7 ms·
> Everyone who has reason to fear a state actor should not use smart phone except for truly innocent activity. It's just insecure. The real lesson here is to n
by dngray 3y ago
> Everyone who has reason to fear a state actor should not use smart phone except for truly innocent activity. It's just insecure.
The real lesson here is to not have unsupported devices in your possession. This malware uses 5 exploits which were from 2021.
> Probably some immutable Linux distro would be better. Are there guides out there how to do that for non-experts?
Android is an immutable system, but it doesn't help when people won't upgrade to a supported device. A "linux distribution" isn't going to help when there are proprietary firmware components that aren't updated.
> Without being opposition in some of that state, most of us handle money in their insecure devices. Can we be sure that "ordinary" criminals don't have enough access for their purposes?
Easiest way is to minimize having unsupported devices. The Pixels have a 5 Y support period that includes the underlying firmware.
This article is misleading, they're not "zero days" when they were discovered 2 years ago.
- saagarjha 3y agoSupported devices, including Pixel phones, are often behind on security patches. Using such a device is better than using something completely supported, but that doesn't mean you'll be immune from these kinds of attacks. (Note that the exploits are from 2021 because that was when they were discovered–they are true zero days.)
- hypertele-Xii 3y agoThe real lesson is to mandate minimum support. Otherwise bigtech will use this as an excuse to destroy the environment for profit through increasing planned obsolescence.
- oezi 3y agoI would require 5 year mandatory security updates for all devices and another 5 years of support which customers can purchase for a fee which is capped at 5% of the sale price per year. Manufacturers which don't fix CVEs within 90 days must accept returns at full sale price. That would fix the whole economics around vulnerablities.
- jeroenhd 3y agoThe EU is working on a law that forbids selling devices with known vulnerabilities. This means manufacturers will either have to patch their stuff quickly or risk getting their entire lineup banned from sale if a serious security issue is found in their hardware. Stores will probably demand support lifetimes as well or they'll be stuck with unsellable stock once a company decides that three years of updates turned out to be too long after all. I think further provisions are necessary, such as source code escrow; once you go out of business or drop software support for a product, the entire code repository should open up to the public to fix it themselves, including the necessary keys to load the replacement software. It shouldn't matter if you use the same code base for other devices that you do support, if you're maintaining that code you may as well push those fixes out to older devices. The biggest issue with phones and tablets is that often the problem lies within kernel driver that the manufacturer has no control over. Qualcomm and friends are the biggest crooks here, sometimes dropping software support for their chips after only two or three years, with no realistic alternatives for sourcing SoCs.
- scarface_74 3y ago> The EU is working on a law that forbids selling devices with known vulnerabilities. How does that help when most vulnerabilities are found after the phone was sold?
- bzzzt 3y agoAt least there would have to be a way to check on the official support status for a device to determine if it may be sold, so more transparency.
- ethbr0 3y agoAdd in a mandatory portion of device sales that goes to responsibly-disclosed vulnerability bounties. It'd have some side effects of centralizing handset manufacture into a few manufacturers (and core component suppliers) and/or pushing more into using straight-Android. But making the economics more aligned with security, in a predictable way for the manufacturer, seems important enough to make the trade-off.
- scarface_74 3y ago> The real lesson is to mandate minimum support. Otherwise bigtech will use this as an excuse to destroy the environment for profit through increasing planned obsolescence. If by $BigTech you mean Google. Apple just released a patch for iPhone 5S devices (circa 2013) earlier this year.
- saiya-jin 3y ago> The real lesson here is to not have unsupported devices in your possession. No, the real lesson from any similar discussion is to never, ever, ever trust any cell phone, or any other form of computer, period. It literally doesnt matter who assembles device, codes/builds OS or does full stack creation of components. It doesnt matter how many gigatons of Apple's koolaid you drank. If you are smart, use other ways or at least change very frequently burner phones (not very ecological but once you are a target for anybody powerful enough, unfortunately such concerns evaporate). The idea that 'this next solution solves everything' is really dumb, it failed spectacularly every single time so far. The chain of elements from screen to packets sent over network, and network itself is extremely long and to claim each of the piece is 100% secure is not naive, just stupidly ignorant. Especially with all the scandals from manufacturers, NSA/CIA, Snowden revalations etc. Or just dont do anything else that everybody else is doing, states nor corporations have no reason yet to go after almost everybody out there. But if you hold any position of power, even completely apolitical then you are already a target for decades and no amount of OS updates will make your phone actually secure.
- kenjackson 3y agoRealistically almost everyone needs some degree of trust in computers nowadays. Except for the the guy who lives off the grid in the woods in the middle of no where, you can’t function without some degree of trust.
- joemazerino 3y agoThe TAG link referenced in this article outlines how they use a fully updated Samsung device as a honeypot. At the time, even a fully updated device wasn't protected.
- carlmr 3y ago>This article is misleading, they're not "zero days" when they were discovered 2 years ago. I thought lack of publication made them 0-days. If it's published it's not a 0-day anymore?
- sgc 3y agoWhen newer OS versions are fugly, user hostile hot garbage, people don't want to update. You need to provide long term support, but also not cannibalize your product for very dubious reasons.
- usr1106 3y ago> The real lesson here is to not have unsupported devices in your possession. That's of course a minimum requirement. But the analysis showed that it took e.g. Samsung 8 months from distributing vulnerable code to distributing the fix for one the CVEs. Google was faster, but even them it took several months. > Android is an immutable system, OK, system might not be a uniquely defined term here. As always it depends where you draw your system border. If you mean the system firmware image, it is probably immutable. Not sure whether all vendors use dmverity. However, I meant "the whole phone". Obviously Android phones are not immutable, you can install apps. And after rebooting they are still there and can again use the same vulnerability if there is one. What I meant by immutable is there is no way to install any executable code, because all storage that is writable is noexec. And even if a vulnerability exists and allows to mess with RAM, the corruption is gone at reboot (well, unless the write protection, code signing / dmverity itself is affected by the vulnerability). Without having really worked with most of them I understand Vanilla OS, Fedora CoreOS, Fedora Silverblue, and SUSE ALP all go into that direction (although they still allow installing additional containerized apps). Including a browser and an email client into the base image and removing the option to install anything else is what I meant with immutable Linux distro. When you update it, you install another signed image. Of course the supply chain for that image is then the risky part, you'll never have zero risk.
- benibela 3y agoBut the browser could run any kind of javascript code