsung-... Furthermore, their mobile business is mature and well-known enough that even if they were staffed with complete amateurs whose legacy code was awful, Samsung has been a prominent player for a long time in terms of tech-biz-years.…

Maybe then security is less to do with individuals and more so company culture ?

I would think that's pretty obvious but I guess not.
Post reply on HN