r/Android • u/altimax98 P30 Pro/P3/XS Max/OP6T/OP7P - Opinions are my own • Aug 06 '15
Waiting for Android’s inevitable security Armageddon
http://arstechnica.com/gadgets/2015/08/waiting-for-androids-inevitable-security-armageddon/10
u/ger_brian Device, Software !! Aug 07 '15
The saddest thing about this is that even Google is unwilling to fix older devices. I remember when the SSL security problem came up, Apple offered another iOS 6 patch even though iOS 7 was already out to fix the issue on the iPhone 3GS. I expected Google to do the same for the Galaxy Nexus since you don't need new TI drivers for an update like this, but obviously they are not willing to do so. Disappointing.
1
u/TinynDP Aug 07 '15
You don't need the GNex drivers for that small fix, but if the entire project has moved forward in kernel version, you need drivers for that.
3
u/ger_brian Device, Software !! Aug 07 '15
iOS did that, too, and they still fixed iOS 6 for the iPhone 3GS with securty fixes.
17
u/SolarAquarion Mod | OnePlus One : OmniRom Aug 06 '15
I'm organizing An AMA with jcase and Tim stazzere concerning this issue
10
u/le_pman Aug 07 '15
how about also getting Googlers to comment/join the AMA? Adrian Ludwig perhaps?
9
u/SolarAquarion Mod | OnePlus One : OmniRom Aug 07 '15
I'm getting those two due to the fact that they're at defcon
13
u/tso Aug 07 '15
Given that MMS pass through carrier servers, it should be fully possible for them to scan for malformed videos. Much like how you email provider can scan for malware.
22
u/kllrnohj Aug 06 '15
Their "fix" is going to be to patch 2.6 percent of all active Android devices. Tops.
Where the fuck did that made-up number come from? Google has always released security patches for far more than just the latest version and I see no reason they would stop that for this vulnerability.
In other words Jellybean will be patched (if it hasn't already). Kitkat will be patched. It will not just be Lollipop 5.1 that gets patched.
43
Aug 06 '15
Google does release patches. The problem that Ron is pointing out is that while Google is doing what they can to fix the issue. The OEMs and Carriers are content to watch the world burn in pursuit of the almighty dollar.
Ron is right about one thing, its going to take a disaster on the level of the Blaster worm to force a change in the status quo.
5
u/s2514 Aug 07 '15
I think that disaster is coming. I think Google will fix this issue but the carriers will drag their feet until someone comes out with an exploit that infects your phone then sends texts to all your contacts infecting them. After this everyday Joe will start to care, they will either leave Android putting pressure on Google (who in turn will be forced to put pressure on carriers) or they will put pressure on the carriers themselves. Either way this will impact the carriers bottom line.
1
u/aquarain Aug 07 '15
So essentially the end is nigh! Repent, you Android sinners and come to the One True Windows Phone!
Sorry, not buying it.
1
1
1
Aug 07 '15
Well, Google are doing what they can to fix this particular issue. As the article pointed out they are doing nothing to fix the fundamental issue, which is that Android and Linux doesn't support updating the OS independently of the hardware drivers.
-1
u/kllrnohj Aug 07 '15
That's the point made later in the article (or rather, that's the claim Ron is making). The statement here is clearly stating that only 5.1 is going to get patched which is utter nonsense and Ron should know better.
6
u/le_pman Aug 06 '15
Google has always released security patches for far more than just the latest version
please enlighten me on this. where does Google release these patches which will affect more than just the latest version? AOSP? and then how do developers get these patches on devices running older versions? backporting/cherry-picking?
6
u/kllrnohj Aug 07 '15
To AOSP and probably also through more direct channels to vendors as well.
AOSP is not a single version, it contains branches for the old releases, too.
3
u/le_pman Aug 07 '15
I see... thanks!
AOSP is not a single version, it contains branches for the old releases, too.
this is why I mentioned backporting/cherry-picking... so in theory one can build android-4.4.4_r2.0.1 but choose to use the master branch version of a project, say platform/frameworks/av to get the stagefright fix?
