Researchers discover Android security flaw which renders more than a billion devices vulnerable
0. phoneArena 26 Mar 2014, 08:59 posted on
While a new update is being installed, a bug that researchers named "Pileup" could allow parasite malicious apps to be "smuggled" with the software, posing as replacements for safe update files that are already present on the file system and assigned permissions...
This is a discussion for a news. To read the whole news, click here
11. itsdeepak4u2000 (Posts: 3718; Member since: 03 Nov 2012)
Yes, that too comes up with the updates given by the OEMs.
42. tasior (Posts: 265; Member since: 04 Nov 2012)
Every system is vulnerable during update. It's logical. Update means changing system. If the update is infected it infects the system. That's why it's crucial, to get update from reliable source.
The only difference between Android and Windows or IOS is that, Android allows You to be the judge, whether the source is reliable. Windows and IOS can be updated only by MS and Apple.
2. papss (unregistered)
31. Arte-8800 (banned) (Posts: 4562; Member since: 13 Mar 2014)
YES PAPSS your beloved platform is bulling and and insulting others while there w8 platform has more hackers and virus than android and OSX
41. sgodsell (Posts: 3757; Member since: 16 Mar 2013)
Naturally Microsoft has to find this security flaw. We can all rest easy now knowing that Microsoft is always looking out for our best interests. Yeah, right. The world knows how trust worthy Microsoft is when it comes Android.
3. chunky1x (Posts: 270; Member since: 28 Mar 2010)
Not really surprising to me. My Windows 7 have way way more security risk than Android, iOS and Windows 8 combined.
4. Troysyx (Posts: 177; Member since: 30 Jul 2012)
Anyone else find it odd that it came from researches at "Indiana University and MICROSOFT"??
17. Ashoaib (Posts: 3229; Member since: 15 Nov 2013)
You got a point... why microsoft is researching on androids vulnerabilities??? microft should focus on its own os...
5. networkdood (Posts: 6330; Member since: 31 Mar 2010)
Oh no, perhaps I should get a Windows phone...hmmm, nm...how about an iphone? Yeah, ok, so every phone has a security risk...Phonearena just stop with these lame stories...
10. PapaSmurf (Posts: 10457; Member since: 14 May 2012)
Not worried at all. Lookout Premium will get the job done.
15. networkdood (Posts: 6330; Member since: 31 Mar 2010)
Tried it, never had a need for it and I have been using Android for 4 years now...
26. PapaSmurf (Posts: 10457; Member since: 14 May 2012)
It's pre-installed on my Note 3 and I got the Premium suite for free. It actually works as it prevented me from downloading several APKs and mp3s that were Trojans and malware. Can't complain. :)
27. networkdood (Posts: 6330; Member since: 31 Mar 2010)
hey, that is good, though - but, I never had those problems - but good to have that protection...
12. androiphone20 (Posts: 1654; Member since: 10 Jul 2013)
If you really thought that this report was looking to get you to buy a phone from another platform then you probably clicked on the wrong link. You take it to the most literal sense it's cray.
14. networkdood (Posts: 6330; Member since: 31 Mar 2010)
Actually, this is exactly what the report is doing - look at the sources of the report....Luyi Xing
, Xiaorui Pan
, Rui Wangy
, Kan Yuan
and XiaoFeng Wang
Indiana University Bloomington
Email: fluyixing, xiaopan, kanyuan, firstname.lastname@example.org
20. Ashoaib (Posts: 3229; Member since: 15 Nov 2013)
Please add ching ming chong from hongkong :))
22. networkdood (Posts: 6330; Member since: 31 Mar 2010)
not up to me - ask Indiana U and microsoft :-)
34. Ashoaib (Posts: 3229; Member since: 15 Nov 2013)
Probably Microsoft will add Bill Paid and Tallmer ;)
16. networkdood (Posts: 6330; Member since: 31 Mar 2010)
This is the source of the article -http://www.informatics.indiana
It is just another company creating a scare, and lo and behold Microsoft is involved...and that in itself is ironic....
7. androiphone20 (Posts: 1654; Member since: 10 Jul 2013)
This is the part where Eric takes back his words
13. protozeloz (Posts: 5396; Member since: 16 Sep 2010)
while in parer this sounds like a lot,it requires quite a few things to actually be pulled (like bypassing the package verification processes before the install) while this could be a security issue and should be addressed I don't see how the average user (read the one not flashing random roms) could be affected by it
18. Sniggly (Posts: 7305; Member since: 05 Dec 2009)
While it sucks that the vulnerability exists in the first place (though it sounds like Microsoft was really working on finding vulnerabilities that they can use in attack ads against Android) it sounds like Google is already working on solutions to the problem.
Someone once pointed out that while security has to think of every possible entry point in software, hackers only have to find one way in. I'd say for as popular Android is, it's impressive that vulnerabilities like these are found so rarely.
19. networkdood (Posts: 6330; Member since: 31 Mar 2010)
If you go here:http://secureandroidupdate.org
it is explained in greater detail and you can see who is behind this info...
24. Sniggly (Posts: 7305; Member since: 05 Dec 2009)
Nice. They take an opportunity to plug their own "security" app.
Not saying the problem doesn't exist, but between that and Microsoft's involvement, I smell a rat.