39 ms·
Major Flaw in Android Phones Would Let Hackers in with Just a Text
- jbb555 11y ago"The bad guy creates a short video, hides the malware inside it and texts it to your number. " How can you "text" a video? Texting uses.... text. The clue is in the name. Not bothering to read the rest of the article.
- veeti 11y agoEver heard of MMS?
- elaus 11y agoThe acronym even says it: it's not a text message, it's multimedia. So the news seems to be about flaws in MMS handling, not SMS/text messages.
- joshuapants 11y agoYou're splitting hairs here, common usage of "texting" includes sending pictures, video, and audio.
- jacquesm 11y agoHe's not splitting hairs, he's probably just from 'somewhere else'. Here where I live (NL) texting someone means SMS, 'apping' someone is used for whatsapp and MMS is used for the rest.
- JosephRedfern 11y agoPerhaps you should read the rest of the article. You might learn something.
- daigoba66 11y agoMMS is colloquially known as texting, just as is SMS.
- dragonwriter 11y agoAnd, on most devices, there's no UI distinction between the two in use, MMS vs SMS is just a distinction the phone makes for messages by content.
- soylentcola 11y agoAdditionally, when someone using a non-standard messaging app (like whatever the default iOS app is), sends a message to my Android phone, it doesn't come through as an SMS but rather as an "attachment" to an MMS message.
- kolev 11y agoIt's known as "picture messaging".
- userbinator 11y agoPlease do bother to read the rest of the article. This is similar to sending malicious attachments with an email (which is just "text", after all) which the user's email client opens automatically.
- antillean 11y agoWord. I don't think I've ever heard/seen MMS referred to as "texting". Until I read the clarifications in response to this comment, this article made absolutely no sense to me.
- dang 11y agoPerhaps "texting" has different meanings in different regions? This feels like a cross-cultural glitch to me. Those happen on HN more often than people realize.
- Dylan16807 11y agoConfusion and disagreement with the wording is valid. Snootily declaring "not bothering to read the rest", though...
- cosarara97 11y agoGoogle might have to rethink Android's updating strategy, if vulnerabilities like this keep coming out. Of course it would be nice to never have to update some devices, but it's not viable if they are: a) As complex as an Android phone and b) Connected to the internet/phone network.
- fpgeek 11y agoThe update strategy has been rethought and, frankly, I'd be surprised if anyone needs to release an OS update to fix this. Google clearly can and will just update the Hangouts app (if they haven't already). I'd expect most other manufacturers to just put an update for their OEM messaging app on the Play Store (if they don't already have a hook in something like an updateable OEM framework app they can use).
- shkkmo 11y ago> But Adrian Ludwig, the lead engineer for Android Security, told NPR the flaw ranks as "high" in their hierarchy of severity; and they've notified partners and already sent a fix to the smartphone makers who use Android. It sounds like the fix can't be (or isn't being) made in the hangouts app.
- shawn-butler 11y agoIt isn't an Hangouts app issue, that is just a one attack vector. It is/was an issue in Stagefright. Details of CVE-2015-1538, CVE-2015-1539, CVE-2015-3824, CVE-2015-3826, CVE-2015-3827, CVE-2015-3828, CVE-2015-3829 probably available soon?
- fpgeek 11y agoSo the Hangouts bit is just about triggering the problem without user intervention? If an attacker can find another way to get you to play a malicious video, there's still a hole? That's clearly more serious.
- stormcrowsx 11y ago
- mikegerwitz 11y agoThere's hype, but is there any actual information about the vulnerability anywhere? Best I was able to find was this: http://blog.zimperium.com/the-biggest-splash-at-blackhat-and-defcon-2015/ Even a CVE?
- ctz 11y agoWow! They managed to distill everything that's wrong with the infosec industry into one page!
- bostik 11y agoFrom the short description in the article we know that the bug is somewhere in the default video codec paths. (Triggerable by embedded and automatically processed video file.) Of course that doesn't tell much, since the potential attack surface is a big one. I wouldn't rule out browser as attack vector but I do think the heavy sandboxing at least limits damage and scope. As the article points out, messaging apps are in a different class. Will be interesting to see how this develops. And because the vulnerability is in the system libraries, any app that can deliver video content may be used as an attack vector.
