QuoteAndroid is insecure. There. I have made a statement, which many people will not like. I use an Android phone, I would say I was a "fanboy" of sorts, but I will also happily say Android is a shoddy, half-baked disgrace. And I will explain why that is. This is something that affects everyone out there with an Android phone. If youre running Android, and its not Gingerbread, with some future update on it (that I gather is not out yet), then you are at risk.
If this needs to be proven, then I would simply point to this video by Thomas Cannon, which shows the ability to steal content from the SD Card of a device: http://vimeo.com/17030639
Yes, someone could arbitrarily steal files from your SD card, just by you visiting a website. What have HTC and other manufacturers done about this? Nothing. When did Google release their patch? Oh wait, theyve not. It should be included in a future update to Gingerbread (2.3).
For more information on this exploit, check out http://www.h-online.com/open/news/it...t-1141200.html. I would draw your attention merely to one small part of this:
Google has now got to the bottom of the problem and is working on a patch, which is currently undergoing evaluation. This will not, however, find its way into Android 2.3 (Gingerbread), the release of which is imminent. It is instead expected to be included in a future update and it could be some time before it finds its way onto many users phones.
This problem affects phones running Android 1.5 through 2.1, as mentioned at this report
If you are using the HTC Hero, you would currently be sitting on Android 2.1. If you take all the current unrooted Android phones, other than the ten people that bought the Nexus S (everyone else will install gingerbread onto the SGS and get an SD slot too, all for free, but again thats another story), everyone is running Android 1.5 to 2.2, pretty much. Maybe some device somewhere is running Android 1.0, but everything is on 1.5 to 2.2, in the grand scheme of things.
So when did you receive the critical OTA update to rectify this security issue? What do you mean, youve not had one? Well, it would appear that Android has a major problem. Security updates are not made available immediately. It appears they are put out with its convenient for Google. But rather than add this important patch to 2.3, they are instead going to add it to something AFTER 2.3, as a form of update.
So, every single person is currently using a vulnerable handset (including those ten people that bought the Nexus S). Has Google told people how to avoid the issue in a security bulletin? Ive not heard of it certainly, and neither has anyone else I know of. The reason for this is that Google is currently stuck here. Your handset is likely made by a company other than Google (OK, I lied, it IS made by a company other than Google, as even the "Google" Nexus 1 was made by HTC), and they need to "customise" your Android experience.
The only trouble is that when they say customise, they mean cripple, by installing needless applications to /system, so you cant remove them on an unrooted device, and by spending 12 months looking at the code, before shoving it out the door full of bugs they introduced. For those of you who used the Hero, think about how long it took HTC to release the 2.1 update. When it finally came, about a year late, it needed an update to re-introduce the calibrate compass feature. Did HTC do much to improve the ROM? Well, if you count updating their incredibly bloated Sense UI in January, and then sitting on the code until July, then perhaps they did. Just remember that we were running 2.1 with Sense on the Hero in January 2010, courtesy of some leaks, yet it still took them until July to actually release it. What did they do in the meantime? Well, nothing much, though they did release some minor, insignificant products like the HTC Desire and Nexus 1.
Should users be expected to wait 6 months for a major update, improving features and security, so HTCs one capable employee can write the software for the next product being released? Does the world stop while HTC frantically works on their next phone, which is awful similar to the last one? Id argue it just did.
Take a look at Redmond now, where they have to support the Windows Operating System. Counting supported versions, there are 5 versions of Windows currently in varying levels of support, which receive security updates regularly - Windows XP, Server 2003, Vista, 7, Server 2008, Server 2008 R2. If you take into account the different Service Pack levels, and 64 bit vs. 32 bit, thats a lot of combinations. And dare I mention the eleventy squillion different "versions" of Vista, so there is a different SKU for every day of the year?
Yet somehow, Microsoft manages to release critical updates relatively quickly. They have to test on many more hardware platforms, with all sorts of architectures, yet they manage to get it pretty much spot on. Sometimes people argue we shouldnt need these updates, but I am sure most of us would admit that Microsoft does a very good job in getting out updates promptly.
Given my Windows XP computer receives updates regularly, (XP being a ten-year-old operating system now) can anyone explain why HTC are not releasing regular updates for my 1 year old phone, running software which was released in July 2010? AOSP keeps evolving, and the Cyanogenmod repo is arguable a better place for manufacturers to pull from, though Google would feel a bit left out...
