Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Shifty Pony
Dec 28, 2004

Up ta somethin'


FAT32 SHAMER posted:

But enough about android

never. android will forever be a source of security fuckery.


or at least as long as the devices ship loaded with auto-updating un-deletable bloatware with permissions like this:

quote:

Peel Smart Remote TV Guide
Peel Technologies Inc.
Free
This app has access to:
In-app purchases

Device & app history
-retrieve running apps

Identity
-find accounts on the device

Calendar
-read calendar events plus confidential information
-add or modify calendar events and send email to guests without owners' knowledge

Contacts
-find accounts on the device
-read your contacts

Location
-approximate location (network-based)
-precise location (GPS and network-based)

Phone
-read phone status and identity

Photos/Media/Files
-read the contents of your USB storage
-modify or delete the contents of your USB storage

Storage
-read the contents of your USB storage
-modify or delete the contents of your USB storage

Microphone
-record audio

Wi-Fi connection information
-view Wi-Fi connections

Device ID & call information
-read phone status and identity

Other
-power device on or off
-transmit infrared
-receive data from Internet
-view network connections
-pair with Bluetooth devices
-access Bluetooth settings
-allow Wi-Fi Multicast reception
-connect and disconnect from Wi-Fi
-expand/collapse status bar
-full network access
-change your audio settings
-run at startup
-draw over other apps
-control vibration
-prevent device from sleeping

apparently after the most recent rounds of updates it uses the "draw over other apps" permission to cause full screen popup ads systemwide and send notifications even if people disable notifications. additionally it uses that permission combined with the "prevent the device from sleeping" and "power device on and off" permissions to effectively replace the device lockscreen with its own.

Adbot
ADBOT LOVES YOU

ThePeavstenator
Dec 18, 2012

:burger::burger::burger::burger::burger:

Establish the Buns

:burger::burger::burger::burger::burger:
peel smart remote, more like peel outta the shop that tries to sell you an android if you're remotely smart

mrmcd
Feb 22, 2003

Pictured: The only good cop (a fictional one).

ate all the Oreos posted:

i thought maybe he had started because we're all smart attractive people?

i can dream :sigh:

There's a surprisingly large number of goons who work at Google so maybe he does, just incognito. :tinfoil:

Truga
May 4, 2014
Lipstick Apathy
that's less of an android problem and more of a vendor problem though imo.

not that android is good or anything, but it's like making GBS threads all over windows just because lenovo installed superfish on your pc.



vvv: google is about to get slapped with another big EU fine in fact, because they don't allow 3rd parties to pre-install not-google search.

i get the reasons, but from a security view it's hosed. of course the correct thing would be to fix google, but that's never going to happen, so secfuck it is

Truga fucked around with this message at 15:31 on Jul 7, 2017

Shame Boy
Mar 2, 2010

Truga posted:

that's less of an android problem and more of a vendor problem though imo.

not that android is good or anything, but it's like making GBS threads all over windows just because lenovo installed superfish on your pc.

I was gonna say microsoft could probably stop that poo poo if they actually tried at all but thinking about it they'd probably get an antitrust lawsuit lol

mrmcd
Feb 22, 2003

Pictured: The only good cop (a fictional one).

ate all the Oreos posted:

I was gonna say microsoft could probably stop that poo poo if they actually tried at all but thinking about it they'd probably get an antitrust lawsuit lol

Google literally has a (completely different) EU antitrust investigation going on right now because they tried to tell manufacturers and telcos they couldn't ship Android phones with 10 GB of crapware and security holes.

FAT32 SHAMER
Aug 16, 2012



it's pronounced null-day

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



tavis-chan....

RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe
https://www.youtube.com/watch?v=wdWgvJRHA0s

this is a good (and funny) talk on pentesting, also covers pentesters and "0day"

Shifty Pony
Dec 28, 2004

Up ta somethin'


mrmcd posted:

Google literally has a (completely different) EU antitrust investigation going on right now because they tried to tell manufacturers and telcos they couldn't ship Android phones with 10 GB of crapware and security holes.

idk, there's probably enough wiggle room for them to set up some sort of quarantine for all preinstalled apps until they are actually launched by the user. they would just have to include their own apps in it too.

hobbesmaster
Jan 28, 2008

mrmcd posted:

Google literally has a (completely different) EU antitrust investigation going on right now because they tried to tell manufacturers and telcos they couldn't ship Android phones with 10 GB of crapware and security holes.

telling computer manufacturers what they could and could not install on their computers was one of things Microsoft got hit with in the US antitrust suit.

The antitrust concern is that google is using android to advance their advertising business and disallowing others from doing the same.

google should probably come up with some sort of certification for crapware free like microsoft's "signature edition" laptops.

