Virus Protection - Xoom General

Hello all,
Wanted to start a thread on virus protection for the Xoom. Appologize up front if my search did not work on finding a thread on this already.
Any recommendations on a virus scanner for the Xoom?

I use lookout on my phone. Haven't look into getting anything on the Xoom yet.

I wouldn't bother. It doesn't need it. If there are any malicious market apps they will be smote by the hand of Google.
Galaxy Tab::Tapatalk

alias_neo said:
I wouldn't bother. It doesn't need it. If there are any malicious market apps they will be smote by the hand of Google.
Galaxy Tab::Tapatalk
Click to expand...
Click to collapse
Assuming they haven't already grabbed and foned-home all of your information

Kcarpenter said:
Assuming they haven't already grabbed and foned-home all of your information
Click to expand...
Click to collapse
Just be more careful what you download from the market and check the permissions.
Sent from my HTC Desire using Tapatalk

Kcarpenter said:
Assuming they haven't already grabbed and foned-home all of your information
Click to expand...
Click to collapse
While this is true, no AV client exists on the market today that can actually do any worthwhile AV scanning.
The problem is that there is no way for the AV clients to hook into the kernel to do real checking. Most apps out there today just look for malicious apps in /data/apps/ by doing a signature check against known bad things.

Related

Mallware APPS Found on Market.

Found this today, just thought I would share. Some of us might have an app or two on this list.
http://www.readwriteweb.com/archive...tm_campaign=Feed:+readwriteweb+(ReadWriteWeb)
Interesting read. Thank you.
Sent from my SGH-T959 using XDA Premium App
Isn't Android Linux? So why is it getting malwares?! lol.
Also, I can't believe the fact that I have to install an antivirus App on my phone is closer to becoming the reality.
PaiPiePia said:
Isn't Android Linux? So why is it getting malwares?! lol.
Also, I can't believe the fact that I have to install an antivirus App on my phone is closer to becoming the reality.
Click to expand...
Click to collapse
any OS can be a target for viruses or malware. With Android becoming rather popular it's now becoming a target. People making viruses and malware programs want to hit a larger target not a smaller target.
Thanks for sharing the info.
Sent from my Loki powered Vibrant via the XDA App
Mallware? You mean apps that do autonomous shopping? That's what your significant other is for. Can't replace 'em with an app!
Scoobyracing03 said:
PaiPiePia said:
Isn't Android Linux? So why is it getting malwares?! lol.
Also, I can't believe the fact that I have to install an antivirus App on my phone is closer to becoming the reality.
Click to expand...
Click to collapse
any OS can be a target for viruses or malware. With Android becoming rather popular it's now becoming a target. People making viruses and malware programs want to hit a larger target not a smaller target.
Click to expand...
Click to collapse
I read about this on engadget & androidcentral had provided a list on which apps it was. AFAIK, I would've never downloaded those apps but one can never be too careful when it comes to personal information. I just installed Lookout a few mins ago.
I hate bastards that make virus's and stuff just to be funny. I would like to shove their phone up their butt. nah they might like it
Luckily, my edition of Common Sense 2011 works for Android too!
Xan_Kriegor said:
Luckily, my edition of Common Sense 2011 works for Android too!
Click to expand...
Click to collapse
If only that were shareware, then everyone could have some.
Sent from my Loki powered Vibrant via the XDA App
PaiPiePia said:
Isn't Android Linux? So why is it getting malwares?! lol.
Also, I can't believe the fact that I have to install an antivirus App on my phone is closer to becoming the reality.
Click to expand...
Click to collapse
android is unix based, but the thing is, the apps can run in the background.
The affected apps use the rageagainstthecage exploit to gain root, then run scripts in the background to get specific information (at least that's what they've identified so far). The thing is, anything (from what i originally heard) below 2.2.1 was able to have an app run the rageagainstthecage exploit or exploid exploit ran without any user interference, but apparently it is not pre-gingerbread.
Xan_Kriegor said:
Luckily, my edition of Common Sense 2011 works for Android too!
Click to expand...
Click to collapse
We need to copies of the 2011 edition out to everyone now!!!!!
Where's that rapper fellow when you need him?!
I help you guys out there ,everythime u download app from market look under what it controls ect u download task killer and in description says it controls network data ,i dont think so budddy ,do the math ppl
Besides that, carefully checking permissions, keep an eye out for those apps very easily by not allowing apps to get root. I actually downloaded an app a couple of weeks ago that asked for root.... Don't think so buddy. Uninstalled immediately, went to the market, rated it one star and made a comment about it! Thankfully we have a very well made super user app that asks whether you want to grant root privileges every time.
Quite frankly you have to be asking for it, giving root to any app.
bartek25 said:
I help you guys out there ,everythime u download app from market look under what it controls ect u download task killer and in description says it controls network data ,i dont think so budddy ,do the math ppl
Click to expand...
Click to collapse
Bartek! The voice of reason.
Sent from my Loki powered Vibrant via the XDA App
lol i reached my thanks limit for today but tomo you get two Br1cK'd

