Android Security Flaw Erases All Data

Page 2 - Seeking answers? Join the Tom's Hardware community: where nearly two million members share solutions and discuss the latest tech.
Status
Not open for further replies.
G

Guest

Guest
The "exploit" only worked on previous, and even before the fix - it did not work on the SGS III.
When a user dials a number on the S3, or clicks on one, the device doesn't automatically dials it, it displays the number and asks what program you'd like to call it with - hence making the exploit not run automatically.
 

gamoniac

Distinguished
Feb 6, 2011
25
0
18,530
A lot of Android fans and Apples fans here, I see.. but no matter what, this is a big security issue regardless of how some try to downplay it. As some have pointed -- what about those older Android phones? I just checked and there is no update available for my old Android phone.
 

Vorador2

Distinguished
Jun 26, 2007
472
12
18,785
You know, Samsung released a patch for this issue trough OTA update ages ago. Only vulnerable devices are phones that aren't up to date.
 

JustAnotherNoob

Distinguished
Apr 19, 2007
61
0
18,640
AAAAND another badly researched (and outdated) article on Tom's called "news".
The issue described was at first believed to affect only Samsung phones. Only a day or so later it was confirmed that it affects all android devices up to ICS. JB users are safe.

And the issue is misrepresented in this "article". The problem was that it was very easily possible to write a website that would automatically trigger the USSD code, WITHOUT THE USER SELECTING OR CLICKING IT. It was simply a problem about how the phones browsers handled a tag. The affected phones would oben this "link" in the phone application and autodial.
If the phone number dialed is a USSD code (and if it is the factory reset code for the device) then bad things can happen (like a full reset without any warnings).
The proper way phone numbers SHOULD be handled would be to open the phone app, put in the number, but have the user hit the dial button.
JB does it the proper way. Older versions of Android can do it either way, depending on device, android version, phone app and manufacturer customizations.

"A proportion of the malware seems to only target Samsung devices. " - Yes, since the USSD codes are device or manufacturer specific (especially things like factory reset codes) it is rather obvious that the Samsung "reset all" code will not affect HTC devices. Doh!

TL;DR> Horribly written article, sensationalist and misleading headline, incomplete information... This "article" is not journalism, this is trolling.
 
Status
Not open for further replies.