Jump to content

Google confirms some Android phones shipped with backdoor

Sauron
Go to solution Solved by Bouzoo,
Quote

Leagoo M5 Plus, Leagoo M8, Nomu S10, and Nomu S20

The what, what, what and what?

On 6/8/2019 at 2:34 PM, DrMacintosh said:

Nope. That's why Apple takes so much effort to secure the iOS firmware signing process and is why jailbreaking is so difficult. Apple keeps iOS locked down to keep it secure and safe. That has its downsides, but it also has a lot of upsides. It's up to the user to decide if they want freedom and customizability of Android, or the ease of use and security of iOS. 

 

Though iOS 13 just catapulted iOS pretty far into Android territory as far as technical ability is concerned. 

Android isn't so much to blame here as it is the manufacturers that are in charge of ensuring malware doesn't slip through during production. Manufacturers can implement strict signing processes to ensure only signed roms can boot (and consequently, make the installation of custom ROMs more difficult/impossible), though this is largely optional, and the flexibility of Android means manufacturers can take whatever approach to security that is deemed prudent.

 

 

My eyes see the past…

My camera lens sees the present…

Link to comment
Share on other sites

Link to post
Share on other sites

10 hours ago, Zodiark1593 said:

Android isn't so much to blame here as it is the manufacturers that are in charge of ensuring malware doesn't slip through during production. Manufacturers can implement strict signing processes to ensure only signed roms can boot (and consequently, make the installation of custom ROMs more difficult/impossible), though this is largely optional, and the flexibility of Android means manufacturers can take whatever approach to security that is deemed prudent.

That wouldn't have helped here - the malware was in a third party firmware for a feature they commissioned, they had no way of knowing what the "real" firmware should look like.

Don't ask to ask, just ask... please 🤨

sudo chmod -R 000 /*

Link to comment
Share on other sites

Link to post
Share on other sites

14 hours ago, Sauron said:

That wouldn't have helped here - the malware was in a third party firmware for a feature they commissioned, they had no way of knowing what the "real" firmware should look like.

 

Whilst i agree, it is also their responsibility to ensure that the party commissioned to do the work is providing them with malware free products. Regardless how the malware got there, it's pretty hard to blame android when someone in those companies cut too many corners.

Grammar and spelling is not indicative of intelligence/knowledge.  Not having the same opinion does not always mean lack of understanding.  

Link to comment
Share on other sites

Link to post
Share on other sites

6 hours ago, mr moose said:

Whilst i agree, it is also their responsibility to ensure that the party commissioned to do the work is providing them with malware free products. Regardless how the malware got there, it's pretty hard to blame android when someone in those companies cut too many corners.

Agree. This is not an Android problem. It's a "cheap manufacturer who can't develop a feature themselves decides to hire a cheap and sketchy third party developer to do it for them, without controlling the end result" problem. Could happen on any platform where you got third parties involved in assembling hardware and installing software.

 

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

8 hours ago, mr moose said:

 

Whilst i agree, it is also their responsibility to ensure that the party commissioned to do the work is providing them with malware free products. Regardless how the malware got there, it's pretty hard to blame android when someone in those companies cut too many corners.

Of course, I blame the decision of going with proprietary blobs.

Don't ask to ask, just ask... please 🤨

sudo chmod -R 000 /*

Link to comment
Share on other sites

Link to post
Share on other sites

On 6/8/2019 at 5:20 PM, will1432 said:

I am gonna call this the size effect the less market share or the less important market share the less likely to get hacked and even if there is a backdoor it is less likely to be discovered by a outside source.

here

I live in misery USA. my timezone is central daylight time which is either UTC -5 or -4 because the government hates everyone.

into trains? here's the model railroad thread!

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×