Welcome Guest ( Log In | Register )

Bump Topic Topic Closed RSS Feed
4 Pages < 1 2 3 4 >Bottom

Outline · [ Standard ] · Linear+

 [!RED ALERT!] HTC Massive Security Vulnerability, HTC EVO 3D, Sensation affected (updated)

views
     
prody
post Oct 4 2011, 10:13 AM

Dance while the record spins
******
Senior Member
1,548 posts

Joined: Apr 2005


This is a major problem for users using original software.
SUSSimilan
post Oct 4 2011, 10:32 AM

Casual
***
Junior Member
344 posts

Joined: Aug 2011
From: Tanah tumpahnya darahku



QUOTE(prody @ Oct 4 2011, 10:13 AM)
This is a major problem for users using original software.
*
exactly. and majority of non-geeks will use what was bundled together with the phone.
cannot imagine the consequences if an evil criminal uploads an app to harvest personal details from the phone.
shakehead.gif

at first, i supported htc bcos of their innovative HTC Sense software which is great and i could accept their handsets even though it didn't have the nicest screen, fastest processor, or slickest design.

but now. sad.gif

phantomash
post Oct 4 2011, 11:11 AM

Not a Fanboy
*******
Senior Member
4,282 posts

Joined: Apr 2008
QUOTE(DarkSilver @ Oct 4 2011, 08:25 AM)
I don't think it's as shallow as yours.
Do you really reading what are those updates for? I don't bloody think so.
If you do read, you don't tell this. It's all MENTIONED, SECURITY VULNERABILITY FIX, etc. Not just the general bug fixing and improvements.
That's why I said, one will treat the message I said before is like "blank message".

Again, this statement will be ignored. Because one will treat it as "blank message" again.

Hey guys here in Android Section, stop feeding the troll.
Ignore this thread. The TS/OP is known for being iFaging.
I must troll this.
*
+1, you seem to be the only guy who noticed. nod.gif


QUOTE(Similan @ Oct 4 2011, 10:32 AM)
at first, i supported htc bcos of their innovative HTC Sense software which is great and i could accept their handsets even though it didn't have the nicest screen,  fastest processor, or slickest design.
*
HAHAHA. bro, you're not a Android user to begin with, in case you missed my post earlier, I'll repeat again, shut the f-ck up.

btw, Desire Z keyboard > BB9900 whistling.gif

This post has been edited by phantomash: Oct 4 2011, 11:14 AM
droid13579
post Oct 4 2011, 01:57 PM

Google Nexus and Vanilla Android Lover, ClariS Fan!?
*******
Senior Member
2,759 posts

Joined: Oct 2011
From: ★クララ - ClariS - アリス★


QUOTE
unlike iOS which is much more secured and users have peace of mind.


I would like you to draw back this statement... iOS isn't that secured like what do you think. in YouTube there are many videos have shown many iOS users have exploit iOS. Even thou the phone lock also can be exploit easily by an amateur.

And most of iOS users have jailbreak their gadgets, so it is not as secured any more.

Even thou android has so call bugs and security problems, their so problems are just a small fry you can settle it yourselves even thou you are not gadget savvy. Just wait HTC release the latest firmware and then update your phone.

So, no matter you are iOS user or Android user. Nothing is perfect and enough said... we won't like to have flame war in Android thread because some iOS dudes come and underestimate the Android.

This post has been edited by droid13579: Oct 4 2011, 02:00 PM
SUSSimilan
post Oct 4 2011, 02:38 PM

Casual
***
Junior Member
344 posts

Joined: Aug 2011
From: Tanah tumpahnya darahku



QUOTE(droid13579 @ Oct 4 2011, 01:57 PM)
I would like you to draw back this statement... iOS isn't that secured like what do you think. in YouTube there are many videos have shown many iOS users have exploit iOS. Even thou the phone lock also can be exploit easily by an amateur.

And most of iOS users have jailbreak their gadgets, so it is not as secured any more.

Even thou android has so call bugs and security problems, their so problems are just a small fry you can settle it yourselves even thou you are not gadget savvy. Just wait HTC release the latest firmware and then update your phone.

So, no matter you are iOS user or Android user. Nothing is perfect and enough said... we won't like to have flame war in Android thread because some iOS dudes come and underestimate the Android.
*
Show that iOS is easy to exploit? At least a link. Don't just simply type a statement.

