This is a major problem for users using original software.
[!RED ALERT!] HTC Massive Security Vulnerability, HTC EVO 3D, Sensation affected (updated)
[!RED ALERT!] HTC Massive Security Vulnerability, HTC EVO 3D, Sensation affected (updated)
|
|
Oct 4 2011, 10:13 AM
|
![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
1,548 posts Joined: Apr 2005 |
This is a major problem for users using original software.
|
|
|
|
|
|
Oct 4 2011, 10:32 AM
|
![]() ![]() ![]()
Junior Member
344 posts Joined: Aug 2011 From: Tanah tumpahnya darahku |
QUOTE(prody @ Oct 4 2011, 10:13 AM) exactly. and majority of non-geeks will use what was bundled together with the phone.cannot imagine the consequences if an evil criminal uploads an app to harvest personal details from the phone. at first, i supported htc bcos of their innovative HTC Sense software which is great and i could accept their handsets even though it didn't have the nicest screen, fastest processor, or slickest design. but now. |
|
|
Oct 4 2011, 11:11 AM
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
4,282 posts Joined: Apr 2008 |
QUOTE(DarkSilver @ Oct 4 2011, 08:25 AM) I don't think it's as shallow as yours. +1, you seem to be the only guy who noticed. Do you really reading what are those updates for? I don't bloody think so. If you do read, you don't tell this. It's all MENTIONED, SECURITY VULNERABILITY FIX, etc. Not just the general bug fixing and improvements. That's why I said, one will treat the message I said before is like "blank message". Again, this statement will be ignored. Because one will treat it as "blank message" again. Hey guys here in Android Section, stop feeding the troll. Ignore this thread. The TS/OP is known for being iFaging. I must troll this. QUOTE(Similan @ Oct 4 2011, 10:32 AM) at first, i supported htc bcos of their innovative HTC Sense software which is great and i could accept their handsets even though it didn't have the nicest screen, fastest processor, or slickest design. HAHAHA. bro, you're not a Android user to begin with, in case you missed my post earlier, I'll repeat again, shut the f-ck up.btw, Desire Z keyboard > BB9900 This post has been edited by phantomash: Oct 4 2011, 11:14 AM |
|
|
Oct 4 2011, 01:57 PM
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
2,759 posts Joined: Oct 2011 From: ★クララ - ClariS - アリス★ |
QUOTE unlike iOS which is much more secured and users have peace of mind. I would like you to draw back this statement... iOS isn't that secured like what do you think. in YouTube there are many videos have shown many iOS users have exploit iOS. Even thou the phone lock also can be exploit easily by an amateur. And most of iOS users have jailbreak their gadgets, so it is not as secured any more. Even thou android has so call bugs and security problems, their so problems are just a small fry you can settle it yourselves even thou you are not gadget savvy. Just wait HTC release the latest firmware and then update your phone. So, no matter you are iOS user or Android user. Nothing is perfect and enough said... we won't like to have flame war in Android thread because some iOS dudes come and underestimate the Android. This post has been edited by droid13579: Oct 4 2011, 02:00 PM |
|
|
Oct 4 2011, 02:38 PM
|
![]() ![]() ![]()
Junior Member
344 posts Joined: Aug 2011 From: Tanah tumpahnya darahku |
QUOTE(droid13579 @ Oct 4 2011, 01:57 PM) I would like you to draw back this statement... iOS isn't that secured like what do you think. in YouTube there are many videos have shown many iOS users have exploit iOS. Even thou the phone lock also can be exploit easily by an amateur. Show that iOS is easy to exploit? At least a link. Don't just simply type a statement. And most of iOS users have jailbreak their gadgets, so it is not as secured any more. Even thou android has so call bugs and security problems, their so problems are just a small fry you can settle it yourselves even thou you are not gadget savvy. Just wait HTC release the latest firmware and then update your phone. So, no matter you are iOS user or Android user. Nothing is perfect and enough said... we won't like to have flame war in Android thread because some iOS dudes come and underestimate the Android. How can you call a problem small fry when personal data is easily retrieve by any android app out there? and ppl here thought iPhone users are not tech-savvy. don't turn this into another keyboard-war. i'm doing all htc android users (or potential buyers) a big favor by highlighting security concerns so they may be wary. keep this thread clean, for goodness sake! the biggest issue here is ...that this disaster happens only when using HTC original firmware! and yes, if u have the technical capability to root/ jailbreak u shld be aware of the risks or issues related to it. again, droidfags shld put aside their pride and accept that there is a problem. this is beneficial rather than defending the obvious flaws with dumbo statements. |
