Bitcoin Forum
May 15, 2024, 02:31:06 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1] 2 »  All
  Print  
Author Topic: Warning for all Android users!  (Read 383 times)
This is a self-moderated topic. If you do not want to be moderated by the person who started this topic, create a new topic.
Lucius (OP)
Legendary
*
Offline Offline

Activity: 3234
Merit: 5679


Blackjack.fun🎲


View Profile WWW
February 07, 2020, 10:55:04 AM
Last edit: February 07, 2020, 12:26:44 PM by Lucius
Merited by DdmrDdmr (2), o_e_l_e_o (1)
 #1

Google has released update for Android (8, 8.1,9, 10) which includes fixes for 25 vulnerabilities, and two of them were marked as critical. They allow the attacker to perform " a remote code execution vulnerability" and "information disclosure". If you use one of the above Android versions, be sure to check manually in settings of your phone is this update available, or if you get an automatic warning be sure to allow installation.

Given that there are a large number of devices that need to receive an update, as always, it will take several months until all the devices are patched. As always, delivery speed depends on the manufacturer of your device, the version of Android and the region where you are located.

To avoid potential abuse from these vulnerabilities, as always, do not download applications from unconfirmed sources, and do not click the suspicious links you receive by email and social networks. Google Play should be safe, but not every application can be checked - so approach every download with great caution.

This is especially important for all who use mobile crypto wallets or any crypto exchange on their smartphones. Treat your devices equally whether it is a PC or a smartphone, security first.

More info : Android's February 2020 Update Patches Critical System Vulnerabilities

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
coupable
Hero Member
*****
Offline Offline

Activity: 2352
Merit: 757


View Profile
February 07, 2020, 11:23:57 AM
 #2

25 vulnerabilities !!  That's terrible !
The saddest part is that the majority (i can guess) of android users don't care about the system installed in their devices nor in frequent updates automatically done (by default).
The great advice should be "stop using android, it's not trusted enough", but what would be the alternative!?

This is especially important for all who use mobile crypto wallets or any crypto exchange on their smartphones. Treat your devices equally whether it is a PC or a smartphone, security first.
Wallets, exchanges, authentification apps, ... are all threatened now if you insist to use them in mobile devices with android. Can we suggest to only use desktop versions?
BuxCoin
Sr. Member
****
Offline Offline

Activity: 698
Merit: 251


View Profile
February 07, 2020, 11:50:29 AM
 #3

I recently read an news article on strandhogg bug and this vulnerabilities , hackers can use this types of bugs to steal data and hack this type of vulnerabilities can cause data theft google should and companies should  push updates fast

good thing is goolge is adding new feature , future version of OS in play-store to deliver this updates fast ,

. Google Play should be safe, but not every application can be checked - so approach every download with great caution.
there are apps in playstore itself which contains malware ,
o_e_l_e_o
In memoriam
Legendary
*
Offline Offline

Activity: 2268
Merit: 18515


View Profile
February 07, 2020, 12:10:40 PM
 #4

Google has released update for Android (8, 8.1,9, 10) which includes 25 vulnerabilities, and two of them were marked as critical.
You might want to change your phrasing here. The way it's worded makes it sound like the new update has 25 vulnerabilities in it i.e. you should not download this new update yet. Better to say it includes patches/fixes for 25 vulnerabilities.

To avoid potential abuse from these vulnerabilities, as always, do not download applications from unconfirmed sources, and do not click the suspicious links you receive by email and social networks. Google Play should be safe, but not every application can be checked - so approach every download with great caution.
Unconfirmed sources are not safe, but neither is Google Play. The vast majority of apps with malicious content are spread via the Google Play Store, since the majority of users wouldn't know how to manually download and install an .apk file. As always, don't trust, verify.