There are too many problems here. First of all, nobody is releasing regular security updates for Android. Why there is no weekly or monthly update made available by Google to correct such issues, I dont know. But if they made such an update, it could easily be applied OTA to phones... Well, it could, if manufacturers didnt all have to use strange customisations to their devices. HTC installs its ghastly Sense UI, to cripple the speed of the phone, and make a half-baked attempt to make it look pretty. Is it worth the endless wait for updates? Id say "No". Samsung adds their own TouchWiz interface, which again just slows the phone down, and adds more bloat to the device.
Then we get onto the issue of networks. Mobile networks insist on customising their device software, to force their logo upon you every time you
a) look at your phone
b) turn on your phone
c) turn off your phone
d) unlock your phone (network name appears on lockscreen)
e) open the notification bar
f) go to the homescreen (if theyve re-badged the browser as "WebnWalk", rather than Browser. Not mentioning any names, *ahem* T-Mobile)
g) Open the app drawer (do we really need apps pre-installed by our network providers, which invariably use resources and must load at startup, despite doing nothing and not being used?)
h) open the browser (dont tell me your network has pre-set your default homepage too?)
And I could continue, but wont.
Your network takes the ROM from your manufacturer, which is now bloated and slow, and makes it even worse by loading more bloated software, and further removing any performance left in the device. If it was possible to actively slow down the device through software, you can bet your bottom dollar that your network would do this. Unfortunately, your network also insists that it re-brands all future updates. So critical updates that protect your security and privacy are not on the cards, unless Vodafone can shove its logo into somewhere else they forgot last time... And this takes time. Time you would be sitting there, vulnerable to this exploit.
I think we need to get our priorities right here. Collectively. We as users need to start demanding regular updates from our handset manufacturer and network, which address security flaws fixed in the previous month. Google needs to promptly patch these fixes, or allow the open source community to fix them, and then port the patch to all "supported" versions of Android at the time. This fix would appear in the next monthly patch. Your handset manufacturer should not be adding anything to the ROM like Sense or Touchwiz, if it will interfere with patching of the base Android installation. If they do, its your security being put at risk. Is that acceptable? I dont think well get many votes for "yes" on that one...
Unfortunately, I dont see this happening. Everyone in the industry seems content to sit and ignore the problems, pretending all is well. The HTC Hero is still a current device, as it is still in use by many customers who took out 24 month contracts with their provider in, perhaps, April or May of 2010. You, the customer, needs to harass your network for value for money. Since you paid them, go to them and demand comment regarding these security holes. Ask them when you can expect a fix, given you are paying them monthly for the phone. If they pass the buck onto HTC or Samsung, remind them it is their responsibility under the Sale of Goods Act, as the contract of sale is between you and them. When will THEY be releasing the next update to fix the browser exploit? When are they upgrading your Hero to Gingerbread? Wouldnt it be fairer if every device was given support dates, like Microsoft gives the various versions of Windows? Windows 2000 is out of support, but this was publicly announced a long time ago. Since you purchase "Windows 2000" as a unit, the comparison here would be "the HTC Hero" is supported up until 31 December 2012. The definition of supported needs to cover what you can expect. Perhaps major Android updates such as Froyo and Gingerbread until 31 May 2011? Perhaps only security updates to the final version of Android after that time? And after 31 December 2012, no further support. The key part being this information was published well in advance, and adhered to rigorously. Your contract with your mobile provider should back your right to prompt and regular updates, and there should be published schedules so you can know when to expect updates.
Is this too much to ask when you spend several hundred pounds on a device, or agree to a long-term contract with a network provider? Let us know your thoughts below, and I will be raising them with the mobile industry. Just consider that a full retail copy of Windows 7 Home Premium is £114.52, and an Android phone is usually significantly more than this. One will get security updates for an extended period of time, backed by a company that does actually respond to security problems. The other will sit vulnerable to exploits indefinitely, as you are expected to buy a new device to remain secure. Thats not on.
http://www.villainrom.co.uk/forum/content.php?240-When-did-you-last-get-a-Security-Update-for-your-Phone&s=a326167a55705be6d4b9b1b0b0b36a2c
Somewhere in that guys post is a man wanting an iPhone.
Quote from: Clockd 0NeSomewhere in that guys post is a man wanting an iPhone.
LoL :D
Doubt it, hes one of the main devs for Android and VillainROM.
He has a handful of cutting edge Android phones, and if he wanted an iPhone, he could just buy one :D
Being serious for a moment, Im surprised that this hasnt had more attention and much sooner, I mean this is a huge flaw is it not? Im surprised Google are not being taken to task about it, as really they are the crux of the problem. They sold out too fast on this one.