Mobile security on smart phones (ANDROID)

anyone know much about the sercurity on the phone?
recently i read about this new free security app called on NQ mobile.
http://www.redmondpie.com/nq-mobile...st-solution-against-malware-viruses-and-more/
i installed it and noticed that it really drains the battery (seems like if toggles apps that aren't even opened into its memory). so it got me thinking .. is it really worth it to install apps like these for anti-virus's, maleware, etc.. ?
did a search and it seems the top three as of March 20th are:
Kaspersky Mobile Security (not free)
Lookout Security & Antivirus (free)
F-Secure Mobile Security (more for parental control)
not too sure where NQ would fit into the picture since the article came out on april 11th.
anyhow anyone with any idea such programs on the android is worth the draw back on power consumption and security risk please comment!
thanks.
IMO I don't think there is an antivirus app out there that would serve its purpose... It's more common sense... There's a good reason why when you try to download non market apps that you have to read that little disclaimer and check the box to allow them to install... Know what the apps do, if it doesn't need a permission or if you dont think it needs a permission then don't install it...
Sent from my HTC Sensation 4g Rocking ARHD 6.6.2
wapena92 said:
IMO I don't think there is an antivirus app out there that would serve its purpose... It's more common sense... There's a good reason why when you try to download non market apps that you have to read that little disclaimer and check the box to allow them to install... Know what the apps do, if it doesn't need a permission or if you dont think it needs a permission then don't install it...
Sent from my HTC Sensation 4g Rocking ARHD 6.6.2
Click to expand...
Click to collapse
Very good advice. Also, keep really sensetive stuff to a minimum. If you can bank on your computer, do it.
I just flash another ROM every couple of days and get my apps from the market. Lol
i hear ya both..
so basically in, layman's terms, these so called "security" apps dont do squat?
and you should just keep personal and secured stuff off these devices and perhaps use a laptop to access key information (like banking and emails)?
I am not sure what you mean when you refer to some apps as non-market apps. think all the security apps i mentioned are available through the android market (aka Play Store).
Not the security apps. By non-market apps we mean any apk's installed that you get any place but the play store.
estallings15 said:
Not the security apps. By non-market apps we mean any apk's installed that you get any place but the play store.
Click to expand...
Click to collapse
thanked you both. .
i see.. guess i am not keen on where else you can get apk files other than the market place (play store) .
so bottom line is no need install these "security apps" cause they dont do anything?
junkiee24 said:
thanked you both. .
i see.. guess i am not keen on where else you can get apk files other than the market place (play store) .
so bottom line is no need install these "security apps" cause they dont do anything?
Click to expand...
Click to collapse
No, they do behind the scene stuff. Lookout scans ALL your apps, just to check for anything malicious. Lookout has some kind of backup, but I never use it. When I bought my myTouch, my T-Mobile rep installed about 5 must have apps on my phone, and Lookout was #1 on his list. I've been using it on every ROM I've had. Hope this helps!
EDIT: You can get apks from the internet. Specifically pirated apps. People do not want to pay for the app, so they download it online. But people could have modified that apk and but a virus or who knows what in that apk. So it's best to keep an anti virus app. Lookout scans a new app each time I install/update it.
invasion2 said:
No, they do behind the scene stuff. Lookout scans ALL your apps, just to check for anything malicious. Lookout has some kind of backup, but I never use it. When I bought my myTouch, my T-Mobile rep installed about 5 must have apps on my phone, and Lookout was #1 on his list. I've been using it on every ROM I've had. Hope this helps!
EDIT: You can get apks from the internet. Specifically pirated apps. People do not want to pay for the app, so they download it online. But people could have modified that apk and but a virus or who knows what in that apk. So it's best to keep an anti virus app. Lookout scans a new app each time I install/update it.
Click to expand...
Click to collapse
Cool.. so now the questions is which security app is better.. Lookout or this NQ one.. ill go ahead and try lookout and see how much battery drain i get.
i dont download any apks outside of the market. but i hear there were a few places that had pirated apks but i guess i never trusted them (blackmarket). its not like Cydia for the iOS, where the apps are safely cracked.. atleast i think they are. so with a security app i guess it would alert you if the apk is corrupt - nice.
Thanks again.
junkiee24 said:
Cool.. so now the questions is which security app is better.. Lookout or this NQ one.. ill go ahead and try lookout and see how much battery drain i get.
i dont download any apks outside of the market. but i hear there were a few places that had pirated apks but i guess i never trusted them (blackmarket). its not like Cydia for the iOS, where the apps are safely cracked.. atleast i think they are. so with a security app i guess it would alert you if the apk is corrupt - nice.
Thanks again.
Click to expand...
Click to collapse
I don't get any battery drain with Lookout. Hope you experience the same thing mate.
I used lookout for a little while, but then I realized that I only need it if I'm careless, which I'm not.
SECURITY!!!
Lookout is very good but since I'm rooted Avast free works wonders beyond basics. van allow which apps have internet access etc. must have for me. very nice on batt.
Has anyone ever had, or known anyone who got a virus or anything on a smartphone? Personally I haven't. Therefore I don't use any type of protection, which I probably should.
Sent from my HTC Glacier using XDA Premium
No, I don't know anyone who ever got malicious SW or any type of virus on Android. For the same reason I never heard of anyone getting a virus on Linux. And for the same reason, I don't have any apps that are made to protect me from things that aren't a threat.
estallings15 said:
Very good advice. Also, keep really sensetive stuff to a minimum. If you can bank on your computer, do it.
Click to expand...
Click to collapse
Right best option to do so...
junkiee24 said:
i hear ya both..
so basically in, layman's terms, these so called "security" apps dont do squat?
and you should just keep personal and secured stuff off these devices and perhaps use a laptop to access key information (like banking and email)
Click to expand...
Click to collapse
The reason why they don't much is because there not meant for this kind of system... Android unique system is a little well very complex to make a antivirus app or that would find malware... There are so many ways around it...
It's amazing... There's an article I read that explained this...
I'm gonna see if I can find it and post the link
Jack_R1 said:
No, I don't know anyone who ever got malicious SW or any type of virus on Android. For the same reason I never heard of anyone getting a virus on Linux. And for the same reason, I don't have any apps that are made to protect me from things that aren't a threat.
Click to expand...
Click to collapse
Well you should look around the web... You'll be surprised want you'll find... The threat on smartphones is very high... It's pretty scary...
If I find any of those articles ill post a link...
Sent from my HTC Sensation 4g Rocking ARHD 6.6.2
junkiee24 said:
i dont download any apks outside of the market. but i hear there were a few places that had pirated apks but i guess i never trusted them (blackmarket). its not like Cydia for the iOS, where the apps are safely cracked.. atleast i think they are. so with a security app i guess it would alert you if the apk is corrupt - nice.
Thanks again.
Click to expand...
Click to collapse
Those security apps don't really know what there looking for... It's a lot different then windows OS... They don't need much to mess around with your info...
Sent from my HTC Sensation 4g Rocking ARHD 6.6.0
http://www.xda-developers.com/android/major-facebook-sdk-vulnerability-run-for-the-hills/
There are good people out there but that's not always the case...
Vulnerability is everywhere...
It's hard to make an app with little mistakes as possible... Making an app period is hard... I've tried and failed horribly at it lol so I can just imagine how hard it is to take out those nicks, bugs and issues that causes problem like this
http://www.lifehacker.com.au/2011/11/do-android-antivirus-apps-actually-do-anything/
So people think otherwise from me...
Here is their opinion... I take this very lightly...
http://www.extremetech.com/computin...s-apps-are-useless-heres-what-to-do-instead/2
Here's with what I agree with...
Like I said some disagree.....
http://m.zdnet.com/blog/hardware/premium-rate-sms-trojans-hit-googles-android-market/17070
And here a small case of sms trojan that hit a little while back...
Just some things to read and think about...
Sent from my HTC Sensation 4g Rocking ARHD 6.6.2
It all boils down to not downloading crappy, unknown apps, and if downloading - checking their permissions. Trojans hit people who don't understand anything and don't have control over their apps (not that there aren't enough of those). Other threats are virtually non-existent.
true.. i am trying avast now.. pretty cool.
thanks everyone!
Exactly that simple lol
And no problem... Keep it safe
Sent from my HTC Sensation 4g Rocking ARHD 6.6.2

Scary Article. How do you protect yourself?

http://www.crn.com/240000735/printablearticle.htm
What software do you have to protect yourself/information?
Alias8818 said:
http://www.crn.com/240000735/printablearticle.htm
What software do you have to protect yourself/information?
Click to expand...
Click to collapse
Before I open any app I open manifests.xml and change permissions. lol
Anything else We can do?
IMO, If you get anything like this. You deserve it! Almost just like on a PC. If your not smart enough to check your stuff before you put it on your phone, then stick to buying your apps. Don't open and launch things from emails you don't know about. Your not smart enough to know what sites are bad and how to control what your clicking through. By all means hurry and pirate an anti... app too please. Then I can charge you to fix it. XXX only make me money.
Did I miss anything? lol
Love,
Your loving IT Pro
Oh yeah I forgot. LBE security guard. Amazing root permissions app. It allows you to revoke certain apps permissions. Like if you don't want angry birds access to your data and wifi you can do that. An added plus is with that you dont get any more stupid adds.
Sent From My Sprint Galaxy Nexus via XDA Premium
Avast! Is pretty awesome, mostly anti-virus protection.........the malware stuff is a totally different kinda animal, would be great to see a good solid app.........gonna try Uber's recommendation.
Sent from my SPH-D700 using xda premium
I use a combo of several apps
Superuser (with PIN) for SU rights
AdFree - to block most ads
Droid Wall - to totally block data & WiFI on an app by app basis
LBE Privacy Guard - to remove specific permission from apps that require data access
One of the easiest thing to do, is only get apps from trusted sources, which will drastically cut down on risks
Finally, think twice about installing an app with a low number of downloads.
DCRocks said:
I use a combo of several apps
Superuser (with PIN) for SU rights
AdFree - to block most ads
Droid Wall - to totally block data & WiFI on an app by app basis
LBE Privacy Guard - to remove specific permission from apps that require data access
One of the easiest thing to do, is only get apps from trusted sources, which will drastically cut down on risks
Finally, think twice about installing an app with a low number of downloads.
Click to expand...
Click to collapse
Why do you have LBE and Droid wall. You do know LBE has that function too right? Internet Firewall....
Sent From My Sprint Galaxy Nexus via XDA Premium
ÜBER™ said:
Oh yeah I forgot. LBE security guard. Amazing root permissions app. It allows you to revoke certain apps permissions. Like if you don't want angry birds access to your data and wifi you can do that. An added plus is with that you dont get any more stupid adds.
Sent From My Sprint Galaxy Nexus via XDA Premium
Click to expand...
Click to collapse
I agree 100% with this. The UI is super simple, and you can see how much data each app is using. It opened my eyes the first few times I used it as there were apps using data that had no real reason to. It didn't make sense to me.
As UBER mentioned, you can also disable GPS for apps like Angry Birds Space. I love how when you install a new app, a notification shows up up top reminding you to set permissions for that app.
Very basic, easy to use, and most importantly, powerful.
Thread Cleaned
And reopened
FNM
MALWARE Reply
So many people have Android devices now that it ruins it for everyone. That is what makes it a popular platform for that kind of stuff. Nobody ever released malware for Windows Mobile.
- 2 Bunny
kainppc6700 said:
So many people have Android devices now that it ruins it for everyone. That is what makes it a popular platform for that kind of stuff. Nobody ever released malware for Windows Mobile.
- 2 Bunny
Click to expand...
Click to collapse
I don't see the issue I download everywhere and even sites I know aren't protected yet I have no malware or problems.
Sent from my SPH-D700 using xda premium
Alias8818 said:
What software do you have to protect yourself/information?
Click to expand...
Click to collapse
My brain
VIRUS Reply
XxLostSoulxX said:
I don't see the issue I download everywhere and even sites I know aren't protected yet I have no malware or problems.
Sent from my SPH-D700 using xda premium
Click to expand...
Click to collapse
Same here. What kind of places do you actually have to go to to get a virus?
- 2B
kainppc6700 said:
Same here. What kind of places do you actually have to go to to get a virus?
- 2B
Click to expand...
Click to collapse
Most likely, any Russian or Chinese market for cracked apps, as most of the infected apps come from these two regions.
Also, any hacker board for cracked apps has a higher than average chance of having an infected app
SECURITY ON MOBILE Reply
DCRocks said:
Most likely, any Russian or Chinese market for cracked apps, as most of the infected apps come from these two regions.
Also, any hacker board for cracked apps has a higher than average chance of having an infected app
Click to expand...
Click to collapse
I don't live in Russia or China, so I can't say I've ever been to one of these "cracked markets".
Could you provide an example of a "hacker board for cracked apps"?
- 2B
Used to use lookout, but I flash my phone so often I haven't downloaded it in a while.
Sent from my SPH-D700 using XDA

