Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > comp.mobile.android > #56151 > unrolled thread
| Started by | Alek <alek.trishan@gmail.com> |
|---|---|
| First post | 2018-10-01 13:54 -0400 |
| Last post | 2018-10-04 13:14 +0100 |
| Articles | 20 on this page of 90 — 16 participants |
Back to article view | Back to comp.mobile.android
Anti-virus? Alek <alek.trishan@gmail.com> - 2018-10-01 13:54 -0400
Re:Anti-virus? Libor Striz <poutnik4REMOVEnntp@CAPITALSgmail.com> - 2018-10-01 20:05 +0200
Re: Anti-virus? Alek <alek.trishan@gmail.com> - 2018-10-01 14:15 -0400
Re: Anti-virus? Calum <com.gmail@nospam.scottishwildcat> - 2018-10-01 19:55 +0100
Re: Anti-virus? Joerg Lorenz <hugybear@gmx.ch> - 2018-10-01 22:11 +0200
Re: Anti-virus? Libor Striz <poutnik4REMOVEnntp@CAPITALSgmail.com> - 2018-10-02 02:14 +0200
Re: Anti-virus? Joerg Lorenz <hugybear@gmx.ch> - 2018-10-02 06:18 +0200
Re: Anti-virus? Libor Striz <poutnik4REMOVEnntp@CAPITALSgmail.com> - 2018-10-02 02:34 +0200
Re: Anti-virus? Hergen Lehmann <hlehmann.expires.5-11@snafu.de> - 2018-10-01 20:49 +0200
Re: Anti-virus? Alek <alek.trishan@gmail.com> - 2018-10-01 16:03 -0400
Re: Anti-virus? Arlen H Holder <arlenh.older@no.spam.net> - 2018-10-02 02:52 +0000
Re: Anti-virus? Hergen Lehmann <hlehmann.expires.5-11@snafu.de> - 2018-10-02 10:29 +0200
Re: Anti-virus? "Carlos E. R." <robin_listas@es.invalid> - 2018-10-03 13:30 +0200
Re: Anti-virus? Hergen Lehmann <hlehmann.expires.5-11@snafu.de> - 2018-10-03 15:09 +0200
Re: Anti-virus? "Carlos E. R." <robin_listas@es.invalid> - 2018-10-03 15:31 +0200
Re: Anti-virus? Hergen Lehmann <hlehmann.expires.5-11@snafu.de> - 2018-10-03 16:33 +0200
Re: Anti-virus? Arlen H Holder <arlenh.older@no.spam.net> - 2018-10-02 02:50 +0000
Re: Anti-virus? Hergen Lehmann <hlehmann.expires.5-11@snafu.de> - 2018-10-02 10:55 +0200
Re: Anti-virus? Arlen H Holder <arlenh.older@no.spam.net> - 2018-10-02 12:32 +0000
Re: Anti-virus? 123456789 <12345@12345.com> - 2018-10-02 09:45 -0700
Re: Anti-virus? Frank Slootweg <this@ddress.is.invalid> - 2018-10-02 17:54 +0000
Re: Anti-virus? 123456789 <12345@12345.com> - 2018-10-02 13:15 -0700
Re: Anti-virus? Arlen H Holder <arlenh.older@no.spam.net> - 2018-10-03 02:38 +0000
Re: Anti-virus? Frank Slootweg <this@ddress.is.invalid> - 2018-10-03 10:49 +0000
Re: Anti-virus? Arlen Holder <a%rlenh.older@no.spam.net> - 2018-10-03 12:11 +0000
Re: Anti-virus? 123456789 <12345@12345.com> - 2018-10-03 08:42 -0700
Re: Anti-virus? Arlen Holder <a%rlenh.older@no.spam.net> - 2018-10-03 16:16 +0000
Re: Anti-virus? Frank Slootweg <this@ddress.is.invalid> - 2018-10-03 17:32 +0000
Re: Anti-virus? Java Jive <java@evij.com.invalid> - 2018-10-03 19:02 +0100
Re: Anti-virus? Hergen Lehmann <hlehmann.expires.5-11@snafu.de> - 2018-10-03 20:13 +0200
Re: Anti-virus? Frank Slootweg <this@ddress.is.invalid> - 2018-10-03 20:09 +0000
Re: Anti-virus? Hergen Lehmann <hlehmann.expires.5-11@snafu.de> - 2018-10-03 23:23 +0200
Re: Anti-virus? Arlen Holder <a%rlenh.older@no.spam.net> - 2018-10-04 13:06 +0000
Re: Anti-virus? Frank Slootweg <this@ddress.is.invalid> - 2018-10-04 15:02 +0000
Google does *not* track *you*! (was: Anti-virus?) Frank Slootweg <this@ddress.is.invalid> - 2018-10-04 15:44 +0000
Re: Google does *not* track *you*! 123456789 <12345@12345.com> - 2018-10-04 09:10 -0700
Re: Google does *not* track *you*! "Carlos E.R." <robin_listas@es.invalid> - 2018-10-07 22:03 +0200
Re: Google does *not* track *you*! 123456789 <12345@12345.com> - 2018-10-07 14:23 -0700
Re: Google does *not* track *you*! Frank Slootweg <this@ddress.is.invalid> - 2018-10-04 17:07 +0000
Re: Anti-virus? 123456789 <12345@12345.com> - 2018-10-04 09:10 -0700