The great advice should be "stop using android, it's not trusted enough", but what would be the alternative!?
There are a number of open source mobile operating systems built upon the Android Open Source Project you could look in to instead if you want to make the move away from stock Android, such as GrapheneOS or LineageOS. There's also completely non-android OSs such as Ubuntu Touch. These will also give you a big privacy boost over stock Android.
libert19
Hero Member
*****
Offline Offline

Activity: 2492
Merit: 943



View Profile WWW
February 07, 2020, 12:17:03 PM
 #5

The great advice should be "stop using android, it's not trusted enough", but what would be the alternative!?
There are a number of open source mobile operating systems built upon the Android Open Source Project you could look in to instead if you want to make the move away from stock Android, such as GrapheneOS or LineageOS. There's also completely non-android OSs such as Ubuntu Touch. These will also give you a big privacy boost over stock Android.

To make that switch, you will need to root and flash that os, imo that is even worse than using stock android.

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits.
..........UNLEASH..........
THE ULTIMATE
GAMING EXPERIENCE
DUELBITS
FANTASY
SPORTS
████▄▄█████▄▄
░▄████
███████████▄
▐███
███████████████▄
███
████████████████
███
████████████████▌
███
██████████████████
████████████████▀▀▀
███████████████▌
███████████████▌
████████████████
████████████████
████████████████
████▀▀███████▀▀
.
▬▬
VS
▬▬
████▄▄▄█████▄▄▄
░▄████████████████▄
▐██████████████████▄
████████████████████
████████████████████▌
█████████████████████
███████████████████
███████████████▌
███████████████▌
████████████████
████████████████
████████████████
████▀▀███████▀▀
/// PLAY FOR  FREE  ///
WIN FOR REAL
..PLAY NOW..
coupable
Hero Member
*****
Offline Offline

Activity: 2352
Merit: 757


View Profile
February 07, 2020, 12:53:31 PM
 #6

The great advice should be "stop using android, it's not trusted enough", but what would be the alternative!?
There are a number of open source mobile operating systems built upon the Android Open Source Project you could look in to instead if you want to make the move away from stock Android, such as GrapheneOS or LineageOS. There's also completely non-android OSs such as Ubuntu Touch. These will also give you a big privacy boost over stock Android.

To make that switch, you will need to root and flash that os, imo that is even worse than using stock android.
Considering that os should be flashed and rooted in order to migrate from standard android, why do you this is worst than using stock android if it offers more privacy?
Honestly, i didn't know that there is alternative operating systems rather than android and ubunto, this is why i did always feel stucked. I will look into open-source ones but first need to learn how to flash root my device. Thank you o_e_l_e_o for the suggestions .
virasog
Legendary
*
Offline Offline

Activity: 2982
Merit: 1161



View Profile
February 08, 2020, 01:30:42 PM
 #7

Google has released update for Android (8, 8.1,9, 10) which includes fixes for 25 vulnerabilities, and two of them were marked as critical. They allow the attacker to perform " a remote code execution vulnerability" and "information disclosure". If you use one of the above Android versions, be sure to check manually in settings of your phone is this update available, or if you get an automatic warning be sure to allow installation.

Given that there are a large number of devices that need to receive an update, as always, it will take several months until all the devices are patched. As always, delivery speed depends on the manufacturer of your device, the version of Android and the region where you are located.

To avoid potential abuse from these vulnerabilities, as always, do not download applications from unconfirmed sources, and do not click the suspicious links you receive by email and social networks. Google Play should be safe, but not every application can be checked - so approach every download with great caution.

This is especially important for all who use mobile crypto wallets or any crypto exchange on their smartphones. Treat your devices equally whether it is a PC or a smartphone, security first.

More info : Android's February 2020 Update Patches Critical System Vulnerabilities

Is the stock android most secure in this situation as it will receive the update first and instantly ?
For different versions of android developed by the mobile phone provides like Color OS etc, they do not receives updates quickly and this will make the phone vulnerable until the update is applied or patched ?