Anyone get device not compatible for Starbucks app?

I'm getting the message "your device isn't compatible with this version" when trying to download the starbucks app.
Anyone else? Why isn't it compatible?
Abyssimpact said:
I'm getting the message "your device isn't compatible with this version" when trying to download the starbucks app.
Anyone else? Why isn't it compatible?
Click to expand...
Click to collapse
Because Caribou is better??
A lot of developers haven't updated their apps to work with 4.2 yet. Might be the issue in your case.
Sent from my Nexus 4 using xda premium
Abyssimpact said:
I'm getting the message "your device isn't compatible with this version" when trying to download the starbucks app.
Anyone else? Why isn't it compatible?
Click to expand...
Click to collapse
No, but the app force closes upon opening for me. So it doesn't work.
dwd3885 said:
No, but the app force closes upon opening for me. So it doesn't work.
Click to expand...
Click to collapse
Same here, I also get FC.
In the meantime, I will use the Square app for Starbucks (if I don't have my card hanging around). I just won't get any benefits on my member card.
d_phekt said:
Because Caribou is better??
Click to expand...
Click to collapse
Caribou's stock is $11, Starbucks stock is $50.
'Nuff said.
Yeah it's a 4.2 Issue
Same. It seems like a JB 4.2 issue. Other people in the app comments have noticed it too.
Abyssimpact said:
Caribou's stock is $11, Starbucks stock is $50.
'Nuff said.
Click to expand...
Click to collapse
Because stock price without regards to volume means absolutely everything. You must be a Starbucks customer, as you certainly have the intellect of one.
Why do people pay so much for a cup of garbage. I can get a can of coffee for the same price as you pay for two cups.
Sent from my LG-MS770 using xda app-developers app
I just installed Cyanogen Mod 10, which is only 4.1.2, and I can't reinstall the app either.
I don't think it's just a 4.2 issue, as people keep posting. Any other ideas?
Like the brand or not, some of us like the app. Help would be appreciated.
Starbucks doesn't work on 4.2 yet.
the1onewolf said:
Starbucks doesn't work on 4.2 yet.
Click to expand...
Click to collapse
Understood...
And, as I just stated before you, I am not ON 4.2 yet, and I am having the same issue.
***UPDATE***
Okay, so, I am still on CM 10 (STILL Android 4.1.2)
I side-loaded the Starbucks APK 2.2.3 (the newest, as of this posting) and it seems to work fine.
HOWEVER, the Play Store shows that it is installed, but still gives me a warning that the app is not compatible with my phone. Doesn't show the normal buttons for Uninstalling or Opening, so I'm assuming it won't Update as normal, either.
Side note: all other apps have seemed to work perfectly on my copy of this build, including Groupon and a side-load of Google Wallet. Not sure what the deal is.
gottgen said:
Understood...
And, as I just stated before you, I am not ON 4.2 yet, and I am having the same issue.
***UPDATE***
Okay, so, I am still on CM 10 (STILL Android 4.1.2)
I side-loaded the Starbucks APK 2.2.3 (the newest, as of this posting) and it seems to work fine.
HOWEVER, the Play Store shows that it is installed, but still gives me a warning that the app is not compatible with my phone. Doesn't show the normal buttons for Uninstalling or Opening, so I'm assuming it won't Update as normal, either.
Side note: all other apps have seemed to work perfectly on my copy of this build, including Groupon and a side-load of Google Wallet. Not sure what the deal is.
Click to expand...
Click to collapse
where did you get the 2.2.3 apk?
2000army said:
where did you get the 2.2.3 apk?
Click to expand...
Click to collapse
I downloaded it onto my Kindle, then backed it up with ES File Explorer and moved the file to my phone with Dropbox.
I don't have enough posts under my belt to post links yet...try this, omit the obvious.
OR, a mod is more than welcome to edit this and/or post the link themselves, after checking it's valid?
dropbox.com/s/6va5115zp0md1mq/Starbucks_2.2.3.apk
gottgen said:
I downloaded it onto my Kindle, then backed it up with ES File Explorer and moved the file to my phone with Dropbox.
I don't have enough posts under my belt to post links yet...try this, omit the obvious.
OR, a mod is more than welcome to edit this and/or post the link themselves, after checking it's valid?
dropbox.com/s/6va5115zp0md1mq/Starbucks_2.2.3.apk
Click to expand...
Click to collapse
Thanks ... worked great!
I'm more concerned with the fact Starbucks has an app. What use it could be? I must investigate this conundrum.
Vertana said:
I'm more concerned with the fact Starbucks has an app. What use it could be? I must investigate this conundrum.
Click to expand...
Click to collapse
Basically, it's a useful app for anyone who's a regular and uses the reloadable rewards card. That's all.
gottgen said:
Basically, it's a useful app for anyone who's a regular and uses the reloadable rewards card. That's all.
Click to expand...
Click to collapse
Just to add on to this: using the re loadable card allows for free refills on coffee and iced coffee as long as you're there. Great for when you're doing homework; just buy a small and get unlimited.
So when the hell is Starbucks going to update their app?!?
Thank you for posting the .APK buddy.. it works just fine on 4.1 but it crashes on 4.2 i really hope starbucks updates its app soon, as i use it a lot
Thanks,
Oops

Master Key Exploit patch?

Has HTC push the patch? Samsung already roll out security patches to S4. I Just scanned, my ONE is unpatched/vulnerable.
Here’s How You Can Check If Your Android Device Is Patched Against The Master Key Exploit.http://www.redmondpie.com/check-if-your-android-device-is-patched-against-the-master-key-exploit/
Sent from my HTC One using xda app-developers app
the Google Edition roms are patched
IINexusII said:
the Google Edition roms are patched
Click to expand...
Click to collapse
THe sense based roms have not been patched yet but when i reached out to them they said that it will be resolved soon with a update. They could not give me an ETA on when it would be coming out but assured me they take it very seriously and are working hard to get it rolled out.
crackeyes said:
THe sense based roms have not been patched yet but when i reached out to them they said that it will be resolved soon with a update. They could not give me an ETA on when it would be coming out but assured me they take it very seriously and are working hard to get it rolled out.
Click to expand...
Click to collapse
That app says I'm patched and I'm running InsertCoin with the latest elementalX. I wonder if the master key patch is in the kernel. If so, that makes sense.
Sent from my HTC One using Tapatalk 2
It appears 4.2.2 build/soft no. 2.24.401.1 / HTC 5.34 is patched as well :good:
@Wiss said:
It appears 4.2.2 build/soft no. 2.24.401.1 / HTC 5.34 is patched as well :good:
Click to expand...
Click to collapse
What CID and OTA or custom Rom?
Sent from my HTC One using Tapatalk 4 Beta
Ye in the last OTA it is patched. The 4.2.2
My One is "patched." I don't download warez, steal paid apps, or install third-party app stores that are untrusted.
I have no sympathy for anyone who does the above and gets their phone jacked up.
BTW Can someone give us a technical (not too technical) explanation of what is this ?
Thanks.
KekeJr said:
BTW Can someone give us a technical (not too technical) explanation of what is this ?
Thanks.
Click to expand...
Click to collapse
Applications are cryptographically signed. The idea is that another software house or or anybody else can't come up with an "update" to that app, as the signature will be different.
The exploit allows exactly that to happen.
Lets say you download Google maps v7 from the internet because you're impatient, and you install it over the top of the existing one. In theory, if it succeeds, it must have come from Google and hasn't been tampered with to install a Trojan or virus or whatever.
With this exploit, the apk can be modified whilst retaining the same signature. Basically you can't trust downloads that didn't come from the play store until the exploit is patched.
BenPope said:
Basically you can't trust downloads that didn't come from the play store
Click to expand...
Click to collapse
Fixed.
This is, and has been, true for every single Android "security issue, virus alert, malware warning," etc that's ever existed.
Sent from my HTC One
BenPope said:
Applications are cryptographically signed. The idea is that another software house or or anybody else can't come up with an "update" to that app, as the signature will be different.
The exploit allows exactly that to happen.
Lets say you download Google maps v7 from the internet because you're impatient, and you install it over the top of the existing one. In theory, if it succeeds, it must have come from Google and hasn't been tampered with to install a Trojan or virus or whatever.
With this exploit, the apk can be modified whilst retaining the same signature. Basically you can't trust downloads that didn't come from the play store until the exploit is patched.
Click to expand...
Click to collapse
First i want to thank you !
Second: ....so, basically this means that it was not that BAD... as the media said !
We all knew that only Play store has trustable content.
Thanks, again !
This patch is in a play store update not an Android update. I have it in play store 4.1.10, there is an app which lets you check I think it's called bluebox or something.you can also check in Google settings if you have an option to verify apps.
unremarked said:
Fixed.
This is, and has been, true for every single Android "security issue, virus alert, malware warning," etc that's ever existed.
Sent from my HTC One
Click to expand...
Click to collapse
