|
|
Log in / Subscribe / Register

I'd like to see "% days vulnerable to publicly-known vulnerabilities" as a smartphone statistic

I'd like to see "% days vulnerable to publicly-known vulnerabilities" as a smartphone statistic

Posted Jan 20, 2016 20:48 UTC (Wed) by b7j0c (guest, #27559)
In reply to: I'd like to see "% days vulnerable to publicly-known vulnerabilities" as a smartphone statistic by david.a.wheeler
Parent article: Dutch consumer group sues Samsung over Android updates (OSNews)

There have been enough exploits to both iOS and Android that one can safely assume it will be many years before either platform settles enough to be hardened against exploits. Both smartphone platforms are insecure. Presently, each new release focuses on new features rather than stability, and as a result, you should not assume future versions will be more secure than present versions.

It also appears that both Apple and Google know about some exploits for considerable periods of time before patching.

Mainstream Nexus phones now have a monthly patch cycle. My 5x has already had two such cycles since I purchased it. I assume that such frequent patching is as likely to introduce bugs as to fix them.

In the case of Samsung, the solution is simple: stop buying their phones. both Lenovo (Moto) and Google (Nexus) offer better alternatives. I don't see how this case has any merit, no one is forced to choose Samsung.


to post comments

I'd like to see "% days vulnerable to publicly-known vulnerabilities" as a smartphone statistic

Posted Jan 20, 2016 22:02 UTC (Wed) by MattJD (subscriber, #91390) [Link] (8 responses)

> Mainstream Nexus phones now have a monthly patch cycle. My 5x has already had two such cycles since I purchased it. I assume that such frequent patching is as likely to introduce bugs as to fix them.

Considering those patch cycles are specifically security bugs (though there have been some minor bug fixes too I believe), what would you suggest they do instead to provide security updates?

I'd like to see "% days vulnerable to publicly-known vulnerabilities" as a smartphone statistic

Posted Jan 21, 2016 1:24 UTC (Thu) by b7j0c (guest, #27559) [Link] (7 responses)

I fully realize that there is no desire for something akin to Debian Stable in the smartphone platform world. If they were to slow down the cycle and focus on stability, the lack of new features would turn off consumers. So, I would recommend they just continue as they are and I will expect and live with bugs.

I'd like to see "% days vulnerable to publicly-known vulnerabilities" as a smartphone statistic

Posted Jan 21, 2016 2:57 UTC (Thu) by MattJD (subscriber, #91390) [Link] (2 responses)

Right, except those monthly patches are akin to what Debian Stable provides. Google seems to have moved to a yearly (thought they may go back to twice yearly) feature release cycle. Those updates will be huge, and will introduce those bugs. But the monthly patches are smaller and targeted in nature, fixing security bugs (with some other important fixes on the side, not features).

I won't argue your preferences (I run Debian Stable on my servers for that development cycle, so I understand why people want that). I'm just saying those two patches you have received aren't major changes, they are minor fixes targeting security. They seem to be what you want, which is why I was curious you didn't like them.

I'd like to see "% days vulnerable to publicly-known vulnerabilities" as a smartphone statistic

Posted Jan 21, 2016 16:54 UTC (Thu) by b7j0c (guest, #27559) [Link] (1 responses)

> Right, except those monthly patches are akin to what Debian Stable provides

except mostly done in secret

I'd like to see "% days vulnerable to publicly-known vulnerabilities" as a smartphone statistic

Posted Feb 2, 2016 7:55 UTC (Tue) by thestinger (guest, #91827) [Link]

The source code is released alongside the security bulletins and the over-the-air updates and each issue has a CVE assigned to it. There are clear commit messages and no obfuscation. In what sense is it done in secret? It's the standard method of doing vulnerability disclosure is done for open-source projects. There are few open source projects with comparable transparency when it comes to security vulnerabilities.

I'd like to see "% days vulnerable to publicly-known vulnerabilities" as a smartphone statistic

Posted Jan 21, 2016 22:26 UTC (Thu) by ksandstr (guest, #60862) [Link] (3 responses)

We used to have this, though. They were called "cell phones"; think about it, a telephone you could carry in your (cargo pants) pocket! Weren't any exploits for those things, at least above the baseband ROM...

I'd like to see "% days vulnerable to publicly-known vulnerabilities" as a smartphone statistic

Posted Jan 22, 2016 12:30 UTC (Fri) by pboddie (guest, #50784) [Link]

You could do bad things to Nokia phones by sending them SMS messages of a certain kind. Probably other manufacturers' products had similar flaws. I could easily imagine that the Bluetooth stack could have been subverted on those phones, too. Nothing was ever as good as people tend to claim.

I'd like to see "% days vulnerable to publicly-known vulnerabilities" as a smartphone statistic

Posted Jan 23, 2016 2:11 UTC (Sat) by rahvin (guest, #16953) [Link] (1 responses)

I wouldn't argue they were secure, just that nobody cared to exploit them because they didn't have any value exploited because it was just a phone. A modern smartphone has as much compute power as a computer from the 90's and a persistent internet connection. There is value in exploiting it just for that, let alone all the personal and financial data that they now house.

One of these days someone is going to be held to account in a civil suit for not fixing exploits and it's going to be very ugly for the manufacturers when that liability lands.

I'd like to see "% days vulnerable to publicly-known vulnerabilities" as a smartphone statistic

Posted Jan 24, 2016 0:32 UTC (Sun) by sbergman27 (guest, #10767) [Link]

Not being a target is as good a security as any. Would you prefer to live in a low-crime neighborhood without a Kevlar jacket, or in a war zone with the best Kevlar jacket money can buy?


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds