Live data from Hacker News

Google confirms Android attacks; no fix for most Samsung users

forbes.com

91–100 of 177 posts

Re: Google confirms Android attacks; no fix for most Samsung users

#91
post #89
post #68

Never mind the December security patches, Samsung haven't even released the November patches yet, the ones for the critical severity RCE. Unless you have a "major flagship model" [1], because apparently only the richest users deserve to be secure. [1] https://security.samsungmobile.com/securityUpdate.smsb

Samsung for the longest time was releasing updates way too late, and what they were releasing monthly was old patches. Buying a device directly from Samsung may be different, but the manufacturer still has to usually convert the pure android update to their branch. Still, trying to find a pure android phone is important. More manufacturers used to make them. Example: https://www.androidauthority.com/best-smartphones-…

> pure android phone

Do these even exist? Last phones I'm aware about were Android One program, but it ended years ago.

The link suggests Google Pixel, but it's not pure android phone, it's full of Google junk software.

Re: Google confirms Android attacks; no fix for most Samsung users

#92
post #69

Earlier quoted context omitted.

> Being reliant on the hardware manufacturer (or network operator?) for OS updates is the crazy world we live in. Being reliant on a single OS permanently nailed to the hardware is no less crazier. I'd like to be able to install another OS on a vulnerable device, it would help tremendously and not only with the security of that specific device. Now I've got some expensive paperweights that I can't even use as such be…

If you are buying now, you want a device on a v5 Linux kernel with BPF support, where the bootloader can be unlocked and VoLTE is implemented in the 3rd-party ROM. LineageOS has a build roster of current devices at this URL: https://lineageos.org/Changelog-30/ The Pixels are the most flexible, but don't buy a model from Verizon (they don't allow unlocked bootloaders). Most other OEMs require you to generate an unlock…

Unfortunately, even with the best after-market support, banking apps and/or contactless payments becomes a cat-and-mouse game, that, even if it works, can stop working at the drop of a hat.

Re: Google confirms Android attacks; no fix for most Samsung users

#93
post #76

Earlier quoted context omitted.

That's always the case, even on Windows, even on Linux for closed-source third party drivers. The only exception is macOS because Apple insists on writing the drivers themselves - that was, in addition to Soldergate, the reason why Apple dropped NVIDIA.

Are apples drivers open source?

No. Which is why "the only exception is macOS" is also false. At some point Apple drops support for that model and then that hardware not only gets no more driver updates, because the whole system is tied to the rest of it, it gets no more updates at all.

So the only exception is systems with open source drivers. Those are basically supported as long as the hardware architecture is and enthusiasts even have the option of adding support themselves. You can install the latest version of many Linux distributions on the first generation of x86-64 hardware from 2003 and some on 32-bit PC hardware going back to the 1980s.

It should literally be a crime that you can't do the same thing on a five year old phone.

Re: Google confirms Android attacks; no fix for most Samsung users

#94
post #5

No fix yet for Samsung. Being reliant on the hardware manufacturer (or network operator?) for OS updates is the crazy world we live in.

> Being reliant on the hardware manufacturer (or network operator?) for OS updates is the crazy world we live in. Being reliant on a single OS permanently nailed to the hardware is no less crazier. I'd like to be able to install another OS on a vulnerable device, it would help tremendously and not only with the security of that specific device. Now I've got some expensive paperweights that I can't even use as such be…

> Being reliant on a single OS permanently nailed to the hardware is no less crazier.

Locking OS upgrades to a network vendor is substantially crazier. It creates pockets where the hardware vendor ships a security update but your network doesn't care to ship it and isn't incented to. It is BANANAS.

Re: Google confirms Android attacks; no fix for most Samsung users

#95
post #68

Never mind the December security patches, Samsung haven't even released the November patches yet, the ones for the critical severity RCE. Unless you have a "major flagship model" [1], because apparently only the richest users deserve to be secure. [1] https://security.samsungmobile.com/securityUpdate.smsb

Google Pixel 7 and Pixel 7 Pro are still stuck on the October patches.

Pixel 6a used to show a September patch as the latest, but tapping "check for updates" found a new one. As mentioned in other comments here, apparently tapping those buttons twice may help.

Re: Google confirms Android attacks; no fix for most Samsung users

#96

Earlier quoted context omitted.

It comes from the surname of a German botanist. Which just happens to mean "fox". Never had problems with it. It would probably help if you pronounced it right, with a /ks/.

The beginning of the English word "fuchsia" is not pronounced like the German word Fuchs, so indeed the spelling does not match the pronunciation. This is independent of the fact that it comes from that word. Plenty of things in English (and, in fact, loanwords in every language) sound different from the words they're derived from; that doesn't mean trying to imitate the source language is the "right" pronunciation.…

> If you pronounce fuchsia like "fuksia" nobody will understand you.

TIL and yet another case of "English is fucking weird".

Re: Google confirms Android attacks; no fix for most Samsung users

#97
post #69

Earlier quoted context omitted.

If you are buying now, you want a device on a v5 Linux kernel with BPF support, where the bootloader can be unlocked and VoLTE is implemented in the 3rd-party ROM. LineageOS has a build roster of current devices at this URL: https://lineageos.org/Changelog-30/ The Pixels are the most flexible, but don't buy a model from Verizon (they don't allow unlocked bootloaders). Most other OEMs require you to generate an unlock…

Unfortunately, even with the best after-market support, banking apps and/or contactless payments becomes a cat-and-mouse game, that, even if it works, can stop working at the drop of a hat.

I can tell you that Wells Fargo works both on Lineage with Mind the Gapps, and Graphene with the Play store installed. I have it on my OnePlus 5 and Pixel 6a.

I understand that most U.S. banking apps work on Graphene.

As far as contactless payments, try a Pixel watch. I understand that it is entirely separate from the phone.

Re: Google confirms Android attacks; no fix for most Samsung users

#98
post #68

Never mind the December security patches, Samsung haven't even released the November patches yet, the ones for the critical severity RCE. Unless you have a "major flagship model" [1], because apparently only the richest users deserve to be secure. [1] https://security.samsungmobile.com/securityUpdate.smsb

Why would you want security, if you get 'play integrity' for phones that received no updates since 2 years. Google's current security practices are more than dubious IMHO. Now they are not releasing any source for security patches for 3 month, to 'protect' vendors that are too slow updating. As if there is no chance for bad actors to reverse engineer those patch sets.

Re: Google confirms Android attacks; no fix for most Samsung users

#99
post #68

Never mind the December security patches, Samsung haven't even released the November patches yet, the ones for the critical severity RCE. Unless you have a "major flagship model" [1], because apparently only the richest users deserve to be secure. [1] https://security.samsungmobile.com/securityUpdate.smsb

Google Pixel 7 and Pixel 7 Pro are still stuck on the October patches.

My 7 is on the December one.

Re: Google confirms Android attacks; no fix for most Samsung users

#100
post #45

Earlier quoted context omitted.

I think your carrier hasn't approved it yet. T-mobile seems to lag on these things. I also can't seem to find a system update. A Google Play system update does seem to exist

We have an OS security update that is only release to users of a specific hardware, once approved by their mobile operator. It may be added to vendor-specific OS versions some time later (weeks, month or never). The vendor-specific may not be approved by a telco if the vendor doesn't have a relationship with that telco. Now think that millions of people use the same OS on many different flavours, on different hardwar…

I never understood why a mobile operator has any say in when to apply security patches?

Does it happen with iPhones?

Post reply on HN