Massive data stealing vulnerability found in many HTC Android phones
androidpolice.com
androidpolice.com
I'm going to guess either very few or none, as most people won't notice/care about this issue, and HTC isn't making any money off supplying updates.
Imagine if Microsoft forced Dell, HP, etc. to handle software security and updates on Windows for PC's they've already sold - it would either never happen or not happen correctly. Swap the players and that's where Android is today.
(yes, I know about alternate firmware - how many non-geeks are capable of using it and have devices that don't have technological blocks like signed bootloaders to prevent it?)
Given that it took it took HTC this long to get an update to an Android version that's been available in source since December and they still managed to mess it up, I don't have high hopes for something like this getting fixed.
For non-geeks the first option is the only viable one, IMHO.
You've obviously settled on the same conclusion.
Do you know how OTA updates are pushed out for the non-Google Android phones that are bought without a contract?
Windows Phone has the same update model as Android. You need manufacturer and carrier compliance for an update to get to a phone. Plus there is no custom ROM alternative like with Android. http://www.winsupersite.com/article/windows-7/Windows-Phone-...
Despite the brain-dead implementation that's the cause of this privacy fiasco, HTC has the best track record among Android manufacturers when it comes to releasing updates. So I would hope they address this issue, and fast.
http://androidandme.com/2011/08/news/updates-or-lack-thereof...
That's fine for personal use many companies strictly prohibit employees from using unauthorized software. You're pretty much stuck with whatever they give you.
"Imagine if Dell, HP, etc forced Microsoft to let them handle software security and updates on Windows for PCs they've already sold..."
Google would get nothing but more work and responsibility out of such an arrangement.
Yes, it would be better for security and end users, but who cares about them? Google is in it for the ad revenue, and the HW vendors are in it to sell units, not have old models with new software compete against their new hardware.
Perhaps it is a testing/debugging-facility that they forgot to remove from the production build?
That'd be about the only semi-plausible excuse for HTC to come out of this alive (when/if mainstream media decides to jump on this).
However, on the OS side it depends on what changes HTC made for carriers and how adequate their codeqa testing and security audits were
I'll have to look into LBEPG and see if it actually fixes this. I had poked around a bit and it seemed painful to implement this kind of functionality in an app, but perhaps they've found a way (or are playing some really invasive games with system libraries).
I literally can not conceive how it wouldn't have crossed their mind that any local app with network permissions would be able to connect to it.
Were they just being lazy? Or were they forced to do it this way by some ignorant manager? I would love to hear how this happened.
> And for Linus's practice of letting distributions do > whatever bloody stupid thing they want. I'm stunned that > this one ever got into production in its current state.
Fixed that for you.
And it looks like (at least on CM) non-whitelisted apps can make DNS queries as well (so they can still send the data home).
I'm pretty sure that even if HTC fixes this mess I would have to wait forever for Orange to push the update with its custom sw.
I call you not overly paranoid, but maybe bizarrely superstitious?