8 ms·
the title should say "every vulnerable Android device": One of the most interesting ones is the addJavascriptInterface vulnerability ( CVE-2012-6636 ) which
by alternize 11y ago
the title should say "every vulnerable Android device":
One of the most interesting ones is the addJavascriptInterface vulnerability ( CVE-2012-6636 ) which affects every device running a version older than Android 4.2
the exploit is from march 2012 and affects devices running android < 4.2. which according to latest platform usage [0] numbers is around 14.9% of all active android devices.
[0] https://en.wikipedia.org/wiki/Android_(operating_system)#Platform_usage https://en.wikipedia.org/wiki/Android_(operating_system)#Pla...
- jacquesm 11y agoWith 1.4 billion active android devices out there that still translates into a whopping 200M or so devices.
- ocdtrekkie 11y agoUnfortunately, Google has stated no intention to support or secure any device running an OS released more than 18 months ago. There's many dozens of CVEs that involve owning devices pre-5.1 that will never be fixed by Google or the OEMs.
- HappyTypist 11y agoEven a slight security only bump to 24 months would help and match Apple.
- jacquesm 11y agoIn NL the consumers rights organization has sued Samsung to force them to provide updates. Really curious how that will play out.
- jacquesm 11y agoPlanned obsolescence at the expense of security.
- cordite 11y agoSounds like something telecoms would like, buying those big expensive phones that keep you on their 2 year contracts (24 months)
- wyldfire 11y agoThat would work, but only if people appreciated the scope of the risk of continued operation of their vulnerable phone.
- droopybuns 11y agoI sincerely think this meme should be considered dead. http://time.com/money/3991578/verizon-2015-mobile-cell-phone-no-contract/ http://time.com/money/3991578/verizon-2015-mobile-cell-phone... I work in the mobile. I am experiencing this daily. IF normal consumers gave a shit about patching old phones, THEN we have a legitimate shot at fixing this problem. But carriers are generally transitioning away from treating handsets as a revenue source and focusing more on transport. So please- think hard about repeating this cheap shot. It's easy and can win you internet points, but I am arguing that now is the best time in history that we could start making progress on this issue. Comments like this do not help move the ball forward.
- cordite 11y agoThank you for educating me on this matter. Though from what I've witnessed, even though it is unreasonable, it seems most non-techs expect the carriers to do it automatically for them without their involvement.
- amlgsmsn 11y agoDoes the open source nature of Android help here for a fix? 200M devices sounds like a lot, is it not possible for the community to fix it?
- ikeboy 11y agoI'm writing this from a Samsung device that never had a supported lollipop release. If I'd be on stock, I'd be vulnerable to many vulnerabilities including stagefright. But I'm using an open source ROM called cyanogenmod, currently on Android 5.1 (cm 12.1). I upgraded to a newer nightly after patches were made to fix stagefright, and now I'm not vulnerable. I could also have installed a version of cyanogenmod from KitKat that back ported the patch. So yes, open source can and has addressed this. If your device is supported by cyanogenmod, you can fix it. Note that marshmallow cm builds are expected to be released soon, and afaik my device (S3) will still be supported: this would make my device upgradable 2 entire major releases after the manufacturer dropped support.
- breakingcups 11y agoIn fact, there are already Marshmallow nightlies for the S3. Interesting is that, even though you are running 12.1 on the S3, there was never an official CyanogenMod release for the S3, only unofficial ones. But now a maintainer has stepped up, made MM (CM 13) run on the S3 again and we get our official releases again.
- ikeboy 11y agohttps://download.cyanogenmod.org/?device=d2spr https://download.cyanogenmod.org/?device=d2spr looks pretty darn official to me. And I don't see any CM 13 releases yet. I thought they were expected to drop in a few weeks. Edit: I assume you were talking about the international version. That does seem to have skipped lollipop. I also came across unofficial builds of 13 for my device, but I'm not upgrading until I have debug time.
- pjmlp 11y agoThat doesn't work for the common user.
- joshka 11y agoThis is interesting. In Australia, there's the Australian Consumer Law, which mandates that products must be of acceptable quality for a duration that aligns with the length of the contracts. Legally a consumer can return such a 'faulty' device to the carrier. I'm guessing that this is something that needs to be bumped up by 6 months in Australia (or more likely the carriers will take a risk that there aren't enough consumers that care about security to follow through with such returns). Perhaps if someone were to post a 'How to get a free phone every 18 months' type of article it could press the point that writing software is not a one shot process, and broken software should be supported for longer periods of time.
- paulddraper 11y agoStill far from "every"