4 ms·
Most will, some will drop support after its X major release behind. But that's not really the issue, the underlying system has a lot of security issues (as all
by Jaepa 9y ago
Most will, some will drop support after its X major release behind. But that's not really the issue, the underlying system has a lot of security issues (as all complex systems do).
So just for 2017 there are:
- 326 code execution vulnerabilities
- 221 memory overflow bugs
- 114 memory corruption issues
- 309 privilege escalation bugs
http://www.cvedetails.com/product/19997/Google-Android.html?vendor_id=1224 http://www.cvedetails.com/product/19997/Google-Android.html?...
Granted, I'm sure a lot of these CVE are very low risk, and some are duplicates (because CVE). But there were a couple of notable really bad security issues. But this is just the Android, not all the of dependencies Android has.
StageFright was already mentions, and there has been a couple of iterations of this already, stemming from different bugs in a parsing library used with MMS. Included in this is a remote code execution and an privilege escalation.
Another fun one is Broadpwn, which is rather new one and was disclosed as BlackHat US this year. Its effects both iOS and Android and can be wormed trivially. It targets a widely used Broadcomm wifi chipset, and does not require _any_ user interaction. A malformed SSID broadcast allows for remote code execution. And when I say any user interaction, you can walk by something broadcasting this and you're infected.
- throwaway613834 9y agoRegarding Broadpwn: I wasn't aware of it, but at the same time -- has it actually been exploited, and has it been patched in more recent hardware or OSes? If the upgrade doesn't help mitigate an actual, existing threat then upgrading doesn't solve anything. To put it another way: if you learn of a very serious exploit like this in the wild and an upgrade is the only way to solve it -- by all means, go ahead and upgrade. I'm not saying you should never upgrade, nor am I saying serious security vulnerabilities cannot pop up. But neither in any way implies you need a periodic 1-2-year hardware/OS refresh. A refresh could be justified in 1 day or in 10 years; it just depends on what the actual threats and mitigations are. Remember what the original discussion was about: it was about whether the periodic refresh is justified. As for the rest of those (StageFright and other attacks) -- I've addressed them in other comments. See here: https://news.ycombinator.com/item?id=15040745 https://news.ycombinator.com/item?id=15040745
- dmoy 9y agoThere is no way I'm going to be continually looking for new incoming CVE that affect my old phone and making sure I have solid workarounds. The risk is too high that I'd miss one, mess up a fix, and then be vulnerable. And even if the risk wasn't that high, we're talking about a lot of time sunk into looking through security postings and verifying my own fixes/workarounds. It doesn't have to take too many minutes per year before it's worth me buying a new $130 moto E or whatever. As in like, 1 hour per three years or something. This is the same reason why I don't run a computer OS at home that isn't patched to the latest security updates. I am not going to run windows XP at home and just disable / find workarounds for every single one of the probably-thousands of risks. That's insane.
- throwaway613834 9y agoThat's a total straw man. You don't need to keep up with CVE. You really think I learned about e.g. StageFright through reading CVE or expected you to do that? If there's a serious vulnerability that actually needs your attention, you will read about it in the news (certainly on HN, most likely also the general news if it affects a sizable population). You will become aware of it somehow, most likely before a patch is even released. You won't need to put any time into it until it happens, and even then the mitigation (like e.g. disabling automatic MMS download here) will usually be far faster than the time to buy a new phone, set up your apps again, and move everything over. Not to mention that the phone you buy won't be updated to that very day anyway, so you'll have more upgrading to do soon after. Seriously, you're way blowing it out of proportion.
- mrmagooey 9y ago> If there's a serious vulnerability that actually needs your attention, you will read about it in the news The ol' security through tech press approach. Seriously though, you can't have the security of your devices dependent on whether or not someone has come up with a catchy name for their exploit. The exploits with names like broadpwn and stagefright are the exceptions, not the rules, there are plenty of critical CVE's that have never had cool names or tech articles written about them. Even if an exploit has a cool name and some press, what if people don't upvote it when it gets posted here (or reddit/wherever)?