Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
Android Security: 8 Signs Hackers Own Your Smartphone
Newest First  |  Oldest First  |  Threaded View
<<   <   Page 3 / 4   >   >>
sjennison
50%
50%
sjennison,
User Rank: Apprentice
12/9/2013 | 8:19:59 PM
Re: MISCONCEPTION
Agreed. In fact, custom ROMs are generally more secure, due to constant updates(nightly, weekly, or monthly, depending on the developer). That is assuming, of course, your ROM dev is fast on their updates.

In fact, the major "master key" exploit, which is one of the biggest security holes, was patched by Cyanogenmod long before the vast majority of manufacturers got around to fixing it.

http://www.ubergizmo.com/2013/07/cyanogenmod-10-1-2-fixes-android-master-key-exploit/

Also, generally rooting allows you to do things like fix the security holes in the system. Rooting installs a root control app (Superuser/SuperSu, etc) that restricts access to only apps the user allows. While the device can still be comprimised using privledge escalation vulnerabilities just like any other device, rooting will not make your device insecure. The very fact that a device can be rooted using exploits means it is inheirently insecure due to those same exploits. A malicious piece of software could exploit them just as easily. Rooting doesn't change that, unless you go deeper and actually fix the hole (assuming you can). Hence where custom ROMs come in - when a vulnerability is found, they release patches in less than a month. The only other OEM who comes close to that speed is Google. Nearly every other manufacturer takes months if not years to push an update through to end users.
krishel67801
100%
0%
krishel67801,
User Rank: Apprentice
12/5/2013 | 2:47:00 PM
google aps
Google Play Store is malware in itself.  I have numerous aps that require play store services to be activated.  Play store then accesses your phone whenever it wants to.  Also play store will not allow aps that block advertising to be obtained thrrough them.  Another good reason for rooting your phone.  Take control away from google.
Aroper-VEC
50%
50%
Aroper-VEC,
User Rank: Apprentice
12/2/2013 | 10:31:04 PM
Re: MISCONCEPTION
Jailbreaking and rooting are synonymous. This is because of the nature of the action. Technically speaking, you use root access to jailbreak a device running iOS. It is only called "rooting" in Android because they want to be different than anything having to do with Apple but, the sum result is the same. When jailbreaking an iOS device in order to unlock the device and load a "clean" or alternate version of the OS and to get rid of bloatware you are doing the same thing in Android. The term is irrelevant since the process and the result are the same.
Lorna Garey
100%
0%
Lorna Garey,
User Rank: Ninja
12/2/2013 | 10:36:22 AM
Re: You Can't Fix Stupid
That's certainly true about stupid, and that some people download shady apps on a whim. However, legit apps ask for so many permissions now that I think the average user gets numb to it. I can see why a couponing app needs location data, but why does a game need to know if I'm at a mall?

App makers should stop with the "permissions bloat" -- that would be a big step toward helping people be more aware and selective. But given retailers' and vendors' hunger to collect more and more data, will that bloat reduction ever happen? Color me skeptical.
Mathew
100%
0%
Mathew,
User Rank: Apprentice
12/2/2013 | 5:45:57 AM
Re: MISCONCEPTION
Thanks for the terminology catch, IamWayne (brain freeze on my part); yes jailbreaking an Android is usually known as rooting it.

In terms of rooting your phone making it more vulnerable to attack, I respectfully disagree. Rooting your phone means that more apps will be able to run with root-level privileges. This increases the chance that your device can be compromised, or that a compromise will have more severe repurcussions. 

The caveat, of course, is that if you know what you're doing, then your risks likely decrease. Likewise, it's great to nuke the bloatware installed by carriers. But the takeaway is that if you don't know what you're doing, then you're probably better off not rooting your phone.

