5 ms·
Aren't you running a graat security risk when you run this on old devices that often don't receive security updates?
by bobbychairs 7y ago
Aren't you running a graat security risk when you run this on old devices that often don't receive security updates?
- leoedin 7y agoNo security updates means potential for exploits, not definitely exploited. If you don't open yourself up to exploits by using the browser or untrusted apps, you're pretty unlikely to be compromised even with an older phone.
- beenBoutIT 7y agoIf this concept gets popular enough eventually the majority of users will start using the same old model Android phone(Nexus 5, etc.). That's when all of the unpatched vulnerabilities will become a serious problem that's difficult to fix.
- jdnenej 7y agoIt's not difficult to fix. It's just that corporations want you to throw out and buy a new phone every year. This is what happens when you let the same company make the software and the hardware.
- bigiain 7y ago> This is what happens when you let the same company make the software and the hardware. Not sure that follows, it seems a quite Android-centric view? (Which I guess is valid in the context of this discussion...) Apple do a remarkably good job (in my opinion) of providing software/security updates to older iOS devices. iPhones as old as an SE or 6S are still getting current versions of iOS. I have a _much_ harder time keeping similar aged Android devices up to date (My Galaxy S6Edge has been stuck on Android 7 forever. I'd need to root it and install a 3rd party ROM to upgrade it. I haven't done that because I use it still as a mobile app test device, and I don't personally "trust" not stock OS installations to be particularly valid test devices for work apps...)
- deleted 7y ago[deleted]
- craftyguy 7y agoThat's absolutely not true, e.g.: https://insinuator.net/2020/02/critical-bluetooth-vulnerability-in-android-cve-2020-0022/ https://insinuator.net/2020/02/critical-bluetooth-vulnerabil... There was another one regarding the wifi chip used in many popular phones a few months ago.
- Thriptic 7y agoPut it on a private VLAN (eg guest Network that can't be reached from main network), pull the Sim card, uninstall all non-essential software, turn off all non-essential services.
- Mister_Snuggles 7y agoThis is good advice for any sort of camera system, not just a repurposed phone. I do this for my cameras, there's too much risk associated with them phoning home to set them up any other way.
- stevehawk 7y agoEVERYONE SHOUlD PUT ALL IO(S)T* DEVICES ON A PRIVATE VLAN :-D * "internet of shitty things"
- saagarjha 7y agoNo, that doesn’t work. Everyone knows the S in IOT stands for security.
- bigiain 7y agoI propose IOCT (where C = Crappy). Although I prefer "Internet of un-updated linux boxes". (A thing to which I'm ashamedly a party to. I was in a startup ~5 years back where I was responsible for the backend that provided the software and OS updates (a customised ARCH Repo and pacman config) for our hardware. The startup went under, having shipped the first production run. I kept the Arch repo up on my own dime for as long as I could, but eventually the control over the domain dried up and the subdomains it relied on no longer existed... There weren't many of our devices still connecting to them that last time the log files showed connections, but I'm looking at two of them right now which I've been occasionally doing security updates to by hand. I feel bad each time I do it, knowing there's customers out there who bought our stuff who are no longer getting any updates...)
- surround 7y agoI have some crappy IOT devices, but I cannot control them unless they are on the same WiFi network as my phone (e.g. Sonos). What should I do?
- orthecreedence 7y agoYou could block its access to the internet with most home routers.