- veeti 11y agoThe vulnerabilities are in Android's "stagefright" media internals. Patches are floating around, for example: http://review.cyanogenmod.org/#/c/103270/1 http://review.cyanogenmod.org/#/c/103270/1
- shawn-butler 11y agoReferenced CVE-2015-1538, CVE-2015-1539, CVE-2015-3824, CVE-2015-3826, CVE-2015-3827, CVE-2015-3828, CVE-2015-3829 issues seem to still be in reserved status.
- hakam 11y agohttps://www.facebook.com/hakam.naser.al.deen https://www.facebook.com/hakam.naser.al.deen
- infinity0 11y agoIt's annoying that the media continues to incorrectly spin Android's security updates problem as somehow caused by its open ecosystem (which itself barely meets the definition of open) and implying that Apple's closed system is the solution. GNU/Linux distros are free open source software, and don't suffer from these sorts of update problems. Many distros have special high-priority security update channels that are enabled by default. Please, call this out if you have friends writing / spreading such nonsense.
- JustSomeNobody 11y agoThey do this for the page views.
- shkkmo 11y agoUm... I don't think the article in question does this. It seems to describe the issue accurately: Updates are dependent on fixes being pushed out by device manufacturers and network carriers.
- infinity0 11y ago"Android phones are very different from iPhones, for example. Apple runs a closed system. It controls the hardware and software, and it's fairly easy to ship out a major revamp. The company says 85 percent of iPhone users have the latest operating system, iOS8." The fact that Apple runs a closed system is not relevant to Android having poor security updates, as is evident by how GNU/Linux distros work - yet these things are mentioned next to each other, as if they are related. (edit: lots of people missing the point here. media articles can equally point to free open source software GNU/Linux distros as having relatively successful security update mechanisms, yet Apple's closed ecosystem is always given more focus as the contrasting example to Android's; why? it is not the closed property that makes a security update mechanism succesful, yet that is the implication.) (edit: this is how weasel wording works; statements of fact which may be individually correct, are placed together in suggestive positions, so that the non-cautious reader walks away with a false understanding of a more complex point, but allow the author to deny responsibility of this) Other media articles have similar weasel wording. I'm not commenting on the author's intent - e.g. they may just be repeating the dominant narrative on this - however the wording has misleading connotations regardless of intent.
- forcer 11y agoI guess simplest fix for the user is to disable MMS? I don't think its that popular feature anyway?
- Someone1234 11y agoI'm not sure video MMS are popular, but I send a lot of picture MMS texts. Considering it is included on T-Mobile's Simple Choice and doesn't require the recipient to sign up to some service to receive them, it is pretty convenient. If this issue got bad I might disable it. But it would be unfortunate to have to do so.
- pja 11y agoCan you actually disable MMS on Android phones? You can stop the default messaging app from automatically downloading them on my phpne, but I can’t find a way to completely disable them.
- nly 11y agoIs removing the MMS options under the APN enough to do this?
- shkkmo 11y agoThat's a good question. Presumably if your phone doesn't have network access for MMS it can't download the message in the first place?
- pmx 11y agoJust set you MMS settings to something that looks valid (so the phone will accept them) but non-working. There is then no way it's going to download 'em.
- Oletros 11y agoYou can disable auto retrieve of MMS in the messaging applications
- ocdtrekkie 11y ago
- pja 11y agoThe real problem here is that video messages expose a huge attack surface to bad actors, very little of which has been security audited. Automatically parsing videos before the user even chooses to interact with them makes it even worse - although I suspect most people would play a video sent to them over MMS even if it came from an unknown contact.
- nsgi 11y agoEven if it does come from a known contact, they could have a worm.
- lsaferite 11y agoThe patches he submitted were to the kernel? He says it will take a long time for those patches to make it to devices, but I question the validity of the assertion simply because Google has moved more and more into the Play framework. So, unless it is truly a kernel bug I would expect that it's fixable in the framework ore target application. Please correct me if I am mistaken though.
- s73v3r 11y agoLots of things are still not in the Play framework. Stuff like this, for instance.
- justin66 11y agoI heard the radio bit and thought it sounded reasonable. The one explanation that was missing was how this exploit fits in with those apps' permissions. The article makes it sound as though the compromised apps get root, which shouldn't really be possible.
