4 ms·
I'll make it easier for you. I have a Nubia phone which runs Pie. Its last security patch is dated August 5th, 2019. Play Services and Chrome are fully updat
by techrat 5y ago
I'll make it easier for you.
I have a Nubia phone which runs Pie.
Its last security patch is dated August 5th, 2019.
Play Services and Chrome are fully updated.
Where is there an in the wild exploit that you can point me to? Proof of concept or otherwise. I'll happily load it up in Chrome on my phone and let it compromise my system.
Meanwhile there's a zero click iMessage exploit article still on the first page of HN.
- BugsJustFindMe 5y agoWhat gives you the impression that Android security updates only involve Play Services and Chrome as opposed to the file system, bluetooth, wifi, CPU, and GPU stacks, or anything else? Do you have a reason for believing that any of the numerous drive-by Android remote code execution CVEs published since August 2019 can be mitigated without updating any of the vendor and kernel components that Google had to update to stop them? Let's ask ourselves this basic question: If Play Services and Chrome could keep an Android Pie system secure, why does Google bother with a separate security patch date? > Meanwhile there's a zero click iMessage exploit article still on the first page of HN. Maybe because it's news and critical Android remote exploits are found often enough to not be news.
- techrat 5y ago> Maybe because it's news and critical Android remote exploits are found often enough to not be news. Then you should have no problem being able to find one that will exploit my phone. I even gave you the specific Android version AND security patch level to target. Get at it instead of pointing to the sky and saying "look!"
- BugsJustFindMe 5y ago> Then you should have no problem being able to find one https://www.cvedetails.com/vulnerability-list.php?vendor_id=1224&product_id=19997&version_id=602087&page=1&hasexp=0&opdos=0&opec=0&opov=0&opcsrf=0&opgpriv=0&opsqli=0&opxss=0&opdirt=0&opmemc=0&ophttprs=0&opbyp=0&opfileinc=0&opginf=0&cvssscoremin=0&cvssscoremax=0&year=0&month=0&cweid=0&order=3&trc=631&sha=a850f96b00aef66c84069296abf33cb95a71a6de https://www.cvedetails.com/vulnerability-list.php?vendor_id=... https://source.android.com/security/bulletin https://source.android.com/security/bulletin Enjoy your phone. Or don't. None of us are your mom, so we can't tell you what to do. > Get at it Abrasive demands are unpleasantly childish. Not being your mom also means that I don't care if you suffer from your own negligence. You can either keep yourself abreast of Android platform security woes or not. As Captain Planet says, the power is yours.
- techrat 5y agoSo basically, you have no in the wild exploit that you can have me load up on my phone and have it become compromised. Got it. Thanks for proving my point.
- chipotle_coyote 5y agoDude, I literally mentioned articles with in-the-wild exploits that have been found for Android this year. "Yes, but those are from a few months ago, they are fixed now, and there is a CURRENT one for iOS" is not the "checkmate, iSheep!" move you apparently think it is.
- techrat 5y agoThen you should be able to provide an actual link of an in the wild exploit.