Slashdot Mirror


Samsung Decides Not To Patch Kernel Vulnerabilities In Some S4 Smartphones

An anonymous reader writes: QuarksLAB, a security research company, has stumbled upon two kernel vulnerabilities for Samsung Galaxy S4 devices, which Samsung has decided to patch only for recent devices running Android Lollipop, but not Jelly Bean or KitKat. The two vulnerabilities (kernel memory disclosure and kernel memory corruption) were discovered in February 2014 and reported to Samsung in August 2014, affecting the samsung_extdisp driver of Samsung S4 (GT-I9500) devices. Bugs break ASLR and lead to denial of service (DoS) state or even elevating attacker privileges.

16 of 144 comments (clear)

  1. The new normal for Android by Anonymous Coward · · Score: 3, Informative

    The number of exploits is increasing exponentially but the vendors are scaling back security patches across the board.

    MBA's FTW.

    1. Re:The new normal for Android by sexconker · · Score: 3, Insightful

      Yup, Android is no longer a platform I can recommend.
      Of course, iOS isn't either, and MS burned all bridges with Windows 10, so fuck it, I'm not buying any shit from you assholes anymore.

    2. Re:The new normal for Android by AK+Marc · · Score: 3, Interesting

      Android is safer if you root it and abandon the official versions. TouchWiz isn't that good anyway. Every other maker's UI is better than TouchWiz. My S3 was abandoned on an old version of Android, but I'd have to go boot it to see what. So Samsung has a habit of abandoning older generations. And iOS isn't any better, with less than 1 year support for my 3G, about the same as I got on my S3.

      Android has the slight edge, because I can root it and go with a generic, or use a maker like Oppo with weekly OS updates, if you want to update that often.

    3. Re: The new normal for Android by drinkypoo · · Score: 3, Interesting

      Great if CM support your phone. I've got a Note 2 and there's been no new milestone for a year. In any case isn't this a bug in the Samsung drivers so I'm not sure how CM would be able to fix this one.

      Forget CM, go to XDA and look for other ROMs for your phone. Based on a quick glance over the appropriate forum, I suggest Resurrection Remix. Yeah, the names of these things are ridiculous. I'm running something called "KatKiss" on my Asus Transformer Prime. You can have it with a choice of three kernels, two without fsync (internal flash is abysmally slow) and one with. I am using the one with because data is more important to me than a couple more frames per second.

      --
      "You're right," Fisheye says. "I should have set it on 'whip' or 'chop.'"
    4. Re:The new normal for Android by Lumpy · · Score: 2

      Arduino phone....

      http://www.instructables.com/i...

      If you control the source.... you control the spice....

      --
      Do not look at laser with remaining good eye.
    5. Re:The new normal for Android by scsirob · · Score: 2

      Yup, this really p*sses me off. I have recently bought a Samsung S5 Mini Duos. It runs Android 4.4.2. Samsung refuses to release an update for my phone even though it is less than 6 months old and the device itself was released less than one year ago.

      --
      To Terminate, or not to Terminate, that's the question - SCSIROB
  2. Re:Samsung != Apple by AK+Marc · · Score: 2

    Apple doesn't either. I bought a 3G at about the end of its sale, and got one year support.

  3. Why aren't there lawsuits over this? by Rainbow+Nerds · · Score: 4, Insightful

    I don't understand why phone manufacturers and carriers don't get sued for things like this. Carriers have typically required two year contracts for phone subsidies, and normally it's possible to buy a phone two years old and get it free. At least that's how it is in the US. That means you can buy a phone that's as much as three years old and have a reasonable expectation to use it for two years because that's the contract with your carrier. That means manufacturers and carriers should provide support for a minimum of five years. That means a phone released in October 2015 should have support until October 2020. I think a customer has a reasonable expectation of this. If nothing else, that should be grounds for a lawsuit against manufacturers and carriers. There's also the issue of delays in fixing vulnerabilities both with the manufacturers and then the carriers. Again, I think there's a reasonable expectation for security updates in a timely manner. Also, when phones ship with locked bootloaders and customers can't choose to unlock them, it makes it very difficult to install a patched version of the OS. This also voids the warranty if you're able to do it. Customers are screwed no matter what they do in this situation, which is why carriers and manufacturers should be sued in the absence of specific laws to protect customers.

    I can't help but wonder if the decision to not provide software updates to older phones is partly because people don't see a huge difference between models and this is one way to push people to buy newer and more expensive phones. I can't say it for certain, but it wouldn't surprise me if that's part of the decision process.