That's funny, because the app store is littered with adware and malware. Just a few days ago, there was an app in the top 20 that was clearly malware, and it remained there for weeks before (presumably) being pulled off. As a general rule, I don't download any apps that require the "run at startup" or "install shortcuts" permissions, unless I fully trust the developer. By the way, there's an easy solution; Google could let us control our own privacy settings (like every other OS on the market), but then again, that would eat into their bottom line After all, Google's business model is to literally steal user data and sell it to others.
unremarked said:
Fixed.
This is, and has been, true for every single Android "security issue, virus alert, malware warning," etc that's ever existed.
Sent from my HTC One
Click to expand...
Click to collapse
It's easy to put malicious apps on the play store since there's no review process like apple, but things tend to get flagged quickly.
Basically don't install a calculator app that has full phone/internet/device permissions
The android security model is actually quite good IMO, there's been some exploits but everybody has them (not just android) and they get patched relatively quickly. Potential exploits aside it's actually quite good.
Sent from my HTC One using Tapatalk 2
REDACTED
Sent from my HTC One using xda app-developers app
WhatsAUsername said:
That's funny, because the app store is littered with adware and malware. Just a few days ago, there was an app in the top 20 that was clearly malware, and it remained there for weeks before (presumably) being pulled off.
Click to expand...
Click to collapse
Really? What app was that? I mean, I get annoyed at Candy Crush Saga spam too, but I hardly consider it malware.
WhatsAUsername said:
By the way, there's an easy solution, Google could let us control our own privacy settings (like every other OS on the market), but then again, that would eat into their bottom line After all, Google's business model is to literally steal user data and sell it to others.
Click to expand...
Click to collapse
You're kidding yourself if you think Apple or Microsoft isn't collecting as much data about you as they can and doing what they want with it. Beyond that, I always take point with folks who accuse any company of "stealing your information." They're not. You're freely giving them access to it (as outlined in that Terms of Service/ELEU agreement you don't read) to utilize their services. If you don't want them to have your info, then don't share your info with them.
bbedward said:
It's easy to put malicious apps on the play store since there's no review process like apple, but things tend to get flagged quickly.
Click to expand...
Click to collapse
Halfway true. It's more difficult than you think to get malicious apps on the Play store. Most of the "successful" attacks have been from someone uploading the 1.0 version of their app(which is perfectly clean, and passes inspection by Google Bouncer) then pushes an update to it with some of the malicious code. As you noted, it usually gets flagged and removed at this point. The other way I've heard of people getting "infected" from apps off the Play store is when the author ties their ads into a nasty website, tricks the user into clicking on it, then further tricks them into downloading an unsigned/untrusted APK.
Yup, as long as your not doing some silly things like getting you apps from the Pirate Bay or Joes crazy world of underground apps you will be more or less safe.
godutch said:
This patch is in a play store update not an Android update. I have it in play store 4.1.10, there is an app which lets you check I think it's called bluebox or something.you can also check in Google settings if you have an option to verify apps.
Click to expand...
Click to collapse
I don't think the update patch is on play store. Latest update scan tell's you to Ask your device vendor for update. So it should be security update OTA from HTC?
Sent from my HTC One using xda app-developers app
alanchai said:
I don't think the update patch is on play store. Latest update scan tell's you to Ask your device vendor for update. So it should be security update OTA from HTC?
Sent from my HTC One using xda app-developers app
Click to expand...
Click to collapse
Check your play store version I have 4.1.10 and I am patched

Categories

Resources