5 ms·
Android and its community are sorta schizophrenic towards security. On one hand, users are told that they should never ever, ever install applications from unt
by disconnected 9y ago
Android and its community are sorta schizophrenic towards security.
On one hand, users are told that they should never ever, ever install applications from untrusted sources. They should always use the play store because applications are scanned for vulnerabilities and whatnot.
On the other hand, we have people telling us that one of the great advantages of Android is that you can sideload apps - bypassing the store security model completely.
On one hand, a VPN needs root access for transparent proxying (or at least TOR does). Changing the hosts file needs root access. Changing gps.conf requires root. Lots of useful operations need root access, so if you are concerned about privacy and security, or just want more control, you probably want root.
On the other hand, root is stupidly hard to obtain, and users are strongly discouraged from doing it anyway because it opens all sorts of attack vectors. Unless the manufacturer provides a legitimate method to do it, the operation of obtaining root itself, like on iOS, often relies on an unpatched local privilege escalation vulnerability. Note that any application can exploit this, not just the rooting app.
I don't support Apple's walled garden approach, but we can't argue that they have a much clearer picture with regards to security, and the results speak for themselves. Malware in the Apple devices is rare, whereas in Android it is rapidly becoming routine. Unfortunately, you sacrifice flexibility for enhanced security.
- jswizzy 9y agoYep as someone who is in a cybersecurity job, it's almost trivial to hack Android.
- ReverseCold 9y agoMost Android devices at least, unless you have the latest Nex... Pixel or Samsung phone.
- blfr 9y agoConsidering this is HN, you're probably fine with any device as long as you run a patched OS on it. Which is fairly easy with LineageOS. And they support a lot of devices. I dug out an old Moto G (1st generation, falcon) last week and it runs Lineage 14 (based on Android 7/Nougat) smoothly.
- nnutter 9y agoMy perception is also that malware ends up in the Google Play Store with much higher frequency than the App Store. Just do a news search for "Google Play Store malware" and "App Store malware" and compare. Also, one can sideload apps, if you have a Mac, onto iOS. Obviously, that's not anywhere as integrated but maybe that's a good thing. Heck, maybe Apple even added that so people in China could sideload VPNs. Maybe iOS VPNs are good enough (no root, no TOR?)?
- lern_too_spel 9y agoAdd up all the malicious app installs on Google Play Store, and it doesn't even come close to the 500 million[1] (conservative estimate) users affected by XCodeGhost. It looks worse when you consider that the 500 million is on an order of magnitude smaller total iOS userbase vs. Play Store userbase and when you consider that Google allows third party security researchers to investigate and publish research on the Play Store while Apple does not, so XCodeGhost is likely to be the tip of the iceberg.[2] [1] https://www.google.com/amp/s/www.macrumors.com/2015/09/20/xcodeghost-chinese-malware-faq/amp/ https://www.google.com/amp/s/www.macrumors.com/2015/09/20/xc... [2] https://www.google.com/amp/s/www.cultofmac.com/128577/apple-kicks-security-researcher-out-of-app-store-and-developer-program-after-ios-vulnerability-demonstration/amp/ https://www.google.com/amp/s/www.cultofmac.com/128577/apple-...
- evgen 9y agoLOL, let's start with StageFright (1 billion+ pwned with just a text message), move on to StageFright2 (because patching is hard...), and then just keep running down the list of malware in the Play store that is still there months after being discovered. XCodeGhost OTOH, seemed to have hit around 40 apps so that would probably not even get it into the top-100 list of Google Play malware families. Malware families. The Play store is such a shitshow that you can actually have different strains of malware running around in fake apps, like some sort of digital syphillus spreading through the brothel that Google forces everyone to visit if they want the shiny apps...
- lern_too_spel 9y ago
- blfr 9y agoRoot is not that hard to obtain on most devices. The instructions are straight-forward[1] and easy to follow, especially for anyone reading this thread. But lately Google has decided that rooted phones are a security issue. So if you do choose to install some sort of su utility, some functions like Android Pay may cease to work, not because of technical reasons but because Google deliberately disables them on rooted phones. [1] for example https://wiki.lineageos.org/devices/lux/install https://wiki.lineageos.org/devices/lux/install
- userbinator 9y agoOf course, once you're root you can also prevent those apps (which don't run as root) from finding out that you have root, but it's an ongoing cat-and-mouse game.
- blfr 9y agoOf course. But Google is currently ahead from what I've read.
- userbinator 9y agobut we can't argue that they have a much clearer picture with regards to security, and the results speak for themselves What they've done could be said to be more authoritarian, and indeed if you do the analogous of throwing everyone in jail by default because they could be guilty, then you will basically have no crime. The question is whether that's actually a good idea... it's the old "freedom vs. security" argument.