|
|
Oct 4 2011, 02:46 PM
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
6,113 posts Joined: Jan 2003 From: Pokey Oaks |
QUOTE(Similan @ Oct 3 2011, 05:42 PM) agree abt ur rule of thumb. Just like bank phishing emails. So many people who are not tech-savvy use Maybank2U. So many kena con. Read email, click on link, enter password, *BAM*.but what is mostly concerning is not androidheads like you, BUT the ppl who are not so tech-savvy. even the caution message whenever u install an app is so complicated and wordy. normally ppl just press "OK" or "I Agree". surely they will just download from the android market bcos naturally, evrybody is assume to be safe. never in their nightmares cld they imagine the possibility of stolen money or worst, kidnapping by just using a htc android phone. rooting doesn't make ur android safer, it is just a remedy to a created problem. custom ROMs are safe? maybe yes, maybe no. the point is, since userbase is small and limited to androidheads, the possibilities of detecting a major security issue (even though it is there) is very unlikely. never in their nightmares cld they imagine the possibility of stolen money or worst, kidnapping by just following a maybank2u email. |
|
|
|
|
|
Oct 4 2011, 02:53 PM
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
3,000 posts Joined: Sep 2005 From: Puchong, Selangor |
It should be mentioned that the htcloggers.apk is only present in the most recent HTC OTAs. So the flagging of the exploit was early in the sense that not much people know about the exploit yet.
The flagging should be hailed more as an act of heroism of the Android developers community than a huge security hole dug by HTC. Everything else is pretty irrelevant. |
|
|
Oct 4 2011, 02:55 PM
|
![]() ![]() ![]()
Junior Member
344 posts Joined: Aug 2011 From: Tanah tumpahnya darahku |
QUOTE(Dannyl @ Oct 4 2011, 02:46 PM) Just like bank phishing emails. So many people who are not tech-savvy use Maybank2U. So many kena con. Read email, click on link, enter password, *BAM*. yes its true. the world is truly a dangerous place maybe it is easier to con/cheat/criminal when many aspects of our lives is connected.never in their nightmares cld they imagine the possibility of stolen money or worst, kidnapping by just following a maybank2u email. SO we don't really want to make it much worse by using technology which has massive security vulnerabilities. although not one system is entirely fool-proof, not even iOS but at least the locks must be in place. and now it seems HTC has opened all its locks and the poor android user now is spreading his legs for the criminal. pls do not praise me as noble and kind for doing this as i gain nothing and even subject myself to insults by childish ppl... but actually it is just the least that i can do to help. |
|
|
Oct 4 2011, 02:57 PM
|
![]() ![]() ![]()
Junior Member
344 posts Joined: Aug 2011 From: Tanah tumpahnya darahku |
QUOTE(DJFoo000 @ Oct 4 2011, 02:53 PM) It should be mentioned that the htcloggers.apk is only present in the most recent HTC OTAs. So the flagging of the exploit was early in the sense that not much people know about the exploit yet. until now, the folks at htc still has not released a fix for this.The flagging should be hailed more as an act of heroism of the Android developers community than a huge security hole dug by HTC. Everything else is pretty irrelevant. on a more sinister note, perhaps htc meant it to be like this for purposes only known among their evil selves. |
|
|
Oct 5 2011, 06:28 AM
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
8,461 posts Joined: Mar 2007 From: Kota Bharu,Kelantan |
I'd like to add something,from what i can see the htcloggers.apk is also present in custom ROMs that are based on HTC's ROM [ARHD etc].On AOSP ROMs like the CM7/XboarderMOD the .apk isn't there.