- pakled_engineer 11y agoI disabled hangouts on a device I couldn't build from source, then got a constant alert it was trying to start again (Hangouts has unexpectedly stopped notice) so blacklisted it in startup scripts. Google gives you no option to remove it.
- ocdtrekkie 11y agoCould it still be selected as the default messaging app? I had no issue disabling Hangouts on my Android 4.4 device.
- pakled_engineer 11y agoReboot your phone, it will start again and try to make itself default messaging app unless you edit init .rc scripts, on 5.1.1 Android anyway.
- ocdtrekkie 11y agoI recommend not being on Android 5.x.
- AdmiralAsshat 11y agoThis is definitely a huge problem, but I only see it being a doomsday scenario if you're using the default SMS app that ships with your phone (and hence cannot be updated with a patch pushed by your OEM). Assuming you're using Hangouts or Messenger[0] (which is sorta like Hangouts without Gmail), however, as your default SMS app, you should be fine as soon as they patch it. And both of those apps are freely available to download, meaning you could always grab them once they're patched and start using them as your default SMS app if you're worried about it. [0] https://play.google.com/store/apps/details?id=com.google.android.apps.messaging https://play.google.com/store/apps/details?id=com.google.and...
- Matt3o12_ 11y agoTry to convince the average user to install a new app, and make it the default sms app. He will neither want nor understand the trouble of learning a new app for something that works just fine. And honestly, I don't blame them because that is not something they should have to worry about. Android should rather work on a feature that allows them to patch their not-so-open operating system just like Apple does (or use a concept that is close to the one in the GNU/Linux world but I don't think Google is gonna do that).
- AdmiralAsshat 11y agoThis is true, but in the case of Messenger, you should consider the following: - It's made by Google (i.e. the guys who made the phone's stock SMS app) - It has nearly identical navigation to the stock "Messages" app, simply with a much cleaner interface - It does not hook into anything other than your contacts, unlike Hangouts For all intents and purposes it's the successor to the stock app, made a separate app specifically so that it can receive timely updates without being tied to a system update. Having used both, there's really no compelling reason not to switch to it (sans the grandma-with-a-smartphone edge case who has never opened the Play Store).
- muraiki 11y agoOther comments have mentioned that Hangouts is not the only possible attack vector, but I'll be honest in saying that I don't really understand all this. :)
- leephillips 11y agoCan I configure my phone to reject text messages with attached video? I'm thinking that would protect me from this exploit, plus, as a bonus, I wouldn't get text messages with attached video. EDIT: I appreciate the replies. I was really wondering if I can disable video attachments without disabling other MMS features such as pictures and long messages (in Android 4.3).
- irremediable 11y agoI'm pretty sure you can just turn off MMS retrieval, yeah -- either in your messaging app or the phone's network settings. The only problem is that many phones automatically turn long SMS messages into a single MMS message. As I understand it, you might not receive those -- although I'm not sure about this.
- mikelward 11y agoDisabling MMS under Settings -> Mobile Networks -> Access Point Names might help.
- kitd 11y agoI assume this can be avoided to some extent by switching off Autodownload of MMS messages in Hangouts?
- bitmapbrother 11y agoThese look to be the flaws: http://review.cyanogenmod.org/#/c/103276/ http://review.cyanogenmod.org/#/c/103276/ http://review.cyanogenmod.org/#/c/103275/ http://review.cyanogenmod.org/#/c/103275/ http://review.cyanogenmod.org/#/c/103274/ http://review.cyanogenmod.org/#/c/103274/ http://review.cyanogenmod.org/#/c/103273/ http://review.cyanogenmod.org/#/c/103273/ http://review.cyanogenmod.org/#/c/103272/ http://review.cyanogenmod.org/#/c/103272/
- nly 11y agoThis is pretty awful code. I saw "buffer[size] = 0" and assumed immediately that was a past-the-end write, but they actually allocate size + 1 bytes. Urgh. Next they introduced a check for strings shorter than 6 bytes because that's the shortest possible valid string. Why not just check for a valid encoding in the first place? There are too many implicit assumptions about the data going on here and not enough actual validation. This entire module needs scrapping and rewriting with a proper FSM/parser generator. And why is an MPEG4 metadata decoder directly handling UTF anyway?
- makomk 11y agoWow. Integer overflows and underflows all over the place. It's almost like no-one's ever even taken a fuzzer to this before, which would surprise me given that Google is usually relatively security-concious.
- alfiedotwtf 11y agoOr it's almost like it was done on purpose as a backdoor.
- TD-Linux 11y agoThis code is probably written by embedded software engineers like myself. No one knows anything about security, and certainly hasn't heard of a fuzzer. If the code works, it ships. The other parts of Android written in C++ are also a horror show, though I think they have gotten better recently. And don't even talk about the proprietary HAL blobs or kernel modules. Unspeakable things happen there. And of course, libstagefright talks directly to these.
- dimino 11y agoIs there a CVE? I'm not sure I understand, and this article only serves to confuse. Consider this line, at the beginning: > In this attack, the target would not need to goof up — open an attachment or download a file that's corrupt. Is this line simply erroneous?
- deleted 11y ago[deleted]
- biggerfisch 11y agoHangouts has an option under "SMS" to disable automatic retrieval of MMS messages. Can anyone confirm if this at least stops the instant loading of malware?
- pd1 11y ago+1, this is all I have done
- pmalynin 11y agoI only wish that there'd be a way to flash a custom ROM on an Android phone... hmmm....
- Zikes 11y agoAt first I thought Stagefright was the catchy name for the bug, and I expected to see a nifty logo for it as well.
- david_shaw 11y agoIt's not, but it seems like the term is being used that way anyway. I've heard "is your device vulnerable to Stagefright?" quite a few times already.
- ck2 11y agoand tens of millions of phones will never be patched this is a nightmare bug that will haunt android forever I can already imagine many celebrities getting hacked through it
- 13 11y agoWhy target people specifically? A phone has all the tools necessary to infect every other peer they can reach. Almost instant billion device botnet, each with a new list of targets to infect in the contacts book. It'll be interesting if this does happen, and the same mistakes as early worms are made (global internet pipe denial of service by probes attempting to find new hosts to infect).
- ck2 11y agoWhoa, never thought of that, but blackhats certainly will. If they get one celebrity, they could get all their friends. I predict a second one of these https://wikipedia.org/wiki/2014_celebrity_photo_hack https://wikipedia.org/wiki/2014_celebrity_photo_hack Ironically this time iphone users will be protected.
- 13 11y agoProbably has engineering challenges past what you would normally face, which thankfully makes a 1B device botnet a little unrealistic. I can't imagine how you'd even begin to control such a thing, just a sequential numerical list of the clients is 4GB. Scary prospect though.
- endymi0n 11y agoNot too far off. There's your discovery layer: https://en.wikipedia.org/wiki/Kademlia https://en.wikipedia.org/wiki/Kademlia C&C: http://www.reddit.com/r/netsec/comments/2pmmfu/using_the_blockchain_as_a_cc_for_a_botnet/ http://www.reddit.com/r/netsec/comments/2pmmfu/using_the_blo... Persistence Layer: https://github.com/cockroachdb/cockroach https://github.com/cockroachdb/cockroach Dissemination Layer: https://en.wikipedia.org/wiki/Gossip_protocol https://en.wikipedia.org/wiki/Gossip_protocol Sprinkle in some AES and public / private keys for verification and you're done. Sequential list isn't needed. (well, all the robust & stealthy large systems engineering together with the low level exploit knowledge is probably a little too much for one person to pull it off, but for a Hacking Team or nation sized actor it's quite doable)
- jimrandomh 11y agoSummary: MMS messages can cause Android phones to decode video with libstagefright, which is a C++ library with vulnerabilities and insufficient sandboxing, leading to remote code execution without user interaction. You can partially mitigate the risk by disabling auto-downloading of MMS messages in whichever app you have set to handle text messages, such as Messaging or Hangouts. THIS IS URGENT. While the precise details of the flaw have not been publicly disclosed, this disclosure is sufficient for a skilled person to rediscover the flaw, which means that there is a considerable risk that someone will systematically use it on all the phone numbers.
- deleted 11y ago[deleted]
- 13 11y agoIt's likely too late for panic, everyone is probably owned already. It has the best infection vector ever, unauthenticated, unsolicited messaging with an easily discoverable addressing method. What more could a worm want?
- ksenzee 11y agoWouldn't you know if you'd received a sketchy MMS from a number you didn't recognize?
