Live data from Hacker News

Blueborne – A new attack vector endangering major operating systems

armis.com

1–10 of 34 posts

Re: Blueborne – A new attack vector endangering major operating systems

#3
Am I missing something? The first line says: "Armis Labs revealed a new attack vector endangering major mobile, desktop, and IoT operating systems, including Android, iOS, Windows, and Linux, and the devices using them."

Why is the title singling out Linux? Reading through the rest of it, it seems like this is on pretty much everything.

Re: Blueborne – A new attack vector endangering major operating systems

#4
post #2

This looks very scary, especially given how many Android devices are out there that receive few or no security updates.

Agreed. And just checked - my Samsung Galaxy S8 is vulnerable, no update available. Thanks Samsung!

This one will get nasty...

Re: Blueborne – A new attack vector endangering major operating systems

#5
post #4
post #2

This looks very scary, especially given how many Android devices are out there that receive few or no security updates.

Agreed. And just checked - my Samsung Galaxy S8 is vulnerable, no update available. Thanks Samsung! This one will get nasty...

Well, I've been meaning to root mine and flash crDroid... This is certainly the final push.

They state 10% of all Android devices are vulnerable and won't get patches, and since the vulnearbility is arguably wormable I can't see how these devices will stay clean.

Re: Blueborne – A new attack vector endangering major operating systems

#6
Title is inaccurate, Windows, Linux and macOS are all affected.

> Microsoft is issuing security patches to all supported Windows versions at 10 AM, Tuesday, September 12.

> Information on Linux updates will be provided as soon as they are live.

> All iPhone, iPad and iPod touch devices with iOS 9.3.5 and lower, and AppleTV devices with version 7.2.2 and lower are affected by the remote code execution vulnerability. This vulnerability was already mitigated by Apple in iOS 10, so no new patch is needed to mitigate it. We recommend you upgrade to the latest iOS or tvOS available.

Re: Blueborne – A new attack vector endangering major operating systems

#7
post #3

Am I missing something? The first line says: "Armis Labs revealed a new attack vector endangering major mobile, desktop, and IoT operating systems, including Android, iOS, Windows, and Linux, and the devices using them." Why is the title singling out Linux? Reading through the rest of it, it seems like this is on pretty much everything.

Windows was patched in July. Google has provided a patch for Android. Therefore, Linux is the only one left to make an announcement.

Re: Blueborne – A new attack vector endangering major operating systems

#8
post #4

Earlier quoted context omitted.

Agreed. And just checked - my Samsung Galaxy S8 is vulnerable, no update available. Thanks Samsung! This one will get nasty...

Well, I've been meaning to root mine and flash crDroid... This is certainly the final push. They state 10% of all Android devices are vulnerable and won't get patches, and since the vulnearbility is arguably wormable I can't see how these devices will stay clean.

Does keeping the BlueTooth radio turned off help here?

Re: Blueborne – A new attack vector endangering major operating systems

#9
Is there an exploit that works on systems with stack canaries? If not, then sensible Linux devices (which may well be a small minority) are not so severely affected.

I'm more worried about higher value targets like cars and things like lightbulbs that never get updated. This could be an amazing wormable bug.

Post reply on HN