Android Stagefright flaws put 950 million devices at risk

Discussion in 'other security issues & news' started by Minimalist, Jul 27, 2015.

  1. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
    https://threatpost.com/android-stagefright-flaws-put-950-million-devices-at-risk
     
  2. Gullible Jones

    Gullible Jones Registered Member

    Joined:
    May 16, 2013
    Posts:
    1,466
    Now watch lots of vendors continue to not provide any patches for old phones.
     
  3. Gullible Jones

    Gullible Jones Registered Member

    Joined:
    May 16, 2013
    Posts:
    1,466
    So, my phone is an affected model (no kidding). Posted about this on the vendor's support forum... 12 hours later, no replies. I don't know if they're even updating the newer phones. There are 3-4 other posts about this, and no replies to any of them.

    Absolutely shameful. I'd say this is a breach of contract on their end, but of course they're smarter than that; they retain the right to sue, I don't. Jerks.

    Anyway, right now my Android phone is lying on my desk with the battery removed. I'm considering transferring the number to a dumb cell phone. Too bad I'd have to keep paying the vendor for service I was not recieving. Yay!

    P.S. What's with the Heartbleed analogies? This is more like Shellshock, actually really serious.
     
  4. subhrobhandari

    subhrobhandari Registered Member

    Joined:
    Nov 6, 2009
    Posts:
    780
    How many of the models would get patched? I think the vendors would only issue OTA for flagships, the rest will be left out. I was thinking about shifting into the ship of smartphones, but after this, would buy another dumbphone until Linux/Firefox OS gets matured.
     
  5. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
    Yes I find this a big problem also. Most vendors just stop supporting older models and stop releasing newer Android versions. That means that after few years, your smartphone becomes insecure. Vendors should release support lifecycle for their devices so that users would know how long their devices will be safe to use.
     
  6. new2security

    new2security Registered Member

    Joined:
    Aug 8, 2008
    Posts:
    517
    Would disabling "auto mms download" feature mitigate this?
     
  7. Gullible Jones

    Gullible Jones Registered Member

    Joined:
    May 16, 2013
    Posts:
    1,466
    OTOH, there's an unexpected benefit to this: smart phones are quite distracting to carry around turned on all the time. I'm using a flip phone instead today, and I feel like my IQ has increased by a few points.
     
  8. artoor

    artoor Registered Member

    Joined:
    Oct 13, 2012
    Posts:
    113
    Location:
    Poland
    I guess so, however, not only by receiving MMS your smartphone can be compromised :(
     
  9. new2security

    new2security Registered Member

    Joined:
    Aug 8, 2008
    Posts:
    517
    Sometimes I regret getting a smartphone. It gives me sore fingers and on top of that security issues.
    I miss the good old gsm only phones.
     
  10. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
    Trend Micro Discovers Vulnerability That Renders Android Devices Silent
    http://blog.trendmicro.com/trendlab...rability-that-renders-android-devices-silent/
     
  11. Dragon1952

    Dragon1952 Registered Member

    Joined:
    Sep 16, 2012
    Posts:
    2,470
    Location:
    Hollow Earth - Telos
  12. subhrobhandari

    subhrobhandari Registered Member

    Joined:
    Nov 6, 2009
    Posts:
    780
    What about the other browsers?
     
  13. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
    I don't know, it's not mentioned in that article.
     
  14. safeguy

    safeguy Registered Member

    Joined:
    Jun 14, 2010
    Posts:
    1,795
    Thanks. Nothing much I can do other than to follow the mitigation suggestion for now.
     
  15. BoerenkoolMetWorst

    BoerenkoolMetWorst Registered Member

    Joined:
    Dec 22, 2009
    Posts:
    4,872
    Location:
    Outer space
    Note that TextSecure doesn't autoplay and gives a warning first:
    https://lists.riseup.net/www/arc/whispersystems/2015-07/msg00084.html
     
  16. Dermot7

    Dermot7 Registered Member

    Joined:
    Dec 20, 2009
    Posts:
    3,430
    Location:
    Surrey, England.
    http://blog.trendmicro.com/trendlab...s-not-the-only-attack-vector-for-stagefright/
     
  17. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    163,907
    Location:
    Texas
    http://www.net-security.org/secworld.php?id=18726
     
  18. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
    Samsung announces new Android security update process, promises over-the-air patches ‘about once per month’
    http://venturebeat.com/2015/08/05/s...es-over-the-air-patches-about-once-per-month/
     
  19. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    163,907
    Location:
    Texas
  20. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
    Android's 5 biggest security flaws 2015
    http://www.techworld.com/security/androids-5-biggest-security-flaws-2015-3622116/

     
  21. Dermot7

    Dermot7 Registered Member

    Joined:
    Dec 20, 2009
    Posts:
    3,430
    Location:
    Surrey, England.
  22. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    163,907
    Location:
    Texas
  23. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
    IBM finds another Android phone bug
    http://www.techworld.com/news/security/ibm-finds-another-android-phone-bug-3622384/

     
  24. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    163,907
    Location:
    Texas
    http://www.theverge.com/2015/8/13/9148437/android-stagefright-vulnerability-disclosure-exodus-patch
     
    Last edited: Aug 18, 2015
  25. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    163,907
    Location:
    Texas
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.