In terms of the risks of rooting being a lie "perpetrated by those in the media," as indicated in my piece, this analysis comes via Marc Rogers, principal security researcher for mobile security firm Lookout. His analysis, by the way, is not an outlier.
shakeeb
100%
0%
shakeeb,
User Rank: Apprentice
11/30/2013 | 12:36:39 PM
Re: You Can't Fix Stupid
Furthermore as an additional feature, appropriate protocols are used to protect sensitive data at the network level.
shakeeb
0%
100%
shakeeb,
User Rank: Apprentice
11/30/2013 | 12:29:00 PM
Re: You Can't Fix Stupid
Great article. However as per the reading I have done, security features are built into the operating system itself to reduce the frequency and impact of security issues.
elysian
50%
50%
elysian,
User Rank: Apprentice
11/30/2013 | 8:31:57 AM
You Don't Jailbreak Android: You ROOT It.
Jailbreak is for iOS.
J_Brandt
50%
50%
J_Brandt,
User Rank: Apprentice
11/29/2013 | 3:12:51 PM
You Can't Fix Stupid
Some great tips.  Sadly many of the people I know who download apps on a whim, who don't bother to read the service agreements, would not have the gumption or ability to dig deep to find any patterns or issues.  To quote Ron White, "you can't fix stupid."  They might notice the battery drain :)
IamWayne
67%
33%
IamWayne,
User Rank: Apprentice
11/29/2013 | 9:54:44 AM
MISCONCEPTION
Some of this is good information. However, the part about as you call it "jailbreaking", in Android it's called rooting. That does NOT make your phone vulnerable. That is a LIE that has been perpetrated by those in the media who do not have a clue. There are many advantages over rooting your Android phone as apposed to leave the malicious mobile carrier bloatware on it. Please research your articles and stop mis-leading the public with misconceptions.
<<   <   Page 3 / 4   >   >>


COVID-19: Latest Security News & Commentary
Dark Reading Staff 7/9/2020
Up Close with Evilnum, the APT Group Behind the Malware
Kelly Sheridan, Staff Editor, Dark Reading,  7/9/2020
Introducing 'Secure Access Service Edge'
Rik Turner, Principal Analyst, Infrastructure Solutions, Omdia,  7/3/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Special Report: Computing's New Normal, a Dark Reading Perspective
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
The Threat from the Internetand What Your Organization Can Do About It
The Threat from the Internetand What Your Organization Can Do About It
This report describes some of the latest attacks and threats emanating from the Internet, as well as advice and tips on how your organization can mitigate those threats before they affect your business. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-5607
PUBLISHED: 2020-07-10
Open redirect vulnerability in SHIRASAGI v1.13.1 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
CVE-2020-15001
PUBLISHED: 2020-07-09
An information leak was discovered on Yubico YubiKey 5 NFC devices 5.0.0 to 5.2.6 and 5.3.0 to 5.3.1. The OTP application allows a user to set optional access codes on OTP slots. This access code is intended to prevent unauthorized changes to OTP configurations. The access code is not checked when u...
CVE-2020-15092
PUBLISHED: 2020-07-09
In TimelineJS before version 3.7.0, some user data renders as HTML. An attacker could implement an XSS exploit with maliciously crafted content in a number of data fields. This risk is present whether the source data for the timeline is stored on Google Sheets or in a JSON configuration file. Most T...
CVE-2020-15093
PUBLISHED: 2020-07-09
The tough library (Rust/crates.io) prior to version 0.7.1 does not properly verify the threshold of cryptographic signatures. It allows an attacker to duplicate a valid signature in order to circumvent TUF requiring a minimum threshold of unique signatures before the metadata is considered valid. A ...
CVE-2020-15299
PUBLISHED: 2020-07-09
A reflected Cross-Site Scripting (XSS) Vulnerability in the KingComposer plugin through 2.9.4 for WordPress allows remote attackers to trick a victim into submitting an install_online_preset AJAX request containing base64-encoded JavaScript (in the kc-online-preset-data POST parameter) that is execu...