Showing posts with label Android updates. Show all posts
Showing posts with label Android updates. Show all posts

Friday, August 14, 2015

The Android Is Still Vulnerable to "Stagefright" Flaw - http://clapway.com/2015/08/14/the-android-is-still-vulnerable-to-stagefright-flaw123/

In July, a vulnerability that affected anywhere up to a billion Android phones was made public by software researchers. Google quickly made a patch available, but a security company said that it had been able to bypass the fix. This bug is called the Stagefright bug. The security company that found this update stated how this gives people a false sense of security.


Currently, 90 Percent Of Android Devices Are ASLR Enabled


Google told BBC in an interview that most of the Android users were protected by a security feature called the Address Space Layout Randomization, or the ASLR. At this time, over 90 percent of Android devices have the ASLR enabled. Enabling this is supposed to protect users from these issues.


ASLR is designed to make it harder for an attacker to plan an attack, and introduces more work into the process. This is more than likely to crash a smartphone in comparison to compromising its security.


Another Company Found That The Bug Was Still There And Offered Their Own Patch


However, this vulnerability still remains. In April, another security company found a bug in Android that could potentially let hackers access information and apps on a victim’s phone, just by simply sending a video message.


The company quickly disclosed this information to Google and provided their own patch for the software, which Google made available to phone manufacturers. Details surrounding this new flaw were made public in July, after Google had integrated the patch into the latest version of Android.


Currently, Google pointed out that there haven’t been any reports of anybody exploiting the bug. This week, the first security company said that one of their researchers was able to bypass the patch easily and that the original venerability still remains. On their blog,  they said that the public believes that the current patch in place protects them from this vulnerability, when in fact it does not.


New Bug Could Be The Beginning Of A Bigger Problem


Another researcher from a different security company described the Stagefright bug as an early warning sign to a much bigger problem that could quickly arise. There isn’t currently a comprehensive update solution to the Android bug, since there are so many different device makers that modify the software. Android is an open source operating system that can be modified by a number of different phone companies.



The Sun LifeLight is bringing the sun indoors. If you’re stuck in the office all day, this tool will help you get the health benefits you receive when outdoors! Check out Clapway Trends to see the results!




The Android Is Still Vulnerable to "Stagefright" Flaw

Tuesday, July 28, 2015

Researchers Find a Major MMS Security Flaw in Android That May Affect a Billion Devices - http://clapway.com/2015/07/28/researchers-find-a-major-mms-security-flaw-in-android-that-may-affect-a-billion-devices-343/

A new report published by researchers indicates that a severe security flaw has been discovered within the Android mobile operating system that has already infected nearly a billion devices.


How it Works


The concept of the flaw is surprisingly simple: a hacker could simply send a photo or video message — containing malicious code — to a user’s Android device. Like receiving any other MMS, the user doesn’t need to take any action in order for the code to accessing information on the device.


“This happens even before the sound that you’ve received a messages has even occurred,” said Joshua Drake, a security researcher at Zimperium.


The entire process utilizes a service within Android called Stagefright. The malicious code access this service, and once the service has been breached, a hacker has gained access to not only data but access to functions on the Android device like the camera.


Seeking a Solution


The good news is that Zimperium, the mobile security firm that first reported the flaw, doesn’t believe hackers are exploiting the security flaw. But that doesn’t mean fixing the issue isn’t imperative.


With the help of some patches from Drake, Google was able to patch the security exploit in less than 48 hours after the company was notified. Unfortunately, getting this patch out to millions of Android users is an entirely different problem that must be faced.


Getting Manufacturers and Carriers On Board


When it comes to Android, Google is just one piece of the puzzle. They work with both hardware partners and the wireless carriers in order to push out Android updates, which is part of the infamous fragmentation issue that plagues the mobile OS.


Google has to send the patches over to the hardware manufacturers in order to implement them into all of their devices in a separate software update. Whether the manufacturers decide to implement the fix in a standalone update or incorporate it in an upcoming update is entirely up to them.


Once the manufacturers have a build, they must then take it to wireless carriers in order to go through a separate certification process for each carrier before finally being sent out in an over-the-air (OTA) update.


Some companies, like HTC, have already come forth and stated that they began implemented patches to fix this exploit in their Android headsets already.



 


Check out Clapway Trends for the latest in tech news:




Researchers Find a Major MMS Security Flaw in Android That May Affect a Billion Devices