Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Android Stagefright Flaws Put 950 Million Devices at Risk
Threat Post ^ | July 27, 2015 | Michael Mimoso

Posted on 07/27/2015 11:42:33 AM PDT by bkopto

Vulnerabilities discovered in the Stagefright media playback engine that is native to Android devices could be the mobile world’s equivalent to Heartbleed. Almost all Android devices contain the security and implementation issues in question; unpatched devices are at risk to straightforward attacks against specific users that put their privacy, data and safety at risk.

Google has patched internal code branches, but devices require over-the-air updates and given the shaky history of handset manufacturers and carriers pushing out security fixes, it’s unknown how long it will take to update vulnerable devices, or whether some will ever get fixed.

SNIP

Drake estimates that 950 million Android devices could be exposed by the half-dozen bugs and implementation issues he’s expected to detail in a presentation next week during the Black Hat conference in Las Vegas.

(Excerpt) Read more at threatpost.com ...


TOPICS: Extended News
KEYWORDS:
Navigation: use the links below to view more comments.
first previous 1-2021-39 last
To: usconservative
"Don't Be Evil" is Google's Corporate Motto.

https://en.wikipedia.org/wiki/Don%27t_be_evil

21 posted on 07/27/2015 2:30:56 PM PDT by dayglored (Meditate for twenty minutes every day, unless you are too busy, in which case meditate for an hour.)
[ Post Reply | Private Reply | To 19 | View Replies]

To: dayglored

I have an old Galaxy Tab 2 for Chromecast videos and for FR when I’m not on a PC.

I’m not too worried. I do nothing fancy or personal on it as it can barely do much right now being so old.


22 posted on 07/27/2015 2:32:03 PM PDT by VanDeKoik
[ Post Reply | Private Reply | To 10 | View Replies]

To: usconservative
You simply stated that Google was evil.

No, I didn't say that. google's slogan was "Don't Be Evil"

Note the birkenstocks...

23 posted on 07/27/2015 2:32:20 PM PDT by null and void (If the government can't protect the Marines, how can we expect it to protect us?)
[ Post Reply | Private Reply | To 18 | View Replies]

To: dayglored
I encourage you to consider this a potentially serious problem and see what it would take to update your devices once the manufacturer produces patches.

Given the Android devices I have are all less than 2 years old, I'd be guessing that an update is coming soon. My Samsung Galaxy 4 cell and Galaxy Note 4 both received several security patches recently. Have to power up the Asus tablets and see if they have anything waiting.

Yeah, I hope my life gets less boring too.... and "interesting times" indeed.

24 posted on 07/27/2015 2:32:21 PM PDT by usconservative (When The Ballot Box No Longer Counts, The Ammunition Box Does. (What's In Your Ammo Box?))
[ Post Reply | Private Reply | To 20 | View Replies]

To: dayglored

Thanks. I just checked and no updates available.


25 posted on 07/27/2015 2:33:11 PM PDT by Lurkina.n.Learnin (It's a shame nobama truly doesn't care about any of this. Our country, our future, he doesn't care)
[ Post Reply | Private Reply | To 10 | View Replies]

To: null and void
No, I didn't say that. google's slogan was "Don't Be Evil"

So you did. I swear, I'd NEVER seen or heard that before.

26 posted on 07/27/2015 2:33:36 PM PDT by usconservative (When The Ballot Box No Longer Counts, The Ammunition Box Does. (What's In Your Ammo Box?))
[ Post Reply | Private Reply | To 23 | View Replies]

To: bkopto

Blackberry is in talks to license its security software to Samsung.


27 posted on 07/27/2015 2:34:14 PM PDT by Praxeologue ( ')
[ Post Reply | Private Reply | To 1 | View Replies]

To: usconservative
So who was Google calling evil then?

They weren't. They were asserting that they weren't evil, the same way the clinton administration asserted that they were the most ethical administration ever, or the obama administration is the most transparent evah...

28 posted on 07/27/2015 2:35:39 PM PDT by null and void (If the government can't protect the Marines, how can we expect it to protect us?)
[ Post Reply | Private Reply | To 19 | View Replies]

To: VanDeKoik
> I’m not too worried. I do nothing fancy or personal on it as it can barely do much right now being so old.

Your choice, but as I mentioned above in #20, it's surprising how a little seemingly innocent information can be used and exploited by sufficiently motivated hackers.

I would hate to see a fellow FReeper harmed, so I encourage you to take precautions, assuming your device's manufacturer comes out with a patch. If they don't because it's too old, I will hope for the best for you and it.