.
.DuelbitsSPORTS.
▄▄▄███████▄▄▄
▄▄█████████████████▄▄
▄██████████████████████▄
██████████████████████████
███████████████████████████
██████████████████████████████
██████████████████████████████
█████████████████████████████
███████████████████████████
█████████████████████████
▀████████████████████████
▀▀███████████████████
██████████████████████████████
██
██
██
██

██
██
██
██

██
██
██
████████▄▄▄▄██▄▄▄██
███▄█▀▄▄▀███▄█████
█████████████▀▀▀██
██▀ ▀██████████████████
███▄███████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
▀█████████████████████▀
▀▀███████████████▀▀
▀▀▀▀█▀▀▀▀
OFFICIAL EUROPEAN
BETTING PARTNER OF
ASTON VILLA FC
██
██
██
██

██
██
██
██

██
██
██
10%   CASHBACK   
          100%   MULTICHARGER   
Lucius (OP)
Legendary
*
Offline Offline

Activity: 3234
Merit: 5679


Blackjack.fun🎲


View Profile WWW
February 08, 2020, 02:09:48 PM
 #8

The saddest part is that the majority (i can guess) of android users don't care about the system installed in their devices nor in frequent updates automatically done (by default).

This is unfortunately true, as most Internet users today pay very little attention to the security of their personal computers, while it is still a common belief that smartphones do not need any security software and that nothing bad can happen on Android OS.

good thing is goolge is adding new feature , future version of OS in play-store to deliver this updates fast ,

If you think on Android 10, it is true that Google will send updates directly to Play Store, which will certainly speed up the process for all users. I am using latest version of Android 10 on my phone, but so far I don't see any options that solve the above issues.

You might want to change your phrasing here. The way it's worded makes it sound like the new update has 25 vulnerabilities in it i.e. you should not download this new update yet. Better to say it includes patches/fixes for 25 vulnerabilities.

Thanks for the warning, I corrected my mistake Wink

Is the stock android most secure in this situation as it will receive the update first and instantly ?
For different versions of android developed by the mobile phone provides like Color OS etc, they do not receives updates quickly and this will make the phone vulnerable until the update is applied or patched ?

From what I read, this is true because stock Android is actually pure Android from Google without any add-ons, so phones which use this type of OS get updates much faster directly from Google. Reason why others need to wait is in fact that manufactures like Samsung or Huawei need to modify their version of Android for each model before release. Then the latest phones get the update first, but it also depends on the region in which the user is located.

All this means that it will take months for all devices to receive patches, which of course increases the risk for all Android OS users

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
canamani
Newbie
*
Offline Offline

Activity: 14
Merit: 0


View Profile
February 08, 2020, 04:30:34 PM
 #9

I have a question. How i can make the update if my phone receive any update from March 2019, as the company have problems with google. And i have android 8 on phone. what to do ?
Findingnemo
Hero Member
*****
Offline Offline

Activity: 2324
Merit: 760


Bitcoin = Financial freedom


View Profile
February 08, 2020, 04:55:11 PM
 #10

Any techies here? I am using Android Oxygen and my system is up to date, is there anything I have to worry about it?

I never install apps from thirdparty websites and rarely even install any new apps rather I just use it to scroll newsfeed of social media and also for chatting purpose mostly.

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits.
..........UNLEASH..........
THE ULTIMATE
GAMING EXPERIENCE
DUELBITS
FANTASY
SPORTS
████▄▄█████▄▄
░▄████
███████████▄
▐███
███████████████▄
███
████████████████
███
████████████████▌
███
██████████████████
████████████████▀▀▀
███████████████▌
███████████████▌
████████████████
████████████████
████████████████
████▀▀███████▀▀
.
▬▬
VS
▬▬
████▄▄▄█████▄▄▄
░▄████████████████▄
▐██████████████████▄
████████████████████
████████████████████▌
█████████████████████
███████████████████
███████████████▌
███████████████▌
████████████████
████████████████
████████████████
████▀▀███████▀▀
/// PLAY FOR  FREE  ///
WIN FOR REAL
..PLAY NOW..
View ArchiveReport to moderator
cryptoaddictchie
Legendary
*
Online Online

Activity: 2072
Merit: 1315



View Profile
February 09, 2020, 08:31:56 AM
 #11

I never install apps from thirdparty websites and rarely even install any new apps rather I just use it to scroll newsfeed of social media and also for chatting purpose mostly.

