Dark Bit Factory & Gravity

GENERAL => General chat => Topic started by: staticgerbil on February 05, 2011

Title: Android security
Post by: staticgerbil on February 05, 2011
Hi guys,

Not so much this month but the few months before that, I feel like I was reading about a new security exploit in Android every other day. 

Like this...
http://www.h-online.com/open/news/item/Android-holes-allow-secret-installation-of-apps-1134940.html
http://venturebeat.com/2010/07/28/android-wallpaper-app-that-steals-your-data-was-downloaded-by-millions/

I read about applications that had access to your messages, could dial numbers and sms without confirmation and I formed the opinion pretty quick that I didn't want one even though they seem like a great, cheap, little dev toy.

I realise everything I've read is all media hype probably blowing stuff out of proportion but I was just wondering if anyone else has read stories like these and was equally scared about getting an Android device that might hold personal data?
Title: Re: Android security
Post by: Shockwave on February 05, 2011
I haven't even got an android.. My phone is about 5 years old and the funny? thing is that I had a piss and then dropped my phone into the toilet the other day so I thought I was going to have to buy an i-phone or something like that..  Amazingly my phone still worked after taking it completely apart and cleaning the piss off all the components.
Title: Re: Android security
Post by: padman on February 05, 2011
[off topic]
LOL Shockwave! But it could have been worse:
http://englishrussia.com/index.php/2007/10/30/the-toilet-phone/ (http://englishrussia.com/index.php/2007/10/30/the-toilet-phone/)
[/off topic]
Title: Re: Android security
Post by: Shockwave on February 05, 2011
Eewww! Fuck.
Title: Re: Android security
Post by: relsoft on February 06, 2011
" I pissed on my Phone! "

Would be a nice sig eh?

 :clap:
Title: Re: Android security
Post by: Shockwave on February 06, 2011
^^ ;)
Title: Re: Android security
Post by: Jim on February 06, 2011
Lots of free apps have access to both location and identity (all apps tell you what features they need before installing), it's the way they're composed that makes an app evil.  Unless of course these bad apps managed to bypass the restrictions.

Jim
Title: Re: Android security
Post by: staticgerbil on February 06, 2011
"all apps tell you what features they need before installing"

Thanks Jim, I think that was an important piece of information that I was missing.

If that's the case then I guess it's probably your own fault for installing a background changer that requests access to your personal info and network access :)
Title: Re: Android security
Post by: LittleWhite on February 07, 2011
"all apps tell you what features they need before installing"

Thanks Jim, I think that was an important piece of information that I was missing.

If that's the case then I guess it's probably your own fault for installing a background changer that requests access to your personal info and network access :)
Depending on how it is described ...
Title: Re: Android security
Post by: staticgerbil on February 07, 2011
I assume it's the OS that describes it, not the app?  So it should be obvious so that their customers don't run into these kinds of issues?

[edit]
Or did you mean they might describe the app in a way suggesting that it can read your email for you to work out what things you like and then download appropriate images?
[/edit]

That has just made another article makes sense for me (I can't find it again)

I was reading that the most downloaded virus for Android was an app that was on the market place that looked and was named exactly like a legitimate anti virus application.  Even some of the employees of the company had it on their phone.

Of course you would give your AV network and personal info privileges.  That's what it's for.

I think I might end up with an Android device in the near future just to have a tinker with :)
Title: Re: Android security
Post by: Jim on February 07, 2011
If the app had said it needed network access and access to your identity then Android market will always tell you that - the exe has bits encoded in it stating those requirements and can't access the relevant APIs without setting them.
However, the app could describe the reasons for these access requirements as "download updates", "recommend backdrops", or it could have said "spam you mercilessly, send your personal details to a marketing company, and publish all your photos on public websites".

The first one is 'good', but might be lying, the second 'bad' but truthful, and anyway there are hundreds of monkeys out there just clicking Yes when the installation messages appear.  They either don't care or don't understand what it means.

Some apps are worth a little bit of privacy invasion, others not.

Jim