|
|
|
Oct 5 2011, 08:02 AM
|
![]() ![]() ![]()
Junior Member
344 posts Joined: Aug 2011 From: Tanah tumpahnya darahku |
QUOTE(Racerx @ Oct 5 2011, 06:28 AM) I'd like to add something,from what i can see the htcloggers.apk is also present in custom ROMs that are based on HTC's ROM [ARHD etc].On AOSP ROMs like the CM7/XboarderMOD the .apk isn't there. +1thanks for the info! ![]() anyway, here is latest official information. response from HTC QUOTE HTC Public Statement HTC takes claims related to the security of our products very seriously. In our ongoing investigation into this recent claim, we have concluded that while this HTC software itself does no harm to customers' data, there is a vulnerability that could potentially be exploited by a malicious third-party application. A third party malware app exploiting this or any other vulnerability would potentially be acting in violation of civil and criminal laws. So far, we have not learned of any customers being affected in this way and would like to prevent it by making sure all customers are aware of this potential vulnerability. HTC is working very diligently to quickly release a security update that will resolve the issue on affected devices. Following a short testing period by our carrier partners, the patch will be sent over-the-air to customers, who will be notified to download and install it. We urge all users to install the update promptly. During this time, as always, we strongly urge customers to use caution when downloading, using, installing and updating applications from untrusted sources. ROTFL even apps from android market can exploit this. so htc is saying android market is 'untrusted source'. |
|
|
Oct 5 2011, 09:33 AM
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
3,000 posts Joined: Sep 2005 From: Puchong, Selangor |
QUOTE(Racerx @ Oct 5 2011, 06:28 AM) I'd like to add something,from what i can see the htcloggers.apk is also present in custom ROMs that are based on HTC's ROM [ARHD etc].On AOSP ROMs like the CM7/XboarderMOD the .apk isn't there. I'm very sure these devs removed whatever logging apps present. They hate this kind of things. Since the ROM is theirs, there's no reason to report back to HTC the issues.Just reading the changelog will tell you ARHD removed htcloggers on 21st september. |
|
|
Oct 5 2011, 03:41 PM
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
8,461 posts Joined: Mar 2007 From: Kota Bharu,Kelantan |
QUOTE(DJFoo000 @ Oct 5 2011, 09:33 AM) I'm very sure these devs removed whatever logging apps present. They hate this kind of things. Since the ROM is theirs, there's no reason to report back to HTC the issues. The .apk was there on ARHD 3.6.0 that i downloaded and used,didn't realize it was removed from ARHD 3.6.1 Just reading the changelog will tell you ARHD removed htcloggers on 21st september. |
|
|
|
|
|
Oct 8 2011, 12:40 PM
|
![]()
Junior Member
44 posts Joined: Aug 2011 From: Petaling Jaya |
At times like these, OSes are all prone to something. However, I don't really hear anything about WP7 and Symbian.
|
|
|
Oct 8 2011, 01:08 PM
|
![]() ![]() ![]()
Junior Member
344 posts Joined: Aug 2011 From: Tanah tumpahnya darahku |
QUOTE(Alveolus @ Oct 8 2011, 12:40 PM) At times like these, OSes are all prone to something. However, I don't really hear anything about WP7 and Symbian. As mentioned numerous times, nothing is perfect. But due to open nature of android, security breaches and malware is easy and becoming increasingly common. As long as the manufacturers react quickly, usually it is alright.The trouble is now, the breach is caused by HTC own software and worst is, those taiwanese is taking their sweet time while htc android users are being threatened everyday! Poor souls. |
|
|
Oct 8 2011, 02:57 PM
|
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]()
All Stars
13,192 posts Joined: Jul 2011 From: Middle of Avalon |
QUOTE(Similan @ Oct 8 2011, 01:08 PM) As mentioned numerous times, nothing is perfect. But due to open nature of android, security breaches and malware is easy and becoming increasingly common. As long as the manufacturers react quickly, usually it is alright. I should've guess who start this babbling thread..:-))The trouble is now, the breach is caused by HTC own software and worst is, those taiwanese is taking their sweet time while htc android users are being threatened everyday! Poor souls. Well that's okay as long as it kept tight inside this thread and not spilling all over the place like usual. I'm heading for more useful thread rather than waste my time here..good day :-P |
|
|
Oct 8 2011, 02:59 PM
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
2,759 posts Joined: Oct 2011 From: ★クララ - ClariS - アリス★ |
I afraid someone might spill the beans...
|
|
|
Oct 8 2011, 03:04 PM
|
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]()
All Stars
13,192 posts Joined: Jul 2011 From: Middle of Avalon |
|
|
|
Oct 8 2011, 03:08 PM
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
2,759 posts Joined: Oct 2011 From: ★クララ - ClariS - アリス★ |
QUOTE If he try then we will close this thread as the other thread before this :-)) p/s - maybe put a vacation ticket might not be a bad idea after all ~~lol~~ Lol... mod already closed one of someones thread... What do you think about this? |
|
|
Oct 8 2011, 03:13 PM
|
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]()
All Stars
13,192 posts Joined: Jul 2011 From: Middle of Avalon |
|
|
Topic ClosedOptions
|
| Change to: | 0.0228sec
0.35
5 queries
GZIP Disabled
Time is now: 5th December 2025 - 12:05 AM |