- ChrisAntaki 11y agoNot if the attacker deletes the message post-pwnage.
- Florin_Andrei 11y agoBut wouldn't there be a trail of notifications, or something?
- 13 11y agoIf malware has root access it can alter everything on the phone without you ever seeing it. Any information falsified, all detection tools subverted.
- pwnna 11y agoI see a series of patches going on CyanogenMod (5 on 12.1 and only 3 on 12.0). Are there any more? 1. http://review.cyanogenmod.org/#/c/103267/ http://review.cyanogenmod.org/#/c/103267/ 2. http://review.cyanogenmod.org/#/c/103268/ http://review.cyanogenmod.org/#/c/103268/ 3. http://review.cyanogenmod.org/#/c/103269/ http://review.cyanogenmod.org/#/c/103269/ 4. http://review.cyanogenmod.org/#/c/103270/ http://review.cyanogenmod.org/#/c/103270/ 5. http://review.cyanogenmod.org/#/c/103266/ http://review.cyanogenmod.org/#/c/103266/
- 0x214655434B21 11y agoLooks like all of jduck's commits are fixes for libstagefright. https://github.com/CyanogenMod/android_frameworks_av/commits/cm-12.0?author=jduck https://github.com/CyanogenMod/android_frameworks_av/commits...
- guelo 11y agoIf a two year old phone doesn't get security patches is that enough for massive class action lawsuits? It's a defective product.
- stormcrowsx 11y agoWith most manufacturers you do good to get updates after 6 months. I'd like to see a class action on it but have no idea of its feasibility.
- pasbesoin 11y agoA bit over a year ago, I bought the first generation Moto X from... well, Verizon "sold" me the phone, but it shipped directly from Motorola, then owned by Google. For reasons I'll mostly skip (signal/reception), I needed to stay with Verizon. I bought the Moto X largely on the... assurance ("promise"?) that this particular phone, coming from a Google-owned Motorola, would actually be updated expeditiously by not just the manufacturer but also, downstream, Verizon. Well, about a month ago my still 4.4.4 phone received an update. FINALLY. Then I looked at the version information; still at 4.4.4 . I tell you, Google, I'm about done with your mobile products. Not that I hate dealing with them, with Android, but the U.S. (and elsewhere?) ecosphere for them simply sucks. At least I am at 4.4.4 . Were I at 4.4.3, the last I read I would be subject to a web component vulnerability that Google has refused to fix below 4.4.4 . I suspect there are a lot of phones and tablets stuck at 4.4.3 or below. In fact, my parents have one, a Samsung tablet sold to the by... VERIZON, about a year and a half ago. (And they didn't buy at the cheap/old end of Verizon's tablet offerings.) I am DONE with this bullshit. Meanwhile, Apple seems to have added some efficiencies to iOS that now allow a 4s phone (not sure about 4) to work reasonably well. I was staying away from Apple's rather closed ecosphere and attitude. I am seriously reconsidering, at this point. I need my primary phone to fucking work and be reliable. I'll keep the more experimental stuff to other platforms.
- tcfunk 11y agoI am with you on this. Though I wish running into the arms of Apple wasn't the answer (was really hoping Ubuntu phone would be an option but that is seeming more and more unrealistic). The fact that the only way to get reasonably-paced system updates is to install 3rd party operating systems (e.g. Cyanogenmod) is extremely frustrating.
- guelo 11y ago> Drake speculates that Stagefright has its excessive permissions and Internet access to satisfy some types of digital rights management processing or streaming playback. Goddamn you Hollywood.
- higherpurpose 11y agoLet's not forget the companies that not just caved to Hollywood, but actively promoted their ideas at W3C and so on (see EME, etc). They share the blame, too. They can't all just throw their hands up in the air and say "they made us do it".
- bcg1 11y agoConsidering that perspective, the irony of the name "Stagefright" is not lost.
- Jehops 11y agoI don't see any mention of Stagefright in the article.
- guelo 11y agoLooks like the moderators switched out the article. It used to point to this one https://threatpost.com/android-stagefright-flaws-put-950-million-devices-at-risk/113960 https://threatpost.com/android-stagefright-flaws-put-950-mil...