Phone
Jul 30, 2005

親子丼をほしい。

RISCy Business posted:

https://www.youtube.com/watch?v=wdWgvJRHA0s

this is a good (and funny) talk on pentesting, also covers pentesters and "0day"

Hilarious... ill think of this when i look at my big rear end paycheck for hacking your poo poo..if you guys did your jobs our industry would have to get bent. Until then ill pop shells, laugh at losers like you, and make more and more money!

power botton
Nov 2, 2011

Maybe they should ship not garbage nexus phones as loss leaders and force every other vendor to compete. the free market bitches

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Shifty Pony posted:

idk, there's probably enough wiggle room for them to set up some sort of quarantine for all preinstalled apps until they are actually launched by the user. they would just have to include their own apps in it too.

Several years ago, a feature was added to Android so that garbage preload apps could be uninstalled. Apps that are required for phone functionality (Dialer, Settings, etc) could have a flag set that would mark them as "critical" and thus not allowed to be uninstalled.

Guess how long it took for the garbage to be marked "critical" as well?

Phone
Jul 30, 2005

親子丼をほしい。
i have phone hopped a bit, and i know it falls under "old man yelling at clouds" poo poo, but man the choices are not great.

with iphones they removed the headphone jack to save .01mm of space (and also to sell you air budzzzzz)

with androids, all of the nexus phones are great handsets until they mysteriously break a year later because there's a design flaw in the power button (n5) or just straight up refuse to boot one day (n5x). the closest manufacturer that is aosp adjacent that doesn't make dumpster fire handsets is oneplus.

but hey, nokia has a new handset out guyzzzzz

Shaggar
Apr 26, 2006
winphone ftw

Shame Boy
Mar 2, 2010

Phone posted:

i have phone hopped a bit, and i know it falls under "old man yelling at clouds" poo poo, but man the choices are not great.

with iphones they removed the headphone jack to save .01mm of space (and also to sell you air budzzzzz)

with androids, all of the nexus phones are great handsets until they mysteriously break a year later because there's a design flaw in the power button (n5) or just straight up refuse to boot one day (n5x). the closest manufacturer that is aosp adjacent that doesn't make dumpster fire handsets is oneplus.

but hey, nokia has a new handset out guyzzzzz

what weird european country are you from where they call them "handsets" i've only ever heard that in relation to landline phones

flakeloaf
Feb 26, 2003

Still better than android clock

Shifty Pony posted:

never. android will forever be a source of security fuckery.


or at least as long as the devices ship loaded with auto-updating un-deletable bloatware with permissions like this:


apparently after the most recent rounds of updates it uses the "draw over other apps" permission to cause full screen popup ads systemwide and send notifications even if people disable notifications. additionally it uses that permission combined with the "prevent the device from sleeping" and "power device on and off" permissions to effectively replace the device lockscreen with its own.

this isn't a new trick for peel remote, it's been doing this poo poo to me for months

if you even look at its lock screen widget, a giant ad will be waiting for you when you unlock

its chat heads widget loves to steal focus from other apps' useful buttons too, that's pretty fun

ThePeavstenator
Dec 18, 2012

:burger::burger::burger::burger::burger:

Establish the Buns

:burger::burger::burger::burger::burger:
i willingly own a galaxy

Phone
Jul 30, 2005

親子丼をほしい。

ate all the Oreos posted:

what weird european country are you from where they call them "handsets" i've only ever heard that in relation to landline phones

cellular telephony endpoints

to your question, the worst European country of them all: south florida

cinci zoo sniper
Mar 15, 2013




ate all the Oreos posted:

what weird european country are you from where they call them "handsets" i've only ever heard that in relation to landline phones

standard english m8

darthbob88
Oct 13, 2011

YOSPOS

Shaggar posted:

winphone ftw

Yeah, I like my Winphone for most purposes, but the app support is non-existent, and IIRC Redmond is going to drop them some time soon.

hobbesmaster
Jan 28, 2008

Shaggar posted:

winphone ftw

even Microsoft employees don't use windows phones

they all have crazy expensive surfaces of course

Phone
Jul 30, 2005

親子丼をほしい。
I genuinely liked the nokia win7 handset I had, it was a solid device that had zero app support. had wordament, though.

Kuvo
Oct 27, 2008

Blame it on the misfortune of your bark!
Fun Shoe

Shifty Pony posted:

Peel Smart Remote TV Guide

bought a pixel specifically because i didnt want to deal with all the snooping poo poo shovelware (also because it would actually receive OTA updates more then once in its lifespan).

Shifty Pony
Dec 28, 2004

Up ta somethin'


Volmarias posted:

Several years ago, a feature was added to Android so that garbage preload apps could be uninstalled. Apps that are required for phone functionality (Dialer, Settings, etc) could have a flag set that would mark them as "critical" and thus not allowed to be uninstalled.

Guess how long it took for the garbage to be marked "critical" as well?

and if they cracked down and actually applied standards for what is critical functionality the manufacturers would simply pool the dialer and settings app with the bloat apps into a single package such that the former depend on code from the latter for operation, similarly to how MS deeply integrated IE into windows.


hobbesmaster posted:

The antitrust concern is that google is using android to advance their advertising business and disallowing others from doing the same.

almost as though vertical integration is a Pandora's Box of anticompetitive awfulness even when you tag but with the internet onto the end.

apseudonym
Feb 25, 2011

Subjunctive posted:

does he do mobile? apseudonym? he should do mobile

Some of the p0 folks do mobile things, the last iOS security bulletin thing had a lot of hilariously bad sounding bugs credited to them and they find some cool Android ones from time to time but not as much as I'd like.


