Heartbleed-Level Vulnerability Found In 950 Million Android Devices, Thanks To DRM

Latest Videos FromTom's Hardware
Contributor

Lucian Armasu is a Contributing Writer for Tom's Hardware US. He covers software news and the issues surrounding privacy and security.

  • dstarr3
    Any reason a mobile carrier couldn't just intercept text messages containing the necessary code?
    Reply
  • InvalidError
    16338411 said:
    Any reason a mobile carrier couldn't just intercept text messages containing the necessary code?
    What motivation would they have to go through the extra hassle and expense?

    You are afraid to get hacked on your no longer supported phone? The carrier offers you to upgrade to a new phone for a fee. You do not upgrade your phone, get hacked and get screwed by bandwidth, LD and other charges? The carrier most likely won't let you get away from it without spending some cash either way.

    The carrier patches their servers to intercept malicious SMS? They have to eat the cost of those server tweaks, they lose one reason to nudge customers to upgrade their phones regularly and they may expose themselves to additional privacy inquiries about their SMS interception. Lose-lose-lose for them.
    Reply
  • JOSHSKORN
    Any reason a mobile carrier couldn't just intercept text messages containing the necessary code?
    Privacy concerns? Would you want your carrier intercepting your texts at any given time? Just a thought.
    Reply
  • targetdrone
    I think the Note II will be my last android device. This is getting ridiculous. Not that there are security flaws in Android, every computer system has them. It's the fact it's impossible to fix them without buying a new device because an affect device is no longer supported for OS updates. Oh yeah maybe I could install a a custom rom(assuming the boot loader isn't locked) but if something goes wrong I'll end up with a $500 brick. No thank you. I think I'll go super retro and get a car phone once my Note II dies.
    Reply
  • Paul NZ
    Good thing I'm not using one atm. I'm using a windows phone
    Reply
  • razor512
    Another reason to avoid android devices which go out of their way to make it difficult to root and install custom ROMs. With the major companies dropping support for older devices after about 18 months, there are millions of devices that will simply never receive an official update to fix this security issue.

    Those with easy access to 3rd party ROMs (easy is the key, larger user base = more attention from devs and faster updates), will get the security fix sooner. I bet within a few hours to a few days, you will see 3rd party ROMs with the DRM disabled until updated code for those libraries are released.
    Reply
  • kenjitamura
    Another reason to avoid android devices which go out of their way to make it difficult to root and install custom ROMs. With the major companies dropping support for older devices after about 18 months, there are millions of devices that will simply never receive an official update to fix this security issue.

    Those with easy access to 3rd party ROMs (easy is the key, larger user base = more attention from devs and faster updates), will get the security fix sooner. I bet within a few hours to a few days, you will see 3rd party ROMs with the DRM disabled until updated code for those libraries are released.

    The only android devices that are difficult to install a custom ROM on are the ones manufactured in China because they don't make the source available to developers. Just don't buy Android devices with Rockchip, Allwinner, Mediatek, or Amlogic hardware and you'll be good.
    Reply
  • alextheblue
    Privacy concerns? Would you want your carrier intercepting your texts at any given time? Just a thought.

    They already do that and store them for the NSA to peruse later - and that's not even a tinfoil hat statement. They're compelled by law to store and share with the NSA and likely other agencies.
    Reply
  • dstarr3
    Privacy concerns? Would you want your carrier intercepting your texts at any given time? Just a thought.

    They already do that and store them for the NSA to peruse later - and that's not even a tinfoil hat statement. They're compelled by law to store and share with the NSA and likely other agencies.

    Indeed. There is no privacy with SMS in the first place. So, them intercepting malicious code would just be a good use of systems already in place. But yeah, I understand why it'll never happen.

    Though, secondarily, I wonder how effective these attacks are for people that use encrypting messaging apps.
    Reply
  • mrmez
    Hardly surprising. The result of highly fragmented hardware and software.
    Much easier to conquer an already divided platform.

    A massive advantage for IOS/OSX.
    88% of apple users are running iOS 8.x
    Meanwhile 50% of android users are running Jellybean or older.
    Reply