- acqq 11y ago"The problem is that Stagefright is an over-privileged application with system access on some devices, which enables privileges similar to apps with root access. Stagefright is used to process a number of common media formats, and it’s implemented in native C++ code, making it simpler to exploit This is huge.
- deleted 11y ago[deleted]
- 11y ago
- Animats 11y agoFrom the article: "The messaging app Hangouts instantly processes videos, to keep them ready in the phone's gallery." Do you have to have the "Hangouts" app installed for this security vulnerability? Google doesn't seem to have learned from Microsoft's decade of "autorun" problems. It has been (0) days since the last C language buffer overflow vulnerability.
- McGlockenshire 11y ago> Do you have to have the "Hangouts" app installed for this security vulnerability? No. The flaw is present in the extraction of the image data from the MMS message. Anything that uses the system standard way of doing this, including but not limited to Hangouts, will be vulnerable. Hangouts retrieves MMS messages by default. This can be disabled under Settings => SMS. Turning this off disables the automatic processing and thus the passive exploit, but opening an MMS message containing the exploit can still be done by hand.
- yodon 11y agoWhat is the telecom law, if any, on text message delivery? It seems like the first network to announce "we block all stage fright export messages before they hit your phone" would win a huge PR coup (and they'd be able to do so much faster than trying to prep updates for every device they ever sold).
- mschuster91 11y agoWhy can't Google force vendors and carriers in the Play license terms to open source their kernel and flashing technology so XDA and friends can take care of updates? That would be the cheapest solution. edit: added benefit, everyone is free to load on his device whatever he chooses. Google should have gone that path way earlier.
- Johnie 11y agoThis overestimates the negotiating position of Google and underestimates the negotiating position of the manufacturers and carriers. In the US, the business model for mobile phones is that carriers buy phones from the manufacturer and sell it to the end consumer. The carriers have ultimate influence on what they purchase which affects what the manufacturers produce. You, the end consumer, is a consumer of carriers rather than phone manufacturers.
- mschuster91 11y agoWell, no Google Android, no phones - Google has a massive stronghold on the market, every consumer wants the latest and greatest phone. Their stronghold is even enough to prevent ODMs (!) from building non-Play-licensed phones - either you only ship non-play-licensed phones or you ship only licensed ones. No in-between.
- johncolanduoni 11y ago> Well, no Google Android, no phones - Google has a massive stronghold on the market, every consumer wants the latest and greatest phone. It isn't that simple. Although creating a successful smartphone platform from scratch would be very difficult, if enough manufacturers got tired of the terms they might band together are create an app store to rival Play while maintaining Android compatibility. In this case, app developers would only need to change code for in-app purchases, licensing, etc. so a large enough group of manufacturers could draw a significant number of apps to the new store.
- johncolanduoni 11y ago
- dang 11y agoWhat's the best URL for this story? It has been posted many times already.
- danyork 11y agoThere are a good number of stories now out about this: http://www.techmeme.com/150727/p8#a150727p8 http://www.techmeme.com/150727/p8#a150727p8 It seems one of the original reports is here: http://blog.zimperium.com/experts-found-a-unicorn-in-the-heart-of-android/ http://blog.zimperium.com/experts-found-a-unicorn-in-the-hea... I'd also note that it seems this is research that will be presented next week at Black Hat and then again at DefCon.
- dang 11y agoHN does prefer original sources generally, but breaking stories like this one often produce articles with additional reporting as they develop. So it's not obvious that the original post has the most relevant information at this point. If someone wants to figure out which URL does, we can change the HN thread to use it. It's currently pointing to the npr.org story rather arbitrarily, but perhaps that's as good as any.
- deleted 11y ago[deleted]
- Abundnce10 11y agoFor TextSecure users, will this be an issue? Usually I'm prompted before I download a image/video. Do you think I'm okay using TextSecure?
- pasbesoin 11y agoI was just looking at the settings the other day. Per other comments in this topic, I'd look at disabling the MMS features; IIRC TextSecure also has user settings for this. Edit: Just had a look. I do not have TextSecure as my default client. There is MMS configuration information, but not a simple "disable automatic retrieval" or similar setting, as there is in my default SMS/MMS client. I don't know whether one appears when TextSecure is the default client; I suspect not, and maybe this should be addressed?
- Abundnce10 11y agoI don't see any option to disable it and I use it as my default client.
