Old Qualcomm Vulnerability Exposes Android User Data (securityweek.com)
Reader wiredmikey writes: Researchers from FireEye have disclosed the details of a serious information disclosure vulnerability affecting a Qualcomm software package found in hundreds of Android device models (Editor's note: the link could have pop-up ads, here's an alternate source). The vulnerability is in the Qualcomm tethering controller (CVE-2016-2060) and could allow a malicious application to access user information. While the flaw could expose millions of Android devices, the vulnerability has limited impact on devices running Android 4.4 and later, which include significant security enhancements, and also does not affect Nexus devices. FireEye said its researchers informed Qualcomm about the vulnerability in January and the vendor developed a fix by early March and started reaching out to OEMs to let them know about the issue. Now it's up to the device manufacturers to push out the patch to customers.FireEye said: "The OEMs will now need to provide updates for their devices; however, many devices will likely never be patched."
Now it's up to the device manufacturers to push out the patch to customers.
you KNOW that, for the most part, never happens. androids are mostly abandoned after the first year of being on the market. vendors have no reason to care and they don't! they leave us all exposed to the continual android bugs and the ONLY recourse is to root and install a new os or just give in and re-re-re-buy your phone all over again, trading one bug for another.
google is 100% at fault for not seeing this and not stopping it. its a wild wild west in android land and I fucking hate how bad it is. 'just buy a nexus!'. fuck you! google abandons things too; I have a nexus one that I thought would get support but it had showstopper bugs that were there from day-1 and NEVER got fixed (screen calibration would stop every day; google never cared, etc etc).
there are so many reasons to hate google, but how they mistandled the whole android and carrier/vendor thing was one of the worst things they've ever done. and the whole architecture of android prohibits piecemeal upgrades. I can't just apt-get update and upgrade. I can't install JUST an ip stack fix or JUST a kernel fix. I have to upgrade a whole monolithic image and that's just SO STUPID its beyhond belief. linux was not that way and you had to do WORK to fuck up linux that badly. they removed the ability to do user level patching and upgrades and to make things worse, most vendors try their best to STOP users from even TRYING to upgrade their own phones.
people ask me why I don't do phone programming, since I write C code and stuff for a living. my hatred of the whole phone scene is why; its a complete disgrace and I want no part of it. let the 20 somethings mess around with this and that phone; I have no time or patience to keep up with all that crap since its such a moving target.
I really do wish 'phones' were not like they were today, but the market is ruined and I see no way around it since the carriers and vendors are so used to calling all the shots. they'll never give control back to users. it won't happen and so phones will always suck and never be YOUR computer.
--
"It is now safe to switch off your computer."
for the end user, apple was doing the right thing. but not for the right reasons, mind you.
they are control freaks, everyone knows that. they controlled the carriers and having the shiney apple toy was all the carriers wanted; they even gave control over to apple for the pleasure of selling and including apple toys in their network.
google could have done the same thing but they didn't think about it deeply enough and now it seems too late to change the model.
google gets its eyeballs and deploys its apps to spy on you. they are happy. they don't WANT to change the model as it suits their whole business model.
--
"It is now safe to switch off your computer."
for the end user, apple was doing the right thing. but not for the right reasons, mind you.
That is TOTAL conjecture on your part; you have absolutely no way to determine what Apple's "motivation" was.
You just ASSUME it is self-serving and evil. Do you have PROOF?
It is just you. That statement is quite an exaggeration. Just as most of the "vulnerabilities" that are found are. Companies like FireEye and Zimperium exist for situations just like this. They have a team of people scouring available source code looking for any little flaw and then when they find something like this they send out press releases and hype it up as the next big doom and gloom phone destroyer so that people will buy their security app. But, when looking into the details you find that this bug only really affects phones running Android less than 4.4 and on the Qualcomm chipset. Many phones back in that era used a TI chipset instead so that limits the numbers right there. And then, when you look at what it is supposedly capable of you see that the worst it could do under ideal circumstances is to steal SMS and phone call data so it could gather who you call and text. But, just like the infamous StageFright vulnerability there still hasn't been a single documented case of it being exploited in the wild because of all of the other Android security in place to mitigate such risks.
The fact that these old bugs are being found is because of the open source advantage that you mentioned. There is no telling how many vulnerabilities exist in iOS devices because the code is not open for review. This is, of course, good and bad, depending on who happens to stumble across the vulnerability first.
Also, no one who cares anything about security should be using Android older than 4.4 or even 5.0. That is like using Windows XP or even Windows 95 and complaining that it has security vulnerabilities.
Nevermore.
search the concept of 'if it walks like a duck...'
funny that a person with a handle 'macs4all' would AT ALL want to white knight apple. nothing strange about that at all. LOL
--
"It is now safe to switch off your computer."
search the concept of 'if it walks like a duck...'
funny that a person with a handle 'macs4all' would AT ALL want to white knight apple. nothing strange about that at all. LOL
Ooo looky; an ad hominem attack! How terribly original...
More like: The last bastion of the "factless"...
To be fair your nick is essentially "shill for apple". You shouldn't be surprised if people assume that anything you say is a bit biased.
So sez the ANONYMOUS COWARD. Boy, count me IMPRESSED!
;-)
No, you INTERPRET my nick that way.
I meant it as more of a "wish" (as in "I'd like to be able to wave a magic wand and give everyone a Mac") than a "shill" (as in "In my eyes, Apple can do no wrong, and I will defend them to the death, even if I don't believe what I am saying.")
See the difference? Of course you don't; or, more correctly, won't admit it; because you will pretend that there IS no difference.
Am I biased? Of course. Just like the Freetards that overrun Slashdot, and claim that F/OSS is ALWAYS the ONLY way, and that Apple's motives are ALWAYS bad.
Now, isn't that where we came in?
I did not see any mention in the article (I went to the ZDnet one) for how to identify if my devices are compromised and would greatly appreciate any assistance from the lazyweb in methodology for determination.
Leela: "Is all the work done by children?" Alien: "No, not the whipping."