Same case with you mate. Never install from a third party app. Using phone for social media would not be harmful IMO, OP is just raising an awareness about those app from Playstore which not all are trusted.

Im currently using huawei device and Im not sure if whether I could update it to the latest OS or stuck with android OS 9. 0 cause Im thinking also of the security of my phone since most of my wallets are mobile app based.

.BEST..CHANGE.███████████████
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
███████████████
..BUY/ SELL CRYPTO..
NotATether
Legendary
*
Offline Offline

Activity: 1596
Merit: 6745


bitcoincleanup.com / bitmixlist.org


View Profile WWW
February 09, 2020, 09:50:18 AM
 #12

Any techies here? I am using Android Oxygen and my system is up to date, is there anything I have to worry about it?

Yes, don't click on random links in your mail or messages. Sophisticated hackers can take over your phone by exploiting undiscovered vulnerabilities in your browser followed by some in the kernel when you click on their link. The links are also put into innocent-looking messages. A lot phones belonging to high-profile people have been hacked that way. This also applies to iOS too.

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
gentlemand
Legendary
*
Offline Offline

Activity: 2590
Merit: 3013


Welt Am Draht


View Profile
February 09, 2020, 10:00:40 AM
 #13

Somewhere along the line the Android model got broken.

I should not have to wait for, or rather be abandoned by, an individual company who are more than likely to be too bone idle to ever do a regular system update let alone a vital security patch.

There must be hundreds of millions of phones with gaping security holes that will never be plugged. Glue your piece of shit skin on top by all means but they shouldn't be able to offer Android without agreeing to a direct pipe of patches straight from Google.
coupable
Hero Member
*****
Offline Offline

Activity: 2352
Merit: 757


View Profile
February 09, 2020, 10:16:44 AM
 #14

Im currently using huawei device and Im not sure if whether I could update it to the latest OS or stuck with android OS 9. 0 cause Im thinking also of the security of my phone since most of my wallets are mobile app based.
As your wallets are mobile app based, i think it would be better not to update your system as it's not that harmful too. I would also recommend you to use another device for your social media apps. I tell you this based on my own experience when i had to delete my BitPay wallet after forgotten its pin code, then by trying to reinstall the wallet i found that the wallet itself had been upgraded to a new version and the old one, which is compatible with my os, is no longer available in play store. I had to upgrade my os or download the wallet version from a third part entity. As my device comtains other wallets, i just bought another device and use it only for bitpay wallet and migrate other wallets to it .
Lucius (OP)
Legendary
*
Offline Offline

Activity: 3234
Merit: 5679


Blackjack.fun🎲


View Profile WWW
February 09, 2020, 03:56:47 PM
 #15

Im currently using huawei device and Im not sure if whether I could update it to the latest OS or stuck with android OS 9. 0 cause Im thinking also of the security of my phone since most of my wallets are mobile app based.

Depending of what Huawei model of phone you using you'll have to wait for your upgrade to be available. In my case (Huawei P30) I get option to upgrade maybe a month after they release it. As always new models get update first, then old ones - and it can take for months to all models get Android 10. Are you sure that you have automatic update ON? Go to Settings - > System/Updates and check manually. There is also option to use Huawei official Support app (check your apps) and check is upgrade available from there.

Any techies here? I am using Android Oxygen and my system is up to date, is there anything I have to worry about it?

In addition to installing some security software as additional protection, you just need to remain vigilant and apply the patch when it is available. In order for hackers to exploit the above vulnerabilities, they must first infect the device and they can only do that through malicious apps.

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
Findingnemo
Hero Member
*****
Offline Offline

Activity: 2324
Merit: 760


Bitcoin = Financial freedom


View Profile
February 09, 2020, 05:52:33 PM
 #16

Any techies here? I am using Android Oxygen and my system is up to date, is there anything I have to worry about it?

In addition to installing some security software as additional protection, you just need to remain vigilant and apply the patch when it is available. In order for hackers to exploit the above vulnerabilities, they must first infect the device and they can only do that through malicious apps.