Re: Anti-virus? Arlen H Holder <arlenh.older@no.spam.net> - 2018-10-03 02:36 +0000
Re: Anti-virus? Arlen H Holder <arlenh.older@no.spam.net> - 2018-10-03 02:34 +0000
Re: Anti-virus? 123456789 <12345@12345.com> - 2018-10-02 20:33 -0700
Re: Anti-virus? Arlen Holder <a%rlenh.older@no.spam.net> - 2018-10-03 04:30 +0000
Re: Anti-virus? 123456789 <12345@12345.com> - 2018-10-02 22:13 -0700
Re: Anti-virus? Arlen Holder <a%rlenh.older@no.spam.net> - 2018-10-03 12:52 +0000
Re: Anti-virus? "Carlos E. R." <robin_listas@es.invalid> - 2018-10-03 15:09 +0200
Re: Anti-virus? Arlen Holder <a%rlenh.older@no.spam.net> - 2018-10-03 15:40 +0000
Re: Anti-virus? 123456789 <12345@12345.com> - 2018-10-03 08:42 -0700
Re: Anti-virus? Arlen Holder <a%rlenh.older@no.spam.net> - 2018-10-03 16:16 +0000
Re: Anti-virus? 123456789 <12345@12345.com> - 2018-10-03 15:52 -0700
Re: Anti-virus? Arlen Holder <a%rlenh.older@no.spam.net> - 2018-10-03 23:31 +0000
Re: Anti-virus? 123456789 <123456@123456.com> - 2018-10-03 21:21 -0700
Re: Anti-virus? Arlen Holder <a%rlenh.older@no.spam.net> - 2018-10-04 13:07 +0000
Re: Anti-virus? 123456789 <12345@12345.com> - 2018-10-04 09:10 -0700
Re: Anti-virus? "Carlos E. R." <robin_listas@es.invalid> - 2018-10-03 13:37 +0200
Re: Anti-virus? nospam <nospam@nospam.invalid> - 2018-10-03 08:44 -0400
Re: Anti-virus? Arlen Holder <a%rlenh.older@no.spam.net> - 2018-10-03 12:52 +0000
Re: Anti-virus? "Carlos E. R." <robin_listas@es.invalid> - 2018-10-03 15:06 +0200
Re: Anti-virus? Arlen Holder <a%rlenh.older@no.spam.net> - 2018-10-03 15:40 +0000
Re: Anti-virus? "Carlos E.R." <robin_listas@es.invalid> - 2018-10-07 20:41 +0200
Re: Anti-virus? Arlen Holder <a%rlenh.older@no.spam.net> - 2018-10-08 15:00 +0000
Re: Anti-virus? Hergen Lehmann <hlehmann.expires.5-11@snafu.de> - 2018-10-02 20:42 +0200
Re: Anti-virus? "Carlos E. R." <robin_listas@es.invalid> - 2018-10-03 13:44 +0200
Re: Anti-virus? Arlen Holder <a%rlenh.older@no.spam.net> - 2018-10-03 12:52 +0000
Re: Anti-virus? "Carlos E. R." <robin_listas@es.invalid> - 2018-10-03 15:14 +0200
Re: Anti-virus? Hergen Lehmann <hlehmann.expires.5-11@snafu.de> - 2018-10-03 15:31 +0200
Re: Anti-virus? "Carlos E. R." <robin_listas@es.invalid> - 2018-10-03 17:47 +0200
Re: Anti-virus? Arlen Holder <a%rlenh.older@no.spam.net> - 2018-10-03 16:16 +0000
Re: Anti-virus? Hergen Lehmann <hlehmann.expires.5-11@snafu.de> - 2018-10-03 18:20 +0200
Re: Anti-virus? Arlen Holder <a%rlenh.older@no.spam.net> - 2018-10-03 17:18 +0000
Re: Anti-virus? Arlen Holder <a%rlenh.older@no.spam.net> - 2018-10-03 15:39 +0000
Re: Anti-virus? "Carlos E. R." <robin_listas@es.invalid> - 2018-10-03 17:49 +0200
Re: Anti-virus? Arlen Holder <a%rlenh.older@no.spam.net> - 2018-10-03 16:16 +0000
Re: Anti-virus? Hergen Lehmann <hlehmann.expires.5-11@snafu.de> - 2018-10-03 15:28 +0200
Re: Anti-virus? Arlen Holder <a%rlenh.older@no.spam.net> - 2018-10-03 15:39 +0000
Re: Anti-virus? "Carlos E.R." <robin_listas@es.invalid> - 2018-10-07 20:48 +0200
Re: Anti-virus? Hergen Lehmann <hlehmann.expires.5-11@snafu.de> - 2018-10-07 21:40 +0200
Re: Anti-virus? Alek <alek.trishan@gmail.com> - 2018-10-02 19:33 -0400
Re: Anti-virus? Arlen H Holder <arlenh.older@no.spam.net> - 2018-10-03 02:40 +0000
Re: Anti-virus? Alek <alek.trishan@gmail.com> - 2018-10-03 13:55 -0400
Re: Anti-virus? nospam <nospam@nospam.invalid> - 2018-10-03 14:08 -0400
Re: Anti-virus? Arlen Holder <a%rlenh.older@no.spam.net> - 2018-10-04 13:07 +0000
Re: Anti-virus? nospam <nospam@nospam.invalid> - 2018-10-04 10:03 -0400
Re: Anti-virus? Arlen Holder <a%rlenh.older@no.spam.net> - 2018-10-06 02:56 +0000
Re: Anti-virus? "Carlos E.R." <robin_listas@es.invalid> - 2018-10-07 20:50 +0200
Re: Anti-virus? Arlen Holder <a%rlenh.older@no.spam.net> - 2018-10-08 15:00 +0000