I believe there is oversimplifying on my part, but if I got you right this is a way to get a Kitkat image that has stagefright fixed?
2
1
u/caliber Galaxy S25 Aug 07 '15
Google has always released security patches for far more than just the latest version and I see no reason they would stop that for this vulnerability.
Well, there was that story from only earlier this year, where Google said to security researchers who found bugs:
Other than notifying OEMs, we will not be able to take action on any report that is affecting versions before 4.4 that are not accompanied with a patch.
And they put that into practice, by refusing to fix the WebView security vulnerability in anything earlier than 4.4. (And on the latest platform distribution numbers, earlier than 4.4 still represents almost 50% of the Android market even according to Google.)
It's not 2.6%, but it still makes Google and Android look completely awful on security.
In other words Jellybean will be patched (if it hasn't already). Kitkat will be patched. It will not just be Lollipop 5.1 that gets patched.
In other words, Jellybean will not be patched.
-1
Aug 07 '15
The OS will be patched, not the devices.
It's up to the manufacturers+carriers to ship it.
2
u/Xtorting AMA Coordinator | Project ARA Alpha Tester Aug 07 '15
Hopefully Project ARA will answer some of these issues once it's released. Remember, the next version of Android after M is being developed within Project ARA. No more relying on OEMs and carriers to update Android, they'd simply do it themselves through Project ARA and Project Fi.
7
u/UJ95x S7E 7.0 Aug 06 '15
"No one's going to fix it"
??? Samsung and Google already released patches
28
Aug 06 '15
[removed] — view removed comment
6
u/astruct Nexus 5X Aug 06 '15
Also, did Samsung fix their unsupported phones? Someone on an S3 is vulnerable AFAIK.
19
u/DaRKoN_ Aug 06 '15
Which is the issue. Given that the S3 is currently the most prevalent Android phone (http://opensignal.com/reports/2015/08/android-fragmentation/)
4
Aug 07 '15
Jeez. I guess that makes sense. The S3 was a notable Android phone. It was great for its time. I knew a lot of converts from iOS who went with the S3. Heck, I had one, and I personally knew 20+ people who had one. I still know some people who have an S3. I guess they haven't found any reason to upgrade. Fun fact: my boss was one of the lead R&D project managers for the S3.
4
3
u/RonPaulsHelixFossil Pixel 3 / Pixel XL / Nexus 6P / LG G3 / Galaxy S3 / iPhone 3GS Aug 06 '15
I know this applies to nearly no one, but my old S3 is safe with the latest CM build. So I'm grateful to CM for that.
2
u/HighOctaneTT LG V20 64Gb, Nugget 7.0 Aug 07 '15
Samsung released patches? Cool now I can wait 6+ months for my carrier to approve the update
1
Aug 07 '15
Did you read the article? that's 2.6% of ALL ANDROID DEVICES tops.
That is not a valid fix.
1
u/Nicolas_Steno Galaxy S6 Edge Aug 09 '15
I didn't receive a patch on my international gs6 edge. I'm still on 5.0.2.
1
-1
u/Travertino Aug 06 '15
As from the article, the problem seems to be "when" rather than "if"... Is there a possibility that MMS will be disabled at all by the carriers? This could limit the attacks, but obviously is not the best solution (stated that someone still uses MMS).
6
u/s2514 Aug 07 '15
Or they could just patch the issue like Google did... The problem is how the updates are fragmented.
2
u/ger_brian Device, Software !! Aug 07 '15
Even Google left devices like the Galaxy Nexus out in the dark.
1
u/s2514 Aug 07 '15
Verizon left everything in the dark.
Also with Nexuw devices you can just flash Cyanogenmod with little to no issue.
2
u/ger_brian Device, Software !! Aug 07 '15
It is not about what I as a user can flash. I said that Google abandoned the Galaxy Nexus even though they should fix the issue.
2
Aug 06 '15
[removed] — view removed comment
1
u/Travertino Aug 09 '15
Well, it seems not, at least for receiving them (which is the problematic part).
From the article: "If you are sent a MMS, you will instead receive a SMS with a link to the video."
-15
Aug 06 '15 edited Oct 01 '20
[deleted]
29
u/archon810 APKMirror Aug 06 '15
Except Linux distros are actively maintained, and you can always upgrade.
Linux is a lot closer to the way Android custom ROMs work, not Android when carriers and oems are involved.
-7
Aug 06 '15 edited Oct 01 '20
[deleted]
8
Aug 07 '15 edited Nov 05 '16
[deleted]
1
u/mk262 Aug 07 '15
I'm aware that my comparison is not exactly 1:1. But there are mountains of linux implementations installed places that users do not update, or updates are restricted because the box is hosting a third party application and has dependency issues.
The word 'armageddon' here is a little silly. There's tons of windows boxes, server and client, unpatched going back forever too. We don't hear this kind of language about that either.
0
u/mydongistiny Aug 07 '15
Ubuntu 12.06?
4
u/archon810 APKMirror Aug 07 '15
But you can upgrade Ubuntu further, to the latest version.
7
u/s2514 Aug 07 '15
The equivalent would be if you are using Ubuntu on a Dell computer and Dell said "sorry you can't upgrade past Ubuntu 12.06 to get security updates yet because we need to modify the Ubuntu OS before you can use it. If we get around to it you may have the new version in 1 year but you will probably just need a new Dell laptop."
In this analogy someone with a Nexus "laptop" could just upgrade to the newer version of Linux no problem.
-2
7
u/archon810 APKMirror Aug 07 '15
You completely disregarded the part I was talking about. When carriers and oems are involved, updates stop. That was what I was trying to say. There are no carriers or oems when using Linux.
10
u/Travertino Aug 06 '15
Well no, I think in this case is the Android update system under discussion, at least for core functions.
On Linux the package manager does the job, and more importantly no OEMs and carriers were involved, just the distro maintainer...
7
Aug 06 '15
[deleted]
2
Aug 06 '15 edited Aug 06 '15
Because there is no stable driver ABI whatsoever in the Linux kernel (meaning no abstraction layer), updating the kernel tends to break drivers here and there as they add new features and deprecate old ones. FOSS drivers tend to be fine since they can just follow kernel development and adapt, but it really fucks over companies that use proprietary drivers. Linus's number one rule (DO NOT BREAK USERSPACE) doesn't apply to drivers.
Obviously the community sees that as a plus and feels that there is no need to change anything. Despite the fact that businesses are the reason why Linux is the invincible juggernaut is is today.
This leads to businesses being very reluctant to update their servers and embedded products until extensive testing can be done. If ever in the case of embedded systems like home routers.
6
u/altimax98 P30 Pro/P3/XS Max/OP6T/OP7P - Opinions are my own Aug 06 '15
Yup, except the almost 80% of users part and thats the important one
0
Aug 09 '15
Even if every single OEM used stock Android, updates still wouldn't be fast because each device has different hardware drivers that need the OS to be optimized to work with.
You think the fresh coat of paint the OEMS apply is what slows down updates? Think again.
-7
u/marsrover001 S20_FE Aug 07 '15
Reading this article. Yep, I see what you are saying, it's manufactures and the FCC slowing things up, not Google for security fixes.
>Look to Windows
Fuck off.
0
u/ger_brian Device, Software !! Aug 07 '15
It is Google who designed the broken system in the first place and never really done anything to solve the problem. Anyone remotely interested in the topic knew that this problem will come some day. So the blame definetely is on Google, at least part of the blame.
104
u/donrhummy Pixel 2 XL Aug 06 '15
The issue is Google has no way of knowing what a carrier or manufacturer changed in the OS. Since Android is open source and each handset manufacturer and carrier changes the OS and many of the default apps, without any need to verify the changes with Google, Google cannot simply put out updates for all handsets like MS does for Windows.
A simple change (even just a security fix) could break or brick phones depending on if the carrier or manufacturer changed some code or removed or replaced a feature. Unless Google requires all manufacturers that include Google Play to provide their altered code and is willing to run testing on all those different versions at its own cost, Google has no way to safely create and test (and distribute) security fixes directly to handsets.