New Vulnerabilities All Come Preinstalled on Android Phones
wired.com
wired.com
Google and Huawei are not on the list. And Samsung's vulnerabilities are only exploitable by system apps.
“We believe that if you are a vendor you should not trust anybody else to have the same level of permissions as you within the system,”
The fine print here is that these are effectively local privilege escalation vulnerabilities, which is far less worrying than anything remotely exploitable.
The age-old advice of not installing applications you don't trust still applies.
That's the one thing that seems to be a legitimate point in this article -- Android phones tend to come with bloatware from manufacturers and carriers, so you don't have the option not to install these applications you shouldn't trust.
Even if the software maker is “trusted” they can still be incompetent.
First example Fortnite:
https://arstechnica.com/gadgets/2018/08/fortnites-android-vu...
Second example Chrome itself. If you turned off System Integrity Protection on the Mac, a Chrome bug completely hosed your system:
https://support.google.com/chrome/thread/15235262?hl=en
This is the year 2019. Apple has proven that it is possible to make an operating system that sandboxes apps so they can’t do stupid stuff. If an app can harm your mobile operating system or can install malware it is a system vulnerability.
I’m not claiming that iOS doesn’t have any security vulnerabilities but Apple treats them as a bug not as designed.
That being said, the only phone on the list that anybody in the US should even think about trusting are ones from Sony.
I disagree. That's exactly the authoritarian viewpoint that the article has. You can't --- or perhaps shouldn't --- try to stop all "bad things" from happening, because it will inevitably also stop some good things and it's a perfect excuse to take away freedom.
That “freedom” has led to 3 decades of viruses, malware and ransomware on computers. Android/Google didn’t learn from any of those mistakes. The mere fact that you need antivirus for a phone is proof.
It's also lead to great productivity and creativity, with people being able to extend the system as much as they want.
This reminds me of the "imagine a world without crime" people... that's a dystopia where everyone is already under strict control. Insecurity is freedom.
How much more willing are people to buy and install random crap on an iOS device than a computer because they know that they don’t have to trust developers and that they can trust IOS to sandbox their apps and apps have to explicitly ask for permission to do many things?
I wish that there were more permissions around what apps could do. Specifically, access the network at all. Right now, you can deny an app permission to use cellular but not WiFi.
Backdoors, exploits, and all manner of existing CVEs exist because of mfg shortcuts, and we should be learning lessons even if the threat model isn’t immediately apparent.
I'd see an issue if these potential vulnerabilities hadn't apparently already been fixed, but since it looks like they have. Meh, clickbait.