I have experience with the spyware and malware installed into android device when we surf random pages while clicking some popup or any annoying notification so now I have new device especially for some crypto wallets so I think twice or thrice before installing any new apps.

Just a tip, check your app manager for an app that doesn't have a logo or name but it does occupy a space which normally can found at the bottom of the list,if you found anything just uninstall it straight away better factory restore your android.

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits.
..........UNLEASH..........
THE ULTIMATE
GAMING EXPERIENCE
DUELBITS
FANTASY
SPORTS
████▄▄█████▄▄
░▄████
███████████▄
▐███
███████████████▄
███
████████████████
███
████████████████▌
███
██████████████████
████████████████▀▀▀
███████████████▌
███████████████▌
████████████████
████████████████
████████████████
████▀▀███████▀▀
.
▬▬
VS
▬▬
████▄▄▄█████▄▄▄
░▄████████████████▄
▐██████████████████▄
████████████████████
████████████████████▌
█████████████████████
███████████████████
███████████████▌
███████████████▌
████████████████
████████████████
████████████████
████▀▀███████▀▀
/// PLAY FOR  FREE  ///
WIN FOR REAL
..PLAY NOW..
View ArchiveReport to moderator
bugsbuds
Newbie
*
Offline Offline

Activity: 14
Merit: 0


View Profile
February 09, 2020, 06:29:37 PM
 #17

I checked in settings and the problem is i not have any update available for my phone , last security update 1 February 2019. When i press search say not any available, what i can do?
Findingnemo
Hero Member
*****
Offline Offline

Activity: 2324
Merit: 760


Bitcoin = Financial freedom


View Profile
February 09, 2020, 06:43:27 PM
 #18

I checked in settings and the problem is i not have any update available for my phone , last security update 1 February 2019. When i press search say not any available, what i can do?
Old devices might never get an update as well,so if you can afford a new one just go for it with latest oxygen version so you will be safer to the vulnerabilities as long as you verify any apps before installing.

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits.
..........UNLEASH..........
THE ULTIMATE
GAMING EXPERIENCE
DUELBITS
FANTASY
SPORTS
████▄▄█████▄▄
░▄████
███████████▄
▐███
███████████████▄
███
████████████████
███
████████████████▌
███
██████████████████
████████████████▀▀▀
███████████████▌
███████████████▌
████████████████
████████████████
████████████████
████▀▀███████▀▀
.
▬▬
VS
▬▬
████▄▄▄█████▄▄▄
░▄████████████████▄
▐██████████████████▄
████████████████████
████████████████████▌
█████████████████████
███████████████████
███████████████▌
███████████████▌
████████████████
████████████████
████████████████
████▀▀███████▀▀
/// PLAY FOR  FREE  ///
WIN FOR REAL
..PLAY NOW..
View ArchiveReport to moderator
Pmalek
Legendary
*
Offline Offline

Activity: 2758
Merit: 7141



View Profile
February 09, 2020, 08:00:09 PM
 #19

I installed the most recent updates for my phone just the other week. It is a relatively new phone but there were no updates available for me since October. I assume that some of these vulnerabilities were fixed with my January update. I only get maximum one per month so the end of February and beginning of March is the next one, if they release one.

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
LTU_btc
Legendary
*
Offline Offline

Activity: 3052
Merit: 1331


Slava Ukraini!


View Profile WWW
February 10, 2020, 08:15:39 PM
 #20

Thanks for warning, it's really concerning thing. Unfortunately I will get this update just in the end of February, because usually I get updates just in the end of ongoing month.
To avoid potential abuse from these vulnerabilities, as always, do not download applications from unconfirmed sources, and do not click the suspicious links you receive by email and social networks. Google Play should be safe, but not every application can be checked - so approach every download with great caution.
Good suggestion, but unfortunately Google Play is very far from being safe. It's full of dangerous apps. Main problem that everyone can upload app to it and it's uploaded without manual check. They just have to pay little dev fee. I'm not big fan of Apple, but their App Store is much better in terms of security.

Pages: [1] 2 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!