Void captures over a million Android TV boxes
news.drweb.com
news.drweb.com
Ah the new economical divide.
Most "real people" also have phones which aren't receiving updates for a few years by now.
In south america the median android version is 8.
And phones are not optional as most countries already jumped into both digital government and money transfer.
Android OEMs have historically been terrible at releasing timely updates (it can take months), releasing updates at all (particularly cheap Android phones get EOLed long before an admittedly way more expensive iPhone would) and such updates aren't typically pushed in the same way.
One big problem with Android is the way driver updates work. It's a nontrivial process to add hardware support for a later Android version because of the Linux roots and having no stable ABI.
I think back to how Windows has changed over the last 2 decades. Once Windows updates were all paid and people would hang on to old versions of Windows forever. Microsoft eventually realized this was a problem for them so paid upgrades aren't what they once were.
Additionally, driver instability used to be a massive problem on Windows. Microsoft to their credit spent a lot of effort improving their driver situation to isolate drivers and have a stable ABI. Windows is way more stable than it was 20 years ago.
Even OSX has adopted user space drivers (DriverKit).
By the way, the above reasons is why some at Google have pushed Fucshia as essentially an Android ecosystem and architecture reset. It's been close to 10 years now. I don't see this going anywhere despite billions being poured into it at this point.
Google is now the only option for phone manufacturers. No backup needed. Plan A worked.
The problem with Windows today is more that it wants to opaquely update itself all the time, and the user gets undesired mandatory "updates" such as ads in menus and sending "telemetry" home (ie user activity data for MS' machine learning ambitions). But of course the most important thing is to keep fucking web browsers up-to-date with laughable and undesired CSS or WASM features (including subsequent exploit/fingerprinting fixes) all the time and even more often than actual content, or what's left of it anyway on the extant web.
As is being pointed out elsewhere, this isn't a vulnerability in an "Android" product. These are TVs running vendor-maintained AOSP builds. They get updates when and how the vendor decides to do it. It's not related to the (fairly reasonable, though often spun) arguments about updates in the phone licensee ecosystem.
It's also something you don't necessarily have knowledge of when you purchase a phone.
It's one reason why people (myself include) prefer Apple. You know you're going to get 4-5+ years of updates.
No? For a licensed Android phone there's a clean split between OEM and OS updates, a clear declaration for support period and a OS-managed tracking of updates with clear visibility to the customer. I get that there are constant platforms flames about whether this is acceptable or inferior to Apple's offering, yada yada yada.
But the point is that none of that is relevant here, because these aren't phones and aren't running a licensed "Android" variant. They're just TVs running vendor-custom firmware that happens to be based on AOSP, and clearly can't be expected to conform to any update regime except whatever the integrator put together.
Basically, the story here is saying "I hacked product A" and you're trying to have an argument like "That's because this unrelated product B is bad". It's a non-sequitur.
Last time I checked you could totally use drivers built for windows 7 on a win 10 OS.
“Freedom”, I believe they called it.
Also, hardware standardization in the PC world is pretty much a thing. Not so much in the mobile (and mobile offshoot) world.
Now, if the phone's original OS were open source, it would be easier to make bugfix patches when old vulns are discovered.
So it is not really "self created" in my book.
The continuing problem with Android, and a display of Google's lost interest in Android, is that they still stick to this paradigm in 2024. Nowadays phone manufacturers ship stock Android with add-ons, and cellular companies no longer have the power to demand anything. If Apple can ship iOS 18 worldwide next Monday, why can't Google?
Then there are devices, like in China, where Google Mobile Services is not on many phones so Google has no leverage at all re supporting updates.
Which is to say I think you are speaking in terms of what you can do within the android's playground itself, its certainly much more open than ios in that regard. But when it comes to the fact of being able to change the playground itself ie install whatever os you want on the hardware or upgrade the os on the phone then suddenly most phones aren't any better than iphones either. Some are slightly better in that you can at least unlock the bootloader or root it, but I don't know if much progress has been made beyond that in being able to reverse engineer or otherwise them to able to install anything you want on them. That was the point with respect to I was speaking.
Qualcomm is the reason. Qualcomm wants OEMs to buy new chips every year, and for that to happen, consumers have to buy new phones every year. To upgrade Android (across kernel versions), OEMs need Qualcomm to provide updated drivers, which Qualcomm has been reluctant to do, because their sales will be undercut by chips they sold years ago. Android phones are closer to Mac than PCs, as there's one hardware-maker who determines which models become obsolete, and when, based on the software they choose to update (or not).
Does Microsoft just maintain broad kernel backward compatibility, or are driver authors doing more work to support more Windows versions? Is it a fundamental architecture difference with how each OS implements their kernel APIs?
Windows on the other hand maintains a very stable interface and has no desire to maintain vendor drivers.
There is; it's called the Android Compatibility Commitment. If a phone manufacturer wants the Google Play Store, their phones need specific security requirements. Which includes measures to lock down the phone to prevent piracy of the store, which for most manufacturers is achieved through a locked bootloader.
https://assets.publishing.service.gov.uk/media/61b794d6d3bf7...
After reading your comment, I was trying to find that for India, and landed on this page: https://gs.statcounter.com/android-version-market-share/all/..., and thought that India it is Android 13
But then for South America, the same page (https://gs.statcounter.com/android-version-market-share/all/...) tells should be Android 13 as well
India also has the same setup - digital money transfer happens via phones (in some ways, your phone number is your identity)
Many of them NEVER received a single update ever. There are so many shady companies producing TV boxes with no plan to ever provide any updates.
Unless one of the larger brands make such a device, I don't see any reason to recommend anything but the ChromeCast or whatever Google calls it now. Or a Roku or an AppleTV, if you swing that way.
You are responsible to update your device.
Just because you're doing something insane/illegal doesn't mean you can't do it safely.
Quite a few of them actually end up configured to preference SD boot over internal flash and/or have easily accessible buttons or shortable pads to trigger bootrom recovery modes.
Which at least, stops them being automatically consigned to e-waste.
Although, customising a LibreELEC image for the dozens of different models of TV box isn't great. Typically involves sorting out the dts for the device and remapping the remote.
While Go and Rust aren't necessarily magic pixie-dust that can account for all types of security vulnerabilities, if I'm going to be faced with the possibility of some project being abandoned at some point for the next new shiny thing that everyone would rather work on, I'd at least like to give it a fighting chance of remaining secure for some time after abandonment without any updates. Ideally it would be a Rust userspace media management package running on Debian Stable getting unattended upgrades every night.
Since nothing like that exists I've recently decided to give CoreELEC/Kodi a try on an ODROID-N2+, albeit disconnected from any network. I was surprised at how seamless and integrated everything was.
The remote control for my television "just worked" with it out of the box thanks to HDMI CEC support. Arrow buttons, play/pause, back, etc. all did just what I expected them to do. It's a marked improvement from the last time I built a custom media box, which I had running MythTV on Gentoo, when I needed to jump through hoops to set up an IR blaster. And you can't argue with a 12v/2a power supply.
For now I'm keeping it off my home network and am "sneaker-netting" content on a USB drive between my trusted devices and the ODROID. When I get tired of doing that I might add some firewall rules to my router to only allow it to talk to a locked-down VM doing nothing but hosting a read-only file share. But some day I hope to look forward to building a similar form-factor box that has all the media gadgets and gizmos with a Rust userspace that respects my privacy and auto-updated Debian Stable so I can actually connect it to the Internet.
I use openwrt for my routers/switches, and when I first set up a "home jail" network, it was the best.
next step was to set up privoxy, so I could point devices at a proxy for updates, and privoxy could whitelist the machines to proxy to.
