1. enb123's Avatar
    I'm gonna guess that this is probably a lot of FUD, but it would be interesting to know how people here feel about it:

    Major Flaw In Android Phones Would Let Hackers In With Just A Text : All Tech Considered : NPR

    It sort of sounds like a flaw within Hangouts and, to a lesser extent, Messenger, which Google could patch without a broad-based OS update. The exploit is a result of videos being automatically downloaded and ready to play without a user having to allow that in Hangouts. But it's presented as the end of days!

    Thoughts?
    07-27-2015 09:41 AM
  2. enb123's Avatar
    I guess I should have figured AC would answer this question pretty quickly!

    The 'Stagefright' exploit: What you need to know | Android Central
    Laura Knotek likes this.
    07-27-2015 10:15 AM
  3. Eclipse2K's Avatar
    I guess I should have figured AC would answer this question pretty quickly!

    The 'Stagefright' exploit: What you need to know | Android Central
    Android Central is on top of the situation as usual!
    07-27-2015 11:06 AM
  4. monsieurms's Avatar
    Well, it's a good introduction. I do understand that Rome is not built in a day. But we need a lot more investigation.....for the next steps.

    --What do security experts recommend at this point? Can people like Lookout do anything about this? In looking at Lookout, they don't even seem to mention StageFright as a threat!!
    --What plans do the carriers have to address this?
    --Is there any carrier who has already fixed it? For instance, it wasn't long back that I upgraded to Lollipop. That was after this patch issued by Google. Was it included by T-mobile? I'm going to look.
    07-28-2015 07:13 AM
  5. LockOnTech's Avatar
    Well, it's a good introduction. I do understand that Rome is not built in a day. But we need a lot more investigation.....for the next steps.

    --What do security experts recommend at this point? Can people like Lookout do anything about this? In looking at Lookout, they don't even seem to mention StageFright as a threat!!
    --What plans do the carriers have to address this?
    --Is there any carrier who has already fixed it? For instance, it wasn't long back that I upgraded to Lollipop. That was after this patch issued by Google. Was it included by T-mobile? I'm going to look.
    At this point, it is a matter of waiting for the solution. Compared to the lenovo superfish mess, google just can't leave this unattended.
    07-28-2015 07:41 AM
  6. monsieurms's Avatar
    At this point, it is a matter of waiting for the solution. Compared to the lenovo superfish mess, google just can't leave this unattended.
    According to various articles, Google fixed this months ago. The problem is that the carriers may not have rolled out the fix.
    07-28-2015 08:23 AM
  7. Dark Penguin's Avatar
    I saw this problem reported on Spiegel.de ("Die Mutter aller Android-Schwachstellen") .

    Can we protect ourselves by disabling MMS, or messages that contain video attachments?
    07-28-2015 09:12 AM
  8. monsieurms's Avatar
    I saw this problem reported on Spiegel.de ("Die Mutter aller Android-Schwachstellen") .

    Can we protect ourselves by disabling MMS, or messages that contain video attachments?
    I contacted Lookout, and they responded as follows:

    "Currently it's not possible for Lookout to fix this flaw or prevent your device from being affected....You can mitigate the potential for automatic execution of the vulnerability by disabling auto-downloading of MMS on your device. To do this, open the messaging app you use and disable automatic downloading of MMS in the apps settings."
    Dark Penguin likes this.
    07-28-2015 09:22 AM
  9. LockOnTech's Avatar
    According to various articles, Google fixed this months ago. The problem is that the carriers may not have rolled out the fix.
    Then I am surprised, how is this a carrier responsibility?
    07-28-2015 01:09 PM
  10. Eclipse2K's Avatar
    Then I am surprised, how is this a carrier responsibility?
    Google fixed this months ago so the fix is out there. Manufacturers such as Motorola, Samsung, LG, etc. have to make the update. Once done, the carriers have to test it before they push it. Although, with an update this crucial, I bet even Verizon wouldn't hesitate to push it.
    monsieurms likes this.
    07-28-2015 01:41 PM
  11. oneeyecarpenter's Avatar
    Hi,

    This issue will be fully disclosed at Blackhat USA 2015 this week. Google used the patches provided by the researchers. HTC and others started to incorporate these at the beginning of July. It will only be included in very few products so far,but a factory reset in newer lollipop devices may do the trick for some.CHECK FIRST with your manufacture. Everyone else will need to disable video autoloading in their messaging apps,hangouts and what's app included,along with all other third party messenger apps. Avast blogged about this,and no mobile security app can protect you on this.https://blog.avast.com/2015/07/29/bi...o-stagefright/

    This is as serious as it gets,contrary to AC and Google down playing it. Besides having your personal information stolen,who ever utilizes this vulnerability can spy on the device owners. This will be extremely bad for those in other countries with repressive regimes,but any government could use this at will,and you may never know it. For example,China may want to spy on Android users in the US,or any other country,and vice a versa. It's shameful that Phil makes light of this,and ridiculed the researchers.
    07-30-2015 06:18 PM
  12. monsieurms's Avatar
    There was some indication that this only applied to versions below Lollipop and if you have a recent Lollipop update it includes the patch Google created.

    Meanwhile, T-mobile says it's waiting on Samsung and will then get to it; Samsung says they are working on it:

    "Samsung: "Google notified us about the issue, and we are working to roll out the software update as soon as possible. Samsung encourages users to keep their software and apps updated, and to exercise caution when clicking on an unsecure mail or link.""
    07-31-2015 02:39 PM
  13. Dark Penguin's Avatar
    There was some indication that this only applied to versions below Lollipop and if you have a recent Lollipop update it includes the patch Google created.
    According to what I've read, the versions affected are Gingerbread through Kitkat.

    I haven't been keeping up with the latest developments, but do recall a lot of people with the S5 had problems with Lollipop, so I'm still holding off on that.
    07-31-2015 03:54 PM
  14. monsieurms's Avatar
    According to what I've read, the versions affected are Gingerbread through Kitkat.

    I haven't been keeping up with the latest developments, but do recall a lot of people with the S5 had problems with Lollipop, so I'm still holding off on that.
    As between some possible blips with Lollipop and damage from Stage Fright, I'd upgrade as soon as possible if that does it.
    07-31-2015 04:23 PM

Similar Threads

  1. Replies: 6
    Last Post: 07-28-2015, 11:30 AM
  2. How do I remove the Security Screen Lock?
    By iloz in forum Blu Android Phones
    Replies: 3
    Last Post: 07-27-2015, 03:39 PM
  3. Replies: 1
    Last Post: 07-27-2015, 03:20 PM
  4. Replies: 0
    Last Post: 07-27-2015, 12:09 AM
  5. Replies: 0
    Last Post: 07-26-2015, 11:58 PM
LINK TO POST COPIED TO CLIPBOARD