    --
    M-I-Z
    kU still sucks!
    1. Re:Why aren't there lawsuits over this? by Rainbow+Nerds · · Score: 2

      I would argue that this kind of bugs constitute a defective product. Then I could invoke my rights for compensation/repair (at least based on EU law regarding sales of defective products).

      I agree it's a defective product and I started thinking about this after I made my post. My idea was to try to force manufacturers to honor their warranty, which is supposed to protect against defects. Also, because Samsung knew about this vulnerability in August 2014 and continued to sell the Galaxy S4, they're knowingly selling a defective product. That ought to be more serious than simply selling a defective product.

      --
      M-I-Z
      kU still sucks!
  4. Re: It's OK - Android is open! by cyber-vandal · · Score: 3, Insightful

    How do you fix bugs in the proprietary closed source drivers?

  5. Re:What kind of dumbass company... by TheRaven64 · · Score: 4, Interesting

    Mobile phone vendors make their money selling new phones. You want a new Android, get a new phone.

    Sure, but the new phone I get will be from a vendor that I can trust to support it for its lifetime. I may upgrade my phone after 2-3 years, but I'll probably hand the old one off to someone else or use it as a spare. If the phone becomes useless after 1 year, then I'll factor that in when I calculate the value of the phone - if I can amortise the cost over 4 years rather than 2, then the cost of the phone is not as good.

    Your contract will be up in 2 years

    What kind of idiot signs a 2-year phone contract in 2015?

    --
    I am TheRaven on Soylent News
  6. Re:Samsung != Apple by peragrin · · Score: 2

    bullshit.

    Software wise apple supports out to at least 3 years and with iOS 9 out to 5 years of previous build models.

    if you bought a 3 year old phone and then expected updates you got what you deserve.

    Android models rarely get one year of updates, and almost never get 3-5 years of bug fixes.

    --
    i thought once I was found, but it was only a dream.
  7. Re: It's OK - Android is open! by Anne+Thwacks · · Score: 2
    Even those of us whose phones are not directly affected are indirectly at risk. Surely we can join a class action against the people responsible for polluting the phonosphere with pathetically insecure software. If the manufacturer wishes to end support for a phone - he should be required to open source ALL the code, and release ALL hardware documentation. Or face fines that would obliterate the company instantly in each and every country where phones could conceivably work.

    And if a company dies, the IP of all its products go to the official receiver - who should put them in the public domain.

    Everyone with a phone should be entitled to join a class action against any manufacturer who does not provide a way to fix security problems - so long as the phone is capable of operation: ie until physical death of said phone.

    Separately, there ought to be a law preventing sale of undocumented hardware to the general public. If you don't know what it is you own, how do you know it is safe to own it? If the manufacturer prevents you from knowing, surely he takes responsibility for its safety, and should be required to place a bond with the government covering the maximum possible risk (of being sued by all phone owners, everywhere, repeatedly, with the highest legal costs that lawyers can imagine).

    --
    Sent from my ASR33 using ASCII
  8. Article is FUD by the+Hewster · · Score: 3, Informative

    This article makes no sense. It says the vulnerability affects the Galaxy S4 but only if you are running an outdated firmware (like Kit kat). However, there is an official (pushed OTA) update to Jelly Bean on this device, so all you have to do to not be vulnerable is apply the update! Same as usual: if you want to avoid vulnerabilities, update your stuff regularly.

  9. Re:What kind of dumbass company... by Threni · · Score: 2

    > What kind of dumbass company is going to spend money porting a new version of an OS to an old platform,
    > with no payday for doing so?

    Well, that's kind of the point. Companies should be forced to state up front how long the phones are going to be kept up to date (from both a security and Android version point of view) and if they don't they can be sued for breaking the terms under which people bought the phones in the first place.

    No-one expects Microsoft to provide updates for windows xp, but they do expect them for 7, because of the published support timelines. Android needs the same; it's no different just because it's not a desktop or a laptop.

  10. Re:What kind of dumbass company... by jeremyp · · Score: 2

    What kind of dumbass company is going to spend money porting a new version of an OS to an old platform, with no payday for doing so?

    Apple.

    Well, OK there must be a payday. Perhaps they see the fact that you can put the latest iOS onto a 4s as a selling point. i.e. if you splashed the cash for one in 2011 you would feel better knowing that, theoretically, you could still have the latest OS four years later even if unreality you replace it after two years.

    --
    All I want is a secure system where it's easy to do anything I want. Is that too much to ask ~~ Randall Munroe