Re: Anti-virus? "Carlos E.R." <robin_listas@es.invalid> - 2018-10-07 20:54 +0200
Re: Anti-virus? Arlen H Holder <arlenh.older@no.spam.net> - 2018-10-02 02:47 +0000
Re: Anti-virus? Andy Burns <usenet@andyburns.uk> - 2018-10-04 13:14 +0100
Page 1 of 5 [1] 2 3 4 5 Next page →
| From | Alek <alek.trishan@gmail.com> |
|---|---|
| Date | 2018-10-01 13:54 -0400 |
| Subject | Anti-virus? |
| Message-ID | <potn0c$8hq$1@dont-email.me> |
Is there really any reason to use an AV app on an Android device? If so, what is the reason? If not, why not? Thanks.
[toc] | [next] | [standalone]
| From | Libor Striz <poutnik4REMOVEnntp@CAPITALSgmail.com> |
|---|---|
| Date | 2018-10-01 20:05 +0200 |
| Message-ID | <potnl8$c3b$1@dont-email.me> |
| In reply to | #56151 |
Alek <alek.trishan@gmail.com> Wrote in message: > Is there really any reason to use an AV app on an Android device? > > If so, what is the reason? > > If not, why not? > > Thanks. > Is there any reason to believe there are no malicious applications for Android ? They may not spread themselves automatically, but some of them were installed by millions of users. -- Libor Striz aka Poutnik ( a pilgrim/wanderer/wayfarer) "Humour is the only effective weapon against stupidity." Miloš Forman ----Android NewsGroup Reader---- http://usenet.sinaapp.com/
[toc] | [prev] | [next] | [standalone]
| From | Alek <alek.trishan@gmail.com> |
|---|---|
| Date | 2018-10-01 14:15 -0400 |
| Message-ID | <poto8p$gc8$1@dont-email.me> |
| In reply to | #56154 |
Can you name three? Libor Striz wrote on 10/1/2018 2:05 PM: > Alek <alek.trishan@gmail.com> Wrote in message: >> Is there really any reason to use an AV app on an Android device? >> >> If so, what is the reason? >> >> If not, why not? >> >> Thanks. >> > Is there any reason to believe there are no malicious > applications for Android ? They may not spread themselves > automatically, but some of them were installed by millions of > users. >
[toc] | [prev] | [next] | [standalone]
| From | Calum <com.gmail@nospam.scottishwildcat> |
|---|---|
| Date | 2018-10-01 19:55 +0100 |
| Message-ID | <potqjn$1b9p$1@gioia.aioe.org> |
| In reply to | #56155 |
On 01/10/2018 19:15, Alek wrote: > Can you name three? HenBox, Guerilla, ZooPark. And they were just from the first half of this year. > > Libor Striz wrote on 10/1/2018 2:05 PM: >> Alek <alek.trishan@gmail.com> Wrote in message: >>> Is there really any reason to use an AV app on an Android device? >>> >>> If so, what is the reason? >>> >>> If not, why not? >>> >>> Thanks. >>> >> Is there any reason to believe there are no malicious >> applications for Android ? They may not spread themselves >> automatically, but some of them were installed by millions of >> users. >>
[toc] | [prev] | [next] | [standalone]
| From | Joerg Lorenz <hugybear@gmx.ch> |
|---|---|
| Date | 2018-10-01 22:11 +0200 |
| Message-ID | <potv1u$ll$1@dont-email.me> |
| In reply to | #56154 |
Am 01.10.18 um 20:05 schrieb Libor Striz: > Alek <alek.trishan@gmail.com> Wrote in message: >> Is there really any reason to use an AV app on an Android device? >> >> If so, what is the reason? >> >> If not, why not? >> >> Thanks. >> > Is there any reason to believe there are no malicious > applications for Android ? They may not spread themselves > automatically, but some of them were installed by millions of > users. > This is not an answer at all! There is no reason to believe snake oil would have prevented that installation. AV-software increases the vulnerable code base. There is only one effective protection: Brain 1.0. And brain 1.0 is clearly preventing the installation of "anti-virus-malware". BTW: This av-crap is typical windows-thinking.