- simoncion 11y agoIt turns out that media attached to an MMS message is not decoded until you actually open the attachment. See: https://github.com/WhisperSystems/TextSecure/issues/3817 https://github.com/WhisperSystems/TextSecure/issues/3817
- pasbesoin 11y agoThanks, moxie (he's on HN). Maybe I will make TextSecure my default app. I'll give "the hype" a day or two to start sorting itself, while I have the "auto" stuff disabled in my current default app.
- simoncion 11y agoAs an additional datapoint: In my -and my lady friend's- experience, TextSecure is the the only app to correctly handle MMS group chat. We tried the stock Android app, the stock Samsung app, and Hangouts. They all failed to do the right thing in one way or the other.
- taco_emoji 11y agoAnybody know if Textra is affected, if I turn off MMS auto-downloading?
- mSyke 11y agoI know this will soon be patched, but would it be theoretically possible to run a root exploit that would root a phone and install a superuser management app? Root your phone with just a text. That would be an interesting exploit.
- G3E9 11y agoWe're thinking along the same lines. It'd be interesting to root your device while navigating around any voided warranties on the basis of your carrier's, or Google's, neglect (I am definitely not a lawyer.) AND... could one possibly use this exploit to push their own patch? Could someone who has a payload with a fix mass-message all android users? That payload could also try and send itself to others within the then-patched device's contact list.
- deleted 11y ago[deleted]
- mSyke 11y agoI know this will soon be patched, but would it be theoretically possible to run a root exploit that would root a phone and install a superuser management app? Root your phone with just a text. That would be an interesting exploit.
- stevenh 11y agoNow would be a good time for Apple to spread word of this disaster far and wide and to offer a free iPhone to anyone who brings in an Android phone for recycling.
- aikah 11y ago> Now would be a good time for Apple to spread word of this disaster far and wide and to offer a free iPhone to anyone who brings in an Android phone for recycling. an opportunity for Microsoft too. Clearly this plus the web-view exploit fiasco will damage the android plate-form for the long run. Hundreds of millions of devices are affected by this exploit and most of them will never be patched. I'm sorry to say but i'll have to pressure my IT department to ban android devices, period. The problem isn't the MMS tech, the problem is android's lousy security model. And the fact that Google think it can wash its hands off all this and shift the blame on manufacturers... outrageous. While some manufacturers actually opensource their android 'implementation' (like Alcatel, you can actually download some source code for a specific device and patch it yourself) , most don't even bother doing that. This stuff is a disaster.
- ocdtrekkie 11y agoAbsolutely true. It's very clear a platform that can't ensure security fixes in a timely manner doesn't belong in the hands of anyone who handles private data. "Android for Work" isn't much of an option for anyone who values security.
- rodgerd 11y agoMicrosoft should be all over it. Apple's products need less of a boost.
- codeshaman 11y agoWhen a vulnerability like this becomes public, I always wonder - how many people knew about it before it became public, for how long and how much has it been exploited. And I also wonder how many more critical exploits are known and used by 'hackers' or agencies today while we have this puffy feeling that our data/communication is private and secure ? The conclusion I can draw from this: never trust that your phone is secure. Or computer for that matter.
- leke 11y agoThis is why my next phone will be running Unbuntu.
- bitmapbrother 11y agoBecause Linux is free of exploits...
- samuellb 11y agoWell technically Android runs Linux (the kernel) too. But Ubuntu can be updated. My HTC Android phone only had a single update (almost when I got it) and it's been vulnerable since. I'm not going to replace my phone each time there's an exploit that the manufacturer doesn't fix. So I don't think an Ubuntu phone would be such a bad idea.
- leke 11y agoYep, this is why I said it. I assumed everyone knew about Ubuntu's update strategy.
- anh79 11y agoThanks Android. You make life much easierr :)
- MBlume 11y agoIf anyone's looking, MySMS has the relevant setting behind "advanced settings"
- alphanumeric0 11y agoJust a_text
- deleted 11y ago[deleted]
- lop9ctrunghatq 11y agowww.facebook.com/thiet.bao.75
- lop9ctrunghatq 11y agowww.facebook.com/thiet.bao.75
- lop9ctrunghatq 11y agowww.facebook.com/thiet.bao.75
- lop9ctrunghatq 11y agowww.facebook.com/thiet.bao.75