How can you call a problem small fry when personal data is easily retrieve by any android app out there? and ppl here thought iPhone users are not tech-savvy. doh.gif

don't turn this into another keyboard-war.
i'm doing all htc android users (or potential buyers) a big favor by highlighting security concerns so they may be wary.
keep this thread clean, for goodness sake! mad.gif

the biggest issue here is ...that this disaster happens only when using HTC original firmware!
and yes, if u have the technical capability to root/ jailbreak u shld be aware of the risks or issues related to it.

again, droidfags shld put aside their pride and accept that there is a problem.
this is beneficial rather than defending the obvious flaws with dumbo statements.

wink.gif


Dannyl
post Oct 4 2011, 02:46 PM

what the fucuk-yimai
*******
Senior Member
6,113 posts

Joined: Jan 2003
From: Pokey Oaks



QUOTE(Similan @ Oct 3 2011, 05:42 PM)
agree abt ur rule of thumb.  rclxms.gif
but what is mostly concerning is not androidheads like you, BUT the ppl who are not so tech-savvy.
even the caution message whenever u install an app is so complicated and wordy.
normally ppl just press "OK" or "I Agree".

surely they will just download from the android market bcos naturally, evrybody is assume to be safe.

never in their nightmares cld they imagine the possibility of stolen money or worst, kidnapping by just using a htc android phone.  sad.gif

rooting doesn't make ur android safer, it is just a remedy to a created problem.
custom ROMs are safe? maybe yes, maybe no.
the point is, since userbase is small and limited to androidheads, the possibilities of detecting a major security issue (even though it is there) is very unlikely.
*
Just like bank phishing emails. So many people who are not tech-savvy use Maybank2U. So many kena con. Read email, click on link, enter password, *BAM*.

never in their nightmares cld they imagine the possibility of stolen money or worst, kidnapping by just following a maybank2u email. sad.gif
DJFoo000
post Oct 4 2011, 02:53 PM

Really? That's the best reply you can come up with?
*******
Senior Member
3,000 posts

Joined: Sep 2005
From: Puchong, Selangor



It should be mentioned that the htcloggers.apk is only present in the most recent HTC OTAs. So the flagging of the exploit was early in the sense that not much people know about the exploit yet.

The flagging should be hailed more as an act of heroism of the Android developers community than a huge security hole dug by HTC.

Everything else is pretty irrelevant.
SUSSimilan
post Oct 4 2011, 02:55 PM

Casual
***
Junior Member
344 posts

Joined: Aug 2011
From: Tanah tumpahnya darahku



QUOTE(Dannyl @ Oct 4 2011, 02:46 PM)
Just like bank phishing emails.  So many people who are not tech-savvy use Maybank2U.  So many kena con.  Read email, click on link, enter password, *BAM*.

never in their nightmares cld they imagine the possibility of stolen money or worst, kidnapping by just following a maybank2u email.  sad.gif
*
yes its true. the world is truly a dangerous place maybe it is easier to con/cheat/criminal when many aspects of our lives is connected.

SO we don't really want to make it much worse by using technology which has massive security vulnerabilities. although not one system is entirely fool-proof, not even iOS

but at least the locks must be in place.
and now it seems HTC has opened all its locks and the poor android user now is spreading his legs for the criminal.

pls do not praise me as noble and kind for doing this as i gain nothing and even subject myself to insults by childish ppl... but actually it is just the least that i can do to help.

SUSSimilan
post Oct 4 2011, 02:57 PM

Casual
***
Junior Member
344 posts

Joined: Aug 2011
From: Tanah tumpahnya darahku



QUOTE(DJFoo000 @ Oct 4 2011, 02:53 PM)
It should be mentioned that the htcloggers.apk is only present in the most recent HTC OTAs. So the flagging of the exploit was early in the sense that not much people know about the exploit yet.

The flagging should be hailed more as an act of heroism of the Android developers community than a huge security hole dug by HTC.

Everything else is pretty irrelevant.
*
until now, the folks at htc still has not released a fix for this.

on a more sinister note, perhaps htc meant it to be like this for purposes only known among their evil selves. yawn.gif
Racerx
post Oct 5 2011, 06:28 AM

Tell Your World
*******
Senior Member
8,461 posts

Joined: Mar 2007
From: Kota Bharu,Kelantan



I'd like to add something,from what i can see the htcloggers.apk is also present in custom ROMs that are based on HTC's ROM [ARHD etc].On AOSP ROMs like the CM7/XboarderMOD the .apk isn't there.
SUSSimilan
post Oct 5 2011, 08:02 AM

Casual
***
Junior Member
344 posts

Joined: Aug 2011
From: Tanah tumpahnya darahku



QUOTE(Racerx @ Oct 5 2011, 06:28 AM)
I'd like to add something,from what i can see the htcloggers.apk is also present in custom ROMs that are based on HTC's ROM [ARHD etc].On AOSP ROMs like the CM7/XboarderMOD the .apk isn't there.
*
+1

thanks for the info!

user posted image

anyway, here is latest official information.
response from HTC

QUOTE
HTC Public Statement

HTC takes claims related to the security of our products very seriously. In our ongoing investigation into this recent claim, we have concluded that while this HTC software itself does no harm to customers' data, there is a vulnerability that could potentially be exploited by a malicious third-party application. A third party malware app exploiting this or any other vulnerability would potentially be acting in violation of civil and criminal laws. So far, we have not learned of any customers being affected in this way and would like to prevent it by making sure all customers are aware of this potential vulnerability.

HTC is working very diligently to quickly release a security update that will resolve the issue on affected devices. Following a short testing period by our carrier partners, the patch will be sent over-the-air to customers, who will be notified to download and install it. We urge all users to install the update promptly. During this time, as always, we strongly urge customers to use caution when downloading, using, installing and updating applications from untrusted sources.