[toc] | [prev] | [next] | [standalone]
| From | Libor Striz <poutnik4REMOVEnntp@CAPITALSgmail.com> |
|---|---|
| Date | 2018-10-02 02:14 +0200 |
| Message-ID | <poud8e$kp2$1@dont-email.me> |
| In reply to | #56159 |
Joerg Lorenz <hugybear@gmx.ch> Wrote in message: > Am 01.10.18 um 20:05 schrieb Libor Striz: >> Alek <alek.trishan@gmail.com> Wrote in message: >>> Is there really any reason to use an AV app on an Android device? >>> >>> If so, what is the reason? >>> >>> If not, why not? >>> >>> Thanks. >>> >> Is there any reason to believe there are no malicious >> applications for Android ? They may not spread themselves >> automatically, but some of them were installed by millions of >> users. >> > This is not an answer at all! > There is no reason to believe snake oil would have prevented that > installation. > > AV-software increases the vulnerable code base. There is only one > effective protection: Brain 1.0. And brain 1.0 is clearly preventing the > installation of "anti-virus-malware". > > BTW: This av-crap is typical windows-thinking. > Then use the Brain 1.0 little more. And no, it is not an effective protection. -- Libor Striz aka Poutnik ( a pilgrim/wanderer/wayfarer) "Humour is the only effective weapon against stupidity." Miloš Forman ----Android NewsGroup Reader---- http://usenet.sinaapp.com/
[toc] | [prev] | [next] | [standalone]
| From | Joerg Lorenz <hugybear@gmx.ch> |
|---|---|
| Date | 2018-10-02 06:18 +0200 |
| Message-ID | <pourj5$dh9$1@dont-email.me> |
| In reply to | #56163 |
Am 02.10.18 um 02:14 schrieb Libor Striz: > Joerg Lorenz <hugybear@gmx.ch> Wrote in message: >> AV-software increases the vulnerable code base. There is only one >> effective protection: Brain 1.0. And brain 1.0 is clearly preventing the >> installation of "anti-virus-malware". >> >> BTW: This av-crap is typical windows-thinking. >> > > Then use the Brain 1.0 little more. > And no, it is not an effective protection. Certainly better than any av-software. By concept this snake oil can only find malware it knows. By definition it is always lagging. Brain 1.0 is preventing even not yet known threats.
[toc] | [prev] | [next] | [standalone]
| From | Libor Striz <poutnik4REMOVEnntp@CAPITALSgmail.com> |
|---|---|
| Date | 2018-10-02 02:34 +0200 |
| Message-ID | <poueen$pos$1@dont-email.me> |
| In reply to | #56159 |
Joerg Lorenz <hugybear@gmx.ch> Wrote in message: > Am 01.10.18 um 20:05 schrieb Libor Striz: >> Alek <alek.trishan@gmail.com> Wrote in message: >>> Is there really any reason to use an AV app on an Android device? >>> >>> If so, what is the reason? >>> >>> If not, why not? >>> >>> Thanks. >>> >> Is there any reason to believe there are no malicious >> applications for Android ? They may not spread themselves >> automatically, but some of them were installed by millions of >> users. >> > This is not an answer at all! > There is no reason to believe snake oil would have prevented that > installation. The true snake oil is to pave the way for malware to have pleasant journey. I have not said it will prevent the installation. OTOH, the malware will not prevent its detection. > > AV-software increases the vulnerable code base. There is only one > effective protection: Brain 1.0. And brain 1