10 ms·
It seems like the crowd here is pro things like this. I understand the e-waste angle. How do you protect and defend android devices that haven't received securi
by Maxburn 4y ago
It seems like the crowd here is pro things like this. I understand the e-waste angle. How do you protect and defend android devices that haven't received security updates for a long time?
- razemio 4y agoI use old Android devices for smart home stuff (e.g. tablet as sensor overview). I guess as long as it is not exposed to a public endpoint, there is not much to fear?
- Maxburn 4y agoIf you can resist using it to browse the internet or receive SMS/MMS I see your point.
- 867-5309 4y agoharden at the app level and put a reverse proxy in front of it
- Hello71 4y agotermux doesn't use most of the system libraries that are likely to be remotely exploitable, e.g. openssl and webview. the remaining unupdatable weakness is the kernel, but it's pretty unlikely to have a TCP RCE or something like that. there's SACK Panic, but that's only DoS, not RCE, and if you're running something on android 5 you probably have low reliability expectations anyways.
- Maxburn 4y agoOK, I see now. For this Termux use case having an old device isn't really a big deal. Just make sure no cellular and only use it on protected LAN.
- kramerger 4y agoI think only core OS vulnerabilities (kernel plus a few libraries) are not updated. 9 times of 10 these are local privilege escalation that are less important if you don't run random apps. Depending on the Android version, most other things could be updated in other ways (security updates from OEM, system updates via play services, app updates including system apps via play store). On top of that, you can add local and network firewalls and similar stuff to harden the system. Basically, probably good enough for the intended usage.
- Maxburn 4y agoI'm aware the play store can do a LOT more than the name implies. What I wasn't thinking about was this tool generally doesn't need the device to be on public IP, so remove the cellular access and have it behind a LAN firewall and it should be ok. Previously I was thinking along the lines of MMS attack's being a problem. I seem to get suspicious links regularly.
- tunap 4y agoTo add: Custom kernel, de-googled ROM(sans Play Store) & side-loading apps.
- Maxburn 4y agoThat came to mind for extending device support. As I understand it though the hardware drivers are all closed source and end support rather quickly. I believe that the drivers are sometimes the source of the problem which sort of complicates extending the lifespan.
- tunap 4y agoThe only problems I experienced are when the wireless bands are deprecated. I'd still be rolling my n900, otherwise. Old drivers or not, there is/was still some development going on; Leste & PostmarketOS, IIRC.
- ruune 4y agoOnly real way is never connecting it to the internet. Otherwise you will always have a vulnerable server with the only hope that it's not a mainstream server and by that not that much threatened by script kiddies and mass scans
- Maxburn 4y agoI guess in this use case removing the cellular access and only using it on LAN would be good enough? Edit; second though NO. Clicking a bad link with some browser exploit on it will still get you infected in that case. So you couldn't use this to browse the internet safely. Still as a Termux only tool seems safe.
- jeroenhd 4y agoUnlike on iOS, your browser runtime is not tied to your phone. Most phones come with Google Chrome as the default browser which no longer gets updates below Android 7, but Firefox still gets updates on Android 5.0+. With an up-to-date browser you run about the same risk you run if you're using a computer. The kernel exploits are problematic, but Android also adds annoying sandboxing that requires a lot of device-specific exploit code to bypass properly. Realistically, even if just the browser was exploited and the kernel and runtime around it were perfectly secure, you'd still have a huge problem. Your browser is where all the access tokens and passwords go into and where your search history is coming from. I wouldn't bank on these long unmaintained devices, but I think they're fine to use for most people.
- Maxburn 4y agoGood point on the browser, so you'd need to go through and uninstall old browsers (if you can) and change the default browser. I agree, seems like this is prolonging things and just delaying the inevitable.
- GuB-42 4y agoYou don't. Android has pretty good "defense in depth" security, from screening in the Play Store, to the app sandbox, to kernel hardening. If you only get reputable apps from reputable sources, have an eye on phishing attempts, and have no reason to think you are a target, you may afford to have a few weak spots in your system. A lot of people run outdated Android version, and most don't get hacked, and among those who do, it is almost always phishing techniques that software updates wouldn't have prevented. If you really can't, it you have a popular, higher-end Android phone from years ago, you may find up-to-date custom ROMs, that you can further optimize for security.
- Maxburn 4y agoYou don't is my position. Lots of things that can be done past end of support to extend it a bit but you are right it's all shades of gray.
- bakugo 4y agoYou don't, because you mostly don't have to unless you're installing random malware apps, same as a desktop computer. "If you use a phone that hasn't been updated in 2 months the evil hackers will hack into it and make the battery explode to kill you" is fear-mongering from hardware manufacturers.
- _def 4y ago2 months... How about, 2 years :p