Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.




3 posts

Wannabe Geek


# 125749 18-Jul-2013 12:00
Send private message

Hi, I overheard someone mention all Android phones (apart for some recent models) have an error in the software and we need to contact the supplier to have them fixed as they are subject to viruses.

Anyone else heard of this?

Create new topic
3344 posts

Uber Geek

Trusted
Vocus

  # 858557 18-Jul-2013 12:07
Send private message

It's a vulnerability which allows a malicious install package to install a modified apk of a system application without the phone knowing it's modified.

But to do that you would have to install a malicious, modified package in the first place.

If you use Google Play store for example, chances are very slim of the vulnerability being exploited, especially since they're scanning all the apps now.

I could link to articles but it's easy enough to search for "android vulnerability", also they're generally quite technical and probably not that meaningful to the average user.

In reality, it's a bad flaw that shouldn't be there, but it's really not as easy to exploit (in the real world) as the security researchers who found it are making it out to be.  And your chances of getting any official patch for an old phone from any manufacturer are, in my opinion, slim to none.

4324 posts

Uber Geek

Mod Emeritus
Trusted
Lifetime subscriber

  # 858558 18-Jul-2013 12:09
2 people support this post
Send private message

This is really a non-issue. It is possible for an application to be compromised by someone and retain its original signature.

If you only install apps from Google Play then you really don't need to worry about it. If you sideload apps you obtain from dodgy 3rd party sites then there is a risk. But there always has been a risk in doing that.

The only place I'd get apps from outside the Google or Amazon stores is Xda Developers.

A little common sense will protect you.

 
 
 
 


1508 posts

Uber Geek


  # 858615 18-Jul-2013 13:44
Send private message

Use cyanogenmod 10.1 and if it is a recent build, it will have the fix built in to it. Otherwise I just saw Modaco have an app called rekey for root users which can protect against the vulnerabily apparently.
http://www.modaco.com/page/news/_/android/protect-against-the-master-key-vulnerability-with-rekey-r1186
Just don't be stupid and use apps you download off rapidshare and you should be fine.




Try Vultr using this link and get us both some credit:

 

http://www.vultr.com/?ref=7033587-3B


BDFL - Memuneh
64667 posts

Uber Geek

Administrator
Trusted
Geekzone
Lifetime subscriber

  # 864875 24-Jul-2013 10:09
Send private message

bradstewart: This is really a non-issue. It is possible for an application to be compromised by someone and retain its original signature.

If you only install apps from Google Play then you really don't need to worry about it. If you sideload apps you obtain from dodgy 3rd party sites then there is a risk. But there always has been a risk in doing that.


Exactly. Just don't download apps from sites, only from the Google Play Market. Symantec has now identified the first implementations of this happening with cracked apps out there.




Create new topic



Twitter and LinkedIn »



Follow us to receive Twitter updates when new discussions are posted in our forums:



Follow us to receive Twitter updates when news items and blogs are posted in our frontpage:



Follow us to receive Twitter updates when tech item prices are listed in our price comparison site:





News »

Microsoft New Zealand Partner Awards results
Posted 18-Oct-2019 10:18


Logitech introduces new Made for Google keyboard and mouse devices
Posted 16-Oct-2019 13:36


MATTR launches to accelerate decentralised identity
Posted 16-Oct-2019 10:28


Vodafone X-Squad powers up for customers
Posted 16-Oct-2019 08:15


D Link ANZ launches EXO Smart Mesh Wi Fi Routers with McAfee protection
Posted 15-Oct-2019 11:31


Major Japanese retailer partners with smart New Zealand technology IMAGR
Posted 14-Oct-2019 10:29


Ola pioneers one-time passcode feature to fight rideshare fraud
Posted 14-Oct-2019 10:24


Spark Sport new home of NZC matches from 2020
Posted 10-Oct-2019 09:59


Meet Nola, Noel Leeming's new digital employee
Posted 4-Oct-2019 08:07


Registrations for Sprout Accelerator open for 2020 season
Posted 4-Oct-2019 08:02


Teletrac Navman welcomes AI tech leader Jens Meggers as new President
Posted 4-Oct-2019 07:41


Vodafone makes voice of 4G (VoLTE) official
Posted 4-Oct-2019 07:36


2degrees Reaches Milestone of 100,000 Broadband Customers
Posted 1-Oct-2019 09:17


Nokia 1 Plus available in New Zealand from 2nd October
Posted 30-Sep-2019 17:46


Ola integrates Apple Pay as payment method in New Zealand
Posted 25-Sep-2019 09:51



Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.


Support Geekzone »

Our community of supporters help make Geekzone possible. Click the button below to join them.

Support Geezone on PressPatron



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.

Alternatively, you can receive a daily email with Geekzone updates.