Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Android security on the ropes with one-two punch from researchers (Link only due to copyright)
Ars Technica — LINK ONLY | by Dan Goodin

Posted on 08/13/2015 9:27:48 PM PDT by Swordmaker

Faulty Stagefright patch and newly reported sandbox bypass leave users exposed.

Link only due to copyright infringement issues from Ars Technica. Read more at the link.

READ THE ARTICLE AT ARS TECHNICA: Android security on the ropes with one-two punch from researchers


TOPICS: Business/Economy; Computers/Internet
KEYWORDS: android; security; technology; windowspinglist
The patch for the StageFright exploit released last week doesn't work in all cases and hackers can go ahead and breech Android anyway! Plus a new flaw in Android allows apps to break through the sandboxing. . . and steal data and passwords from other apps. Information in the Ars Technica article. — Swordmaker
1 posted on 08/13/2015 9:27:48 PM PDT by Swordmaker
[ Post Reply | Private Reply | View Replies]

To: dayglored; ShadowAce; ~Kim4VRWC's~; 1234; Abundy; Action-America; acoulterfan; AFreeBird; ...
Two more security hits on Android . . . the patch released by Google for StageFright last week, which they are still pushing out, doesn't fix the problem, and a new vulnerability that breaks the Android sandbox that allows apps to steal data and passwords revealed today. Info from Ars Technica. — PING!

Ping to dayglored and Shadow Ace for your lists. . .


Android Security
Ping!

If you want on or off the Mac Ping List, Freepmail me.

2 posted on 08/13/2015 9:32:15 PM PDT by Swordmaker ( This tag line is a Microsoft insult free zone... but if the insults to Mac users continue...)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker
We're gonna need a bigger boat.

Well, at least we need to consider starting up an Android ping list.

3 posted on 08/13/2015 9:37:30 PM PDT by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 2 | View Replies]

To: dayglored
Well, at least we need to consider starting up an Android ping list.

It's beginning to look as if there is a dire need for one.

4 posted on 08/13/2015 9:40:09 PM PDT by Swordmaker ( This tag line is a Microsoft insult free zone... but if the insults to Mac users continue...)
[ Post Reply | Private Reply | To 3 | View Replies]

To: Swordmaker; Abby4116; afraidfortherepublic; aft_lizard; AF_Blue; Alas Babylon!; amigatec; ...
More Android security problems, including a faulty patch release ... PING!

You can find all the Windows Ping list threads with FR search: just search on keyword "windowspinglist".

Thanks to Swordmaker for the heads-up.

Anybody want to start up an Android Ping List???

5 posted on 08/13/2015 9:40:27 PM PDT by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 2 | View Replies]

To: dayglored; ShadowAce
Yeah, dayglored and I will help any volunteer with the nuts and bolts of managing a list. . . how to manage a list. etc. We just have our hands full with our respective lists. I'm sure Shadow Ace can chime in with advice too.

Don't you all rush forward to volunteer, now, we just need one good person who loves Android and wants to help their fellow Android Freepers. . . There is a need on FreeRepublic. We'd be glad to help you learn the ropes.

6 posted on 08/13/2015 9:44:31 PM PDT by Swordmaker ( This tag line is a Microsoft insult free zone... but if the insults to Mac users continue...)
[ Post Reply | Private Reply | To 5 | View Replies]

To: Swordmaker

M4L Android


7 posted on 08/13/2015 9:56:35 PM PDT by Scrambler Bob (Using 4th keyboard due to wearing out the "/" and "s" on the previous 3)
[ Post Reply | Private Reply | To 1 | View Replies]

To: rdb3; Calvinist_Dark_Lord; JosephW; Only1choice____Freedom; amigatec; Ernest_at_the_Beach; ...

8 posted on 08/14/2015 3:44:01 AM PDT by ShadowAce (Linux - The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker

I’ll bite, I’m an android enthusiast and FR addict. How hard is it to run a ping list?


9 posted on 08/14/2015 4:45:14 AM PDT by ThunderSleeps (Stop obarma now! Stop the hussein - insane agenda!)
[ Post Reply | Private Reply | To 6 | View Replies]

To: ThunderSleeps

First!!!


10 posted on 08/14/2015 5:01:39 AM PDT by Stentor ("The best lack all conviction, while the worst are full of passionate intensity.")
[ Post Reply | Private Reply | To 9 | View Replies]

To: Swordmaker

http://www.theverge.com/2015/8/5/9099627/google-stagefright-android-vulnerability-protect-patch

Stagefright has had trouble getting around Android’s Address Space Layout Randomization protections (commonly known as ASLR). The bug can still be used to trigger unauthorized code — a troubling result under any circumstances — but ASLR system has made it difficult to reliably run any specific piece of code across a range of devices, a difficulty acknowledged by Drake himself.

from Twitter:
Hey guys! Instead of redoing/reproducing my work, why don’t you see if you can bypass ASLR via Stagefright!
— Joshua J. Drake (@jduck) August 3, 2015

Not as easy an exploit on the Android to execute, Ars Technica has lots of hype.

Huge PR hit for Android, and it is speeding up security updates to phones from months to weeks.


11 posted on 08/14/2015 6:35:30 AM PDT by dila813
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker

If you do start an Android Ping list, please add me to it.


12 posted on 08/14/2015 6:41:32 AM PDT by ibheath
[ Post Reply | Private Reply | To 1 | View Replies]

To: dila813
Not as easy an exploit on the Android to execute, Ars Technica has lots of hype.

No, Ars Technica doesn't hype. . . they report factual data. Hype is picked up by people who don't know what they are talking about and exaggerate it. An app seeking specific data can run tests across the sandboxes, once they've been breeched, seeking for what they're looking for until they find it. There will not be that many apps running.

This second exploit released yesterday does exactly that. . . combine the two and you have the perfect means of breaking security. The people who came up with it took up Drake's challenge and found it. OOPS.

Yes, it is a huge PR hit for Android, but even worse is that not all Android devices will be updated to patch the vulnerabilities this exploit uses so it will remain in the wild from now on. I have no doubt that future versions of Android will be safe from this exploit, and current Android devices that RUN the patch that eventually gets sent out will be also, but it is dependent on carriers and manufacturers being willing to follow through, and some just are not willing. Other than that, it's dependent on users themselves hearing about it and then finding it and applying it. . . and again some won't hear about it and some who do won't update, being convinced of their devices' current invulnerability.

13 posted on 08/14/2015 10:36:22 AM PDT by Swordmaker ( This tag line is a Microsoft insult free zone... but if the insults to Mac users continue...)
[ Post Reply | Private Reply | To 11 | View Replies]

To: ibheath; ThunderSleeps
If you do start an Android Ping list, please add me to it.

You have your first list member, ThunderSleeps

14 posted on 08/14/2015 10:37:29 AM PDT by Swordmaker ( This tag line is a Microsoft insult free zone... but if the insults to Mac users continue...)
[ Post Reply | Private Reply | To 12 | View Replies]

To: Swordmaker

link video of this attack being demonstrated without knowing anything out about the target phone. In other words, random target.

That’s the point, sorry if you don’t get it.

Its yet to be demonstrated in a blind attack on a random phone.

Theoretically, if you attack a enormous number of phones you will get a few.

Many exploits are very bad in effect, but the attack success rate is very low. This happens to be one of them.


15 posted on 08/14/2015 4:51:32 PM PDT by dila813
[ Post Reply | Private Reply | To 13 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson