Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

Recursion

(56,582 posts)
Mon Jul 27, 2015, 11:20 PM Jul 2015

Android Stagefright Flaws Put 950 Million Devices at Risk

Source: Threat Post

Vulnerabilities discovered in the Stagefright media playback engine that is native to Android devices could be the mobile world’s equivalent to Heartbleed. Almost all Android devices contain the security and implementation issues in question; unpatched devices are at risk to straightforward attacks against specific users that put their privacy, data and safety at risk.

Google has patched internal code branches, but devices require over-the-air updates and given the shaky history of handset manufacturers and carriers pushing out security fixes, it’s unknown how long it will take to update vulnerable devices, or whether some will ever get fixed. Silent Circle has patched its Blackphone against the vulnerabilities, as has Mozilla, which uses Stagefright code in Firefox.

The flaws have been in Android since—and including—version 2.2; devices running Android versions older than Jelly Bean (4.2) are at greater risk since they lack exploit mitigations that have been built into newer versions of the OS.

Researcher Joshua Drake, vice president of platform research and exploitation at Zimperium zLabs, said exploits could be particularly insidious given the fact that an attacker need only use a malicious MMS message that could trigger the vulnerability without user interaction, and delete the message before the victim is aware. All an attacker would need, Drake said, is the device’s phone number.


Read more: https://threatpost.com/android-stagefright-flaws-put-950-million-devices-at-risk/113960



One mitigation for the moment is to turn off auto-download on MMS.
2 replies = new reply since forum marked as read
Highlight: NoneDon't highlight anything 5 newestHighlight 5 most recent replies
Android Stagefright Flaws Put 950 Million Devices at Risk (Original Post) Recursion Jul 2015 OP
Hasn't Android always been full of holes? SoapBox Jul 2015 #1
Why do you say that? Recursion Jul 2015 #2

SoapBox

(18,791 posts)
1. Hasn't Android always been full of holes?
Tue Jul 28, 2015, 12:03 AM
Jul 2015

I've never purchased any devices run on Android...it scares me.

And no one ever talks about it.

Recursion

(56,582 posts)
2. Why do you say that?
Tue Jul 28, 2015, 12:11 AM
Jul 2015


Any software has security flaws; Android is based on the Linux kernel, which has a pretty good track record and is open source and constantly audited.
Latest Discussions»Latest Breaking News»Android Stagefright Flaws...