4 ms·
> How in this decade, with all we know and have learned about security and exploits, can this kind of thing still happen? The software industry has learned a l
by RandomOpinion 10y ago
> How in this decade, with all we know and have learned about security and exploits, can this kind of thing still happen?
The software industry has learned a lot about a security and exploits, certainly.
The hardware industry, including embedded developers, well, not so much...
- goodplay 10y agoEspecially when hardware makers make money off it. I'll need to replace my phone soon, and I'll make an effort to buy something that doesn't use broadcom.
- josteink 10y agoWell good luck with that. As far as I've understood it, there's surprisingly few core HW companies powering the Android mobile ecosystem.
- goodplay 10y agoGeneric Chinese phones seem to sport either intel or allwinner. Both aren't broadcom.
- Moru 10y agoYou could argue that this will be fixed in the next generation broadcom chips. However, do you know what bugs exist in other manufacturers chips? On the other hand, broadcom is more interesting to attack because there are so much more of them...
- goodplay 10y agoTargeted attacks are hard enough to fend off on systems that are fully up-to-date. What chance does an out-of-date locked-down phone have? If you're not allowed to control and secure your phone yourself, the next best thing is to go with uncommon tech. Security-by-obscurity seems to be back in fashion :( I'm also avoiding broadcom as a "vote with my wallet"-type of punishment for being reckless with people's property. If enough people react similarly, broadcom will learn from its mistake. If not, at least I've done my part.