ROTFL
even apps from android market can exploit this. so htc is saying android market is 'untrusted source'.

DJFoo000
post Oct 5 2011, 09:33 AM

Really? That's the best reply you can come up with?
*******
Senior Member
3,000 posts

Joined: Sep 2005
From: Puchong, Selangor



QUOTE(Racerx @ Oct 5 2011, 06:28 AM)
I'd like to add something,from what i can see the htcloggers.apk is also present in custom ROMs that are based on HTC's ROM [ARHD etc].On AOSP ROMs like the CM7/XboarderMOD the .apk isn't there.
*
I'm very sure these devs removed whatever logging apps present. They hate this kind of things. Since the ROM is theirs, there's no reason to report back to HTC the issues.

Just reading the changelog will tell you ARHD removed htcloggers on 21st september.
Racerx
post Oct 5 2011, 03:41 PM

Tell Your World
*******
Senior Member
8,461 posts

Joined: Mar 2007
From: Kota Bharu,Kelantan



QUOTE(DJFoo000 @ Oct 5 2011, 09:33 AM)
I'm very sure these devs removed whatever logging apps present. They hate this kind of things. Since the ROM is theirs, there's no reason to report back to HTC the issues.

Just reading the changelog will tell you ARHD removed htcloggers on 21st september.
*
The .apk was there on ARHD 3.6.0 that i downloaded and used,didn't realize it was removed from ARHD 3.6.1 blush.gif
Alveolus
post Oct 8 2011, 12:40 PM

New Member
*
Junior Member
44 posts

Joined: Aug 2011
From: Petaling Jaya
At times like these, OSes are all prone to something. However, I don't really hear anything about WP7 and Symbian.
SUSSimilan
post Oct 8 2011, 01:08 PM

Casual
***
Junior Member
344 posts

Joined: Aug 2011
From: Tanah tumpahnya darahku



QUOTE(Alveolus @ Oct 8 2011, 12:40 PM)
At times like these, OSes are all prone to something. However, I don't really hear anything about WP7 and Symbian.
*
As mentioned numerous times, nothing is perfect. But due to open nature of android, security breaches and malware is easy and becoming increasingly common. As long as the manufacturers react quickly, usually it is alright.
The trouble is now, the breach is caused by HTC own software and worst is, those taiwanese is taking their sweet time while htc android users are being threatened everyday! Poor souls.

waveweaver
post Oct 8 2011, 02:57 PM

★★Android & Apple★★
********
All Stars
13,192 posts

Joined: Jul 2011
From: Middle of Avalon
QUOTE(Similan @ Oct 8 2011, 01:08 PM)
As mentioned numerous times, nothing is perfect. But due to open nature of android, security breaches and malware is easy and becoming increasingly common. As long as the manufacturers react quickly, usually it is alright.
The trouble is now, the breach is caused by HTC own software and worst is, those taiwanese is taking their sweet time while htc android users are being threatened everyday! Poor souls.
*
I should've guess who start this babbling thread..:-))
Well that's okay as long as it kept tight inside this thread and not spilling all over the place like usual.
I'm heading for more useful thread rather than waste my time here..good day :-P
droid13579
post Oct 8 2011, 02:59 PM

Google Nexus and Vanilla Android Lover, ClariS Fan!?
*******
Senior Member
2,759 posts

Joined: Oct 2011
From: ★クララ - ClariS - アリス★


I afraid someone might spill the beans... yawn.gif
waveweaver
post Oct 8 2011, 03:04 PM

★★Android & Apple★★
********
All Stars
13,192 posts

Joined: Jul 2011
From: Middle of Avalon
QUOTE(droid13579 @ Oct 8 2011, 02:59 PM)
I afraid someone might spill the beans...  yawn.gif
*
If he try then we will close this thread as the other thread before this :-))
p/s - maybe put a vacation ticket might not be a bad idea after all ~~lol~~
droid13579
post Oct 8 2011, 03:08 PM

Google Nexus and Vanilla Android Lover, ClariS Fan!?
*******
Senior Member
2,759 posts

Joined: Oct 2011
From: ★クララ - ClariS - アリス★


QUOTE
If he try then we will close this thread as the other thread before this :-)) p/s - maybe put a vacation ticket might not be a bad idea after all ~~lol~~


Lol... mod already closed one of someones thread... What do you think about this? tongue.gif
waveweaver
post Oct 8 2011, 03:13 PM

★★Android & Apple★★
********
All Stars
13,192 posts

Joined: Jul 2011
From: Middle of Avalon
QUOTE(droid13579 @ Oct 8 2011, 03:08 PM)
Lol... mod already closed one of someones thread... What do you think about this?  tongue.gif
*
As long as he keep tight inside this thread and not spilling overboard with his nonsense, then i'll pass. Got much better things to do than layan his usual babbling :-)

4 Pages < 1 2 3 4 >Top
Topic ClosedOptions
 

Change to:
| Lo-Fi Version
0.0228sec    0.35    5 queries    GZIP Disabled
Time is now: 5th December 2025 - 12:05 AM