Cyanogenmod Updater vulnerable to MITM attack
kyhwana.org
kyhwana.org
(Example: https://www.google.com/search?q=b13afc01102c84425ca995469f1a...)
They need to sign their updates as well.
The security is created by humans to be used by humans; so nothing is truly safe if <insert random circumstance> happens; and anyway, for cases like yours the hack would be found after few days when any of the people in charge of the compiling realizes that the check-sum is spoofed and would advice anyone to update the OS after the issues is taken care of.
CM Account, CM Updater, Movie Studio, File Manager and CM Wallpaper are all apps that I uninstall as soon as I flash a ROM to one of my devices.
Their CM File Manager for one is a totally redundant application that hasn't been updated in a long time, despite being broken (it doesn't work in Super User mode without done juggling about)
Their CM Account is one other thing that I find totally pointless.
CM would be better off bringing more innovative features to Android instead of just copying drivers from CAF and changing headers to say CM instead of CAF or AOSP.
The innovation in the Android ROM community has been coming from Paranoid Android, AOKP, Omni and Slim ROMs, and from the Xposed community.
They've been reduced to being a repo shepherd for certain devices, but most of their user base comes from people running "Unofficial" builds compiled by independent developers.
I think, as a start up, they'd be better off if they focused on features instead of just trying to market CM Phones that essentially run a Nexus like build of plain vanilla Android.
The whole point of FOSS is to be able to see what's going on, for freedom and control to the user. At this point I barely see Android as any better than IOS, aka, a very pretty jail for the user.
I run CyanogenMod Stable on my phone, the kernel build date is given as Sep 23 2013. Are they really meaning to imply that no security advisory published for Linux after that effects CyanogenMod? Most are purely local attacks, but still therefore malware vectors, and then there's things like CVE-2013-7027, which on the face of it should effect Android.
At the moment, I'm running CyanogenMod purely under the assumption it'll be more secure than the default Samsung installation (no updates in about two years), as at least it gets updates! Yet, at the end of the day, I see little to convince myself they are actually keeping up with upstream security fixes. No Android distribution seems to have a coherent story when it comes to security advisories, sadly. :( (I have a Galaxy S2, if anyone wants to convince me to try another distribution/OS!)
And for anyone wondering about privacy/FOSS tools in general, the EFF put together Prism-Break site has been constantly updated.
There are lots of exploits, and every time someone publishes a rooting method that does not require "fastboot oem unlock" (gingerbreak, ashmem, mempodroid, exploid, etc) it's one of the CVEs being exploited.
You are lacking perspective if you think that: 1) a completely open source phone is easy to make 2) iOS and Windows phone are on par with Android's level of openness
Edit: people downvoting, state why please
> Content Blocked (content_filter_denied) > Content Category: "Malicious Sources/Malnets"
Any idea why this site would be blocked at $BIGCORP?