Auto updates also have a reputation for harming the user at least as often as helping (removing features, adding ads, whatever) and so trust in that is declining while the need for decent security (smart cars/homes) is increasing. Not sure what to conclude from this except that we need more focus on secure-by-design systems and maybe immutability guarantees rather than autoupdates, app stores, and plugin/extension frameworks but these things are sometimes impractical fundamentally and sometimes just inconvenient for surveillance capitalism.
it’s pretty safe to assume that most companies spend money trying to make money, which usually involves exfiltrating my data, turning off things I need but they don’t want to support, general rent seeking, ads injection.
Trusting any small manufacturer of anything to spend time/money on fixing problems with security or quality control is a hilariously naive idea these days, when crowdstrike and Boeing are showing that even big companies don’t care. We all know the security update is enhanced spyware, planned obsolescence / a slow push to force me to buy a new device, or something else that’s going to make things worse.
From what little has been leaked, I really doubt Tesla should be enar the top.
I didn't find the Ford one specifically, but I also didn't go surfing through the many pages of results
https://old.reddit.com/r/EnoughMuskSpam/comments/99sbwa/form...
I’m gonna steal this one from you - it’s quite clever IMO
The teams maintaining all of this usually have a LOC/headcount ratio approaching 1 million too. It's a very different threat model than the old days when every manufacturer had their own systems and trying to craft an exploit required individualized work for all of them.
With the explosion of the number of those boxes, we added more surface of attack, but the number of good security people didn't increase.
You need systems secure against teams commercially motivated attackers with 10 M$+ budgets and tens of full-time professionals working for years. Nobody in commercial IT would even dare to claim they could stop such attacks even though they are regular occurrences these days. If they do not even dare to say they can do it, why on Earth would anybody believe those vendors have, what, accidentally made things better than they think?
Ranking companies by security is like ranking the relative resistance of individual sheets of toilet paper to bullets. Sure, maybe the single ply toilet paper is not as good as the two ply, but neither of them provide objectively useful degrees of protection. And that is just talking about the bare minimum to protect against current threats.
If you can hack every Honda at rush hour to turn off the brakes, slam the accelerator, and drive slightly into oncoming traffic how many people do you think would die in the next minute before anything can be done or people informed to stop driving their cars? 1K? 10K? 100K? 1M? Does Honda survive killing more people than died in most wars? If a criminal organization demonstrates they can and will do it, how much would Honda pay in extortion to avoid being put out of existence and their executives jailed? How much security is adequate to avoid the deaths of thousands to millions? Certainly orders of magnitude more than the 10 M$ attacks that steam roll the "best commercial IT security" available today. Any reasonable number is vastly in excess of what these companies can secure today.
20 years ago, the hackers were 18 year olds demanding 300 dollars from grandmas. 10 years ago, the hackers were 28 year olds founding businesses demanding 10 thousand dollars from small businesses. Now they are 38 year olds managing teams demanding millions from billion dollar companies. Soon we will see them demanding billions if the trends continue for 5-10 more years. The software security doomsayers were right, just early. Even Mark Zuckerberg took a decade with huge piles of VC funds to get to a multi-billion dollar valuation; you have to forgive the hacking teenagers who had to bootstrap their criminal enterprises for taking so long.
I'd trust google to maintain the security in a fleet of robo taxi's where cars can be brought in, modified or replaced relatively quickly over Tesla trying to convince individual owners to do the same...
People are too attached with property and social status stuff.
Beyond that, it seems like the nature of self driving might be one of gradual incremental improvement, where in order to actually develop it you more or less have to run a fleet of robo taxi's in different places with different climates and different road conditions.
Finally, the people most likely to deliver it are google (waymo) and I think they have zero desire to sell cars to consumers but are literally running a taxi service as we speak.
Repossessing a self driving car, on the other hand...
It would be have it self-drive from the owner's home to someplace nearby not associated with the the thieves to get it out of sight from the owner's security cameras and whatever other security cameras in the neighborhood might be watching where the gang can disable the cloud connection and then transport it by truck or driving it in manual mode to their chop shop.
This was apparently found due to seeing some changed files, so they didn’t ship with void, but it wouldn’t have been hard to push it out to pre-comprised boxes.
Linus Tech Tips made a full video on the subject. They seem to lean to the second option.