Stories
Slash Boxes
Comments

SoylentNews is people

posted by janrinok on Tuesday October 08 2019, @02:28AM   Printer-friendly
from the you-can-trust-your-friends,-right? dept.

Submitted via IRC for carny

Millions Of Android Phones Are Vulnerable To Israeli Surveillance Dea...

Google issued an alert overnight about a fresh vulnerability affecting hundreds of millions of Android phones, including its own Pixel 1 and 2 devices. According to Google security researcher Maddie Stone, the weakness is actively being used against targets of the Israeli spyware dealer NSO Group.

If you own any of the following phones, your device likely remains vulnerable today as patches are not yet available: the Google Pixel 1 and 2, Huawei P20. Xiaomi Redmi 5A, Xiaomi Redmi Note 5. Xiaomi A1, Moto Z3, Oreo LG phones and the Samsung S7, S8, S9 models. Those are some of the most popular Android phones in existence today. Huawei has shipped over 16 million P20 smartphones around the world, according to the Chinese company's figures from the end of 2018. (A source told Forbes after publication that the number of affected devices is likely much higher, as those were the only ones that Google had been able to test).

[...] The problem was defined by Stone as a kernel privilege escalation bug, which means it provided a way for a hacker who'd already found a way onto the device to get deeper access, right into the heart of the Android operating system. Getting control of the kernel allows a hacker to do almost whatever they like on the phone, grabbing much of the data within. Whoever was exploiting the vulnerability would have likely used other bugs, combining them in what's known as an "exploit chain" to completely own an Android device remotely. That is, after all, what NSO trades in; it's built a reputation for being able to remotely target and take over smartphones, but its reported sales of this technology to Mexico and the U.A.E. has put it at the center of a storm over privacy and surveillance.

from the all-phones-are-surveillance-devices dept.


Original Submission

 
This discussion has been archived. No new comments can be posted.
Display Options Threshold/Breakthrough Mark All as Read Mark All as Unread
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
  • (Score: 2) by Freeman on Tuesday October 08 2019, @03:09PM (1 child)

    by Freeman (732) on Tuesday October 08 2019, @03:09PM (#904108) Journal

    Much better to get an Android phone that is compatible with LineageOS https://lineageos.org/ [lineageos.org] or go native with https://puri.sm/products/librem-5/ [puri.sm] and their PureOS.

    In 2017, Purism started a crowdfunding campaign for Librem 5, a smartphone aimed not only to run purely on the free software provided in PureOS, but to "[focus] on security by design and privacy protection by default". Purism claimed that the phone would become "the world's first ever IP-native mobile handset, using end-to-end encrypted decentralized communication."[27] Purism cooperated with KDE and GNOME in its development of Librem 5.[28]

    https://en.wikipedia.org/wiki/Librem#Operating_system [wikipedia.org]

    --
    Joshua 1:9 "Be strong and of a good courage; be not afraid, neither be thou dismayed: for the Lord thy God is with thee"
    Starting Score:    1  point
    Karma-Bonus Modifier   +1  

    Total Score:   2  
  • (Score: 1) by Mojibake Tengu on Tuesday October 08 2019, @04:15PM

    by Mojibake Tengu (8598) on Tuesday October 08 2019, @04:15PM (#904136) Journal

    Sounds good. The more ways the people could get things done for themselves, the better.

    However, not just consumer phones, but also mobile industrial terminals are very plagued by proprietary software, both systems and applications. If librem could come through to that sector, that would be great.

    --
    Respect Authorities. Know your social status. Woke responsibly.