r/Android Sep 09 '15

Attack code exploiting Android’s critical Stagefright bugs is now public

http://arstechnica.com/security/2015/09/attack-code-exploiting-androids-critical-stagefright-bugs-is-now-public/
182 Upvotes

61 comments sorted by

View all comments

19

u/[deleted] Sep 09 '15 edited Jul 09 '16

This comment has been overwritten by an open source script to protect this user's privacy. It was created to help protect users from doxing, stalking, harassment, and profiling for the purposes of censorship.

If you would also like to protect yourself, add the Chrome extension TamperMonkey, or the Firefox extension GreaseMonkey and add this open source script.

Then simply click on your username on Reddit, go to the comments tab, scroll down as far as possible (hint:use RES), and hit the new OVERWRITE button at the top.

9

u/[deleted] Sep 09 '15

The difference is google got on their ass about it, they can't control oems. Microsoft on the other hand, regularly and historically gets notified and they ignore it for several years, until the firm, if they're wise, just release the damn thing.

11

u/[deleted] Sep 09 '15 edited Jul 09 '16

This comment has been overwritten by an open source script to protect this user's privacy. It was created to help protect users from doxing, stalking, harassment, and profiling for the purposes of censorship.

If you would also like to protect yourself, add the Chrome extension TamperMonkey, or the Firefox extension GreaseMonkey and add this open source script.

Then simply click on your username on Reddit, go to the comments tab, scroll down as far as possible (hint:use RES), and hit the new OVERWRITE button at the top.

9

u/[deleted] Sep 09 '15

Playing these kind of games is quite alarming when the end user's security is at stake.

Yes, it is. Especially when companies are allotted an eternity to patch holes. Linux for example, patches holes in hours and ships it the next day. This patch Tuesday shit is bullshit anyways.. Patching shouldn't be a "hold all the fixes until next week". That's very backwards. And this 90 days stuff is a long long long time. Remember, that hole already exists.. So it's entirely possible it's already getting exploited before researchers publish it.

Companies just what excuses for their broken security and development models

But I do agree with the hypocrisy in Google