29 posted on 07/27/2015 2:36:59 PM PDT by dayglored (Meditate for twenty minutes every day, unless you are too busy, in which case meditate for an hour.)
[ Post Reply | Private Reply | To 22 | View Replies]

To: usconservative

Not to worry, no offense taken. One can’t know everything!


30 posted on 07/27/2015 2:37:11 PM PDT by null and void (If the government can't protect the Marines, how can we expect it to protect us?)
[ Post Reply | Private Reply | To 26 | View Replies]

To: null and void
>> So who was Google calling evil then?

> They weren't...

Actually, according to the Wikipedia article I linked above, they were indeed taking a shot at their competitors who were (relatively speaking, back then) doing more nefarious things.

However, Google lost their right to throw stones pretty quickly, and now they are, by their own definition, doing evil.

What? Pride goeth before a fall?? You don't say....

31 posted on 07/27/2015 2:39:30 PM PDT by dayglored (Meditate for twenty minutes every day, unless you are too busy, in which case meditate for an hour.)
[ Post Reply | Private Reply | To 28 | View Replies]

To: null and void
Not to worry, no offense taken. One can’t know everything!

Thanks for that. Wasn't trying to offend and glad you didn't take it that I was. I can see how that could've been misinterpreted due to my bad choice of words and how I framed them.

32 posted on 07/27/2015 2:41:10 PM PDT by usconservative (When The Ballot Box No Longer Counts, The Ammunition Box Does. (What's In Your Ammo Box?))
[ Post Reply | Private Reply | To 30 | View Replies]

To: dayglored

Ah. Thanks!


33 posted on 07/27/2015 2:46:56 PM PDT by null and void (If the government can't protect the Marines, how can we expect it to protect us?)
[ Post Reply | Private Reply | To 31 | View Replies]

To: dayglored

Oh I’m ready to retire it in a few weeks for a cheap Windows tablet, but I’ll try to limit my use until I can see if there is some patch (not expecting much).


34 posted on 07/27/2015 3:03:18 PM PDT by VanDeKoik
[ Post Reply | Private Reply | To 29 | View Replies]

To: dayglored

Already texted two article to my son. He just got a new Galaxy a week ago. I know that because I drove 300 miles round trip to deliver it to him.


35 posted on 07/27/2015 3:34:43 PM PDT by Excellence (Marine mom since April 11, 2014)
[ Post Reply | Private Reply | To 10 | View Replies]

To: bkopto; ~Kim4VRWC's~; 1234; Abundy; Action-America; acoulterfan; AFreeBird; Airwinger; Aliska; ...
For all our Android using friends who are also Apple device users. . . this is an extremely serious vulnerability that will have exploits soon if they are not already out in the wild. — ANDROID PING!


Android Vulnerability and potential Exploit Ping!

If you want on or off the Mac Ping List, Freepmail me.

36 posted on 07/27/2015 4:05:17 PM PDT by Swordmaker ( This tag line is a Microsoft insult free zone... but if the insults to Mac users continue...)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker

Thanks for the ping Swordmaker.


37 posted on 07/27/2015 4:45:11 PM PDT by House Atreides (CRUZ or lose!)
[ Post Reply | Private Reply | To 36 | View Replies]

To: bkopto

This vulnerability reveals one of the biggest of all issues with the Android operating system - that most devices use customized versions that the user cannot update themselves. The manufacturer/distributor of the specific hardware has to push out updates - and they, as the article mentions, already tend to drag their feet on said updates - even the biggest names in such devices... Add to it- there are millions of “off-brand” android devices in consumer hands that will likely NEVER see an update to fix this (or any other issues).

It would be like if every single manufacturer had to push out Windows updates to consumer computers - and with a special, customized version for each model by each manufacturer - Dell would have to engineer dozens of versions of the OS just to cover THEIR hardware... then think of the many different makers...

Sometimes, the “wide-open”/open-source concept can bit you in the butt....


38 posted on 08/01/2015 7:57:31 PM PDT by TheBattman (Isn't the lesser evil... still evil?)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Up Yours Marxists

Understand that “android” is a very generic concept - that runs on such a humongous variety of hardware bits... not just phones and tablets, but several “netbook” computers, and a plethora of devices - watches, some cameras, and so much more - open source=cheap (at least until something makes you have to engineer firmware updates for a dozen different devices at once...)

Of course - this article also inflates the number because it is assuming that every android-based device ever sold or made is still operational and in use among consumers today. I can vouch for a few that are no longer functional myself... and all those millions of dead, drowned, destroyed smart phones - but they are counted in the number...


39 posted on 08/01/2015 8:01:14 PM PDT by TheBattman (Isn't the lesser evil... still evil?)
[ Post Reply | Private Reply | To 9 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-39 last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson