5 ms·
PinePhone Malware Surprises Users, Raises Questions
- ocdtrekkie 5y agoThis is a particularly weird space because people have generally not been concerned about security in segments unlikely to be profitable to attack: Modder communities have generally been full of hacked or modified apps and operating systems, published by random unknown people all over the world, and generally haven't been that scary, because there's no financial incentive to attack. Attackers are generally looking for a large number of victims or particularly valuable targeted data. Attacking the PinePhone is... ridiculous... there's almost no reason to do so, with few users, almost none of which who would pay a ransom or who has sensitive state actor data available. And the fact that it's such a useless attack vector is also why nobody had their guard up on executing code there.
- tssva 5y ago"Some men just want to watch the world burn."
- csdvrx 5y ago> Attacking the PinePhone is... ridiculous... It serves as a warning: security matters everywhere.
- garbagecoder 5y agoThis is it, right here. No one gets a pass, even something that is largely a hobby.
- bsjks 5y agoWhen you execute a random file you got off the internet (even worse, with sudo) you don’t get to complain about the consequences. The rest of the story is pure fluff.
- garbagecoder 5y agoWanna know how I know you don't support 1000s of normie users?
- tata71 5y agoSo glad I don't see this as a presumed badge of honor anymore. Rather be working on simplifying security/privacy tools for these users, or educating them.
- eloeffler 5y agoWe need a curated list of random files from the internet. awesome-randomfiles anyone?
- aordano 5y agohttps://virustotal.com https://virustotal.com
- Seirdy 5y agoAndroid enforces robust sandboxing on all programs, so this would not have happened. This is the security tradeoff that comes with the standard desktop model of computing, and people should be upfront about it when promoting phones running desktop operating systems
- BusyLurker3K 5y agoWhat a horrible sensationalist headline. It reads as if the malware was baked into the PinePhone.
- CRImier 5y agoWhen you read "Linux malware", do you interpret it as "malware baked into Linux"?
- wvenable 5y agoIn this case, I definitely interpreted it as "baked into PinePhone" like the commenter. Admittedly the same headline that says "iPhone Malware Surprises Users" would probably read the other way. It depends a bit on the subject. If it said "Lenovo Malware Surprises Users" I'd it expect it baked in too rather than just malware that just effects Lenovos. "Malware for PinePhone" would make it clearer.
- CRImier 5y agoThank you, I see this viewpoint better now. Not certain I'd make the headline different knowing this, but this is good to keep in mind.
- GhettoComputers 5y ago> In this case, I definitely interpreted it as "baked into PinePhone" like the commenter. Pinephone doesn’t make software, it just makes hardware. It’s philosophy is they make hardware that’s easy to hack. All the software is community maintained and not official.
- TrickardRixx 5y agoI also read it as "baked into PinePhone". As to why, well the headline didn't include the fact that the PinePhone ships with no software. So that's not information I had at the time.
- GhettoComputers 5y ago>apart from obfuscation, the most complex thing about it is that it’s Bash, a language with unreadability baked in. Hehe take that posix nerds!