Tavis does what Tavis wants, he cannot be aimed.


E: wildcard certs are good Subjunctive is correct as to why y'all crazy sometimes.

apseudonym fucked around with this message at 17:51 on Jul 7, 2017

Shame Boy
Mar 2, 2010

Phone posted:

cellular telephony endpoints

to your question, the worst European country of them all: south florida

oh yeah i remember this coming up before, i grew up like 4 hours north of you but apparently in a completely different universe

Phone
Jul 30, 2005

親子丼をほしい。
I won't tell anyone that you lived in orlando

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Shifty Pony posted:

and if they cracked down and actually applied standards for what is critical functionality the manufacturers would simply pool the dialer and settings app with the bloat apps into a single package such that the former depend on code from the latter for operation, similarly to how MS deeply integrated IE into windows.

The open source nature of Android means that Google can recommend and strongly suggest, but ultimately cannot fully control what OEMs do, which is unfortunate for end users.

CmdrRiker
Apr 8, 2016

You dismally untalented little creep!

ate all the Oreos posted:

i needed the root password to this new public-internet-facing VM someone had set up and noticed the guy had a habit of mailing passwords in emails (there were several earlier in the email chain) so i ask him to give me the password another way that's more secure than email

he just sends it to me on slack and tells me "oh good idea suggesting we be secure and not put this in an email!" :negative:

That's not too bad if you're hosting Slack on your own servers. It would at least be a step in the right direction.

CmdrRiker
Apr 8, 2016

You dismally untalented little creep!

I never thought about it before, but Google does a poo poo ton of data mining with all of their products. For example, when you get an email about your flight schedule and it magically appears on your calendar and at the top of your inbox app on the day of your departure. I became more aware of this poo poo when a colleague of mine got a job at Google and then promptly stopped using his Gmail account and wouldn't tell me why.

Can anyone else speak to this weird privacy business when it comes to Google and datamining emails?

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

ratbert90 posted:

Hey, these are actually really neat! Do you mind also handling libressl as well? Thanks!
i'm fairly certain that it uses the same ciphers as openssl

Shame Boy
Mar 2, 2010

Phone posted:

I won't tell anyone that you lived in orlando

not even orlando :v:

CmdrRiker posted:

That's not too bad if you're hosting Slack on your own servers. It would at least be a step in the right direction.

nope we use slack's hosting and we don't even pay for anything so it deletes all our messages within a week because we've used up our free quota lol

Migishu
Oct 22, 2005

I'll eat your fucking eyeballs if you're not careful

Grimey Drawer

Kuvo posted:

bought a pixel specifically because i didnt want to deal with all the snooping poo poo shovelware (also because it would actually receive OTA updates more then once in its lifespan).

pixels are good phones, brent

Shame Boy
Mar 2, 2010

Volmarias posted:

The open source nature of Android means that Google can recommend and strongly suggest, but ultimately cannot fully control what OEMs do, which is unfortunate for end users.

i wouldn't mind this so much if I could just put a stock install on the phone or whatever via a process that's not "download some skeevy poo poo from xda-forums"

i'd think they could do something with the branding at least, like you can't use the Android name or call your phone a Certified Google Android(tm) Compatible Device or whatever if you don't allow users to run stock or uninstall poo poo or whatever

Daman
Oct 28, 2011

Phone posted:

I won't tell anyone that you lived in orlando

speaking of horrible places...

If any of you are going to defcon and want a cool hardware badge cheaper than the other parties grab this https://sunshinectf.org/floridaman/

the guy making them is legit, if you don't want it mailed he'd be fine giving it to you irl at dc

CmdrRiker
Apr 8, 2016

You dismally untalented little creep!

ate all the Oreos posted:

nope we use slack's hosting and we don't even pay for anything so it deletes all our messages within a week because we've used up our free quota lol

Well, there you go. It'll eventually be deleted. Almost as good as having never put it there in the first place.

gonadic io
Feb 16, 2011

>>=

cinci zoo sniper posted:

if you ever say it "zero day" to a british person you'll be laughed out into the loving oblivion. do you also "zero" when dictating a phone number with 0 in it?

I'm British and say zero day :shrug:

Adbot
ADBOT LOVES YOU

apseudonym
Feb 25, 2011

CmdrRiker posted:

I never thought about it before, but Google does a poo poo ton of data mining with all of their products. For example, when you get an email about your flight schedule and it magically appears on your calendar and at the top of your inbox app on the day of your departure. I became more aware of this poo poo when a colleague of mine got a job at Google and then promptly stopped using his Gmail account and wouldn't tell me why.

Can anyone else speak to this weird privacy business when it comes to Google and datamining emails?

I still use mine and I doubt that's why he switched ¯\_(ツ)_/¯.

  • Locked thread