But this is the same for all phones I guess, the companies responsible for them do not care and do not want to keep them running smoothly since they all have this inherent 2 year lifespan from contracts and such. The firmware on my SE C905 is shocking. Any more than a handful of texts kept on the phone at any time causes the whole phone to take about 5 seconds to respond to anything. It will never be fixed or upgraded, they just wouldnt care. If it was any other software on a different platform you can bet they would fix it, but because these are almost seen as a disposable commodity now they are happy to shaft us.
I dont even like Apple products, but even I would be tempted to get an iPhone because it just works.
Quote from: Clockd 0NeBut this is the same for all phones I guess, the companies responsible for them do not care and do not want to keep them running smoothly since they all have this inherent 2 year lifespan from contracts and such.
True of most companies yes, but RIM do keep things updated fairly well. My 8900 has only just dropped out of the update loop when OS6 came along. Was supported from its initial release running through the various OS upgrades to OS5. Its still in heavy rotation with companies who use Blackberry, and dont upgrade their entire handset line every 2 years. Last place I was at we were still on some 5 and 6 year old handsets for users who didnt see the point in upgrading!
Actually, in a lot of cases the OS gets frequent updates. Its normally down to the carrier to enforce these updates. Most of them arent bothered.
With Android, Google have yet to fix this problem. They say its going to be sorted in the upcoming Gingerbread release but for those that arent intimate with the inner workings of their phones, arent going to see this fix if they have a phone the manufacturer/carrier doesnt choose to support.
My Hero is currently running 2.2 and has dabbled with a pre-release of 2.3. Mine will run it, but even the cutting edge phones that are shipping with 2.2 are vulnerable.
I think it should highlight an issue for all phone providers, seeing how much personal info is stored on a phone these days. They should be kept up to date, in a similar fashion to Windows Update for example.
I thought in that quote he said that it affects phones up to 2.1, so 2.2 should be safe?
Nah, Ive been speaking to him and its even going to affect 2.3 until Google release a fix. Even then its up to the carriers to push that to devices, unless youre running a custom rom.
When the original article was done, 2.2 wasnt out. Now that its known about, people have checked in all released.
Hes been talking to devs and theyre itching to get their hands on the source for this fix, so they can port it to other devices.
From Pulsar @ Villainrom
Quote@All
With the help of Thomas Cannon, we have established that FroydVillain 1.7.2 is not affected by this vulnerability.
The same should be true of other recent CyanogenMod based ROMs, but we cant be certain with regards to that.
I believe VR12 and below are vulnerable, and would encourage anyone on Vr12 to look at installing the latest Froyd ROM to ensure they are kept secure. Due to HTC being mean, we dont have sources to the base of the sense rom, so we couldnt fix it, even if we tried...
So, you all appear to be safe on Froyd 1.7 So now we need to encourage the average user to install a custom rom, just for ensuring their security.
So, spread the word folks. VillainROM will keep you safe, if using the latest froyd rom. We now need to step into the shoes of htc and keep as many phone owners secure, since they wont do it...
I CBA to read all that so can anyone summerise what exactly is vunerable and what the big deal is?
Its not like I buy stuff online or store my bank deatils on my phone who cares if they see I have crazy birds and a weather app on my sd card.
They can upload a file if they know the name. Nothing interesting is stored in a file anyway, so he might be able to guess the name of your angry birds score file, or some of your camera pics, or maybe part of your SMS database. All your bank account details are stored in your google account on googles servers.
So yes its a big hole, but its one that cant really be used against you. That said google should have fixed it immediately.
Quote from: SamAll your bank account details are stored in your google account on googles servers.
So yes its a big hole, but its one that cant really be used against you. That said google should have fixed it immediately.
only if i used google checout I assume? I dont think Ive ever given google my bank account details.
No, just through the browser.
And yes, they can only have the details in your google account if you gave it them.
Quote from: soopahflyNo, just through the browser.
And yes, they can only have the details in your google account if you gave it them.
So unless you are daft enough to have your vital details in your google account then it isnt much of a big deal.
Im not defending google at all though these things should not be happening at all and I hope they rush the fix out and convince the networks to implement it asap.
Quote from: DEViANCEQuote from: soopahflyNo, just through the browser.
And yes, they can only have the details in your google account if you gave it them.
So unless you are daft enough to have your vital details in your google account then it isnt much of a big deal.
Im not defending google at all though these things should not be happening at all and I hope they rush the fix out and convince the networks to implement it asap.
No, even if its in google account they cant get it.
All this exploit can do is upload a file from your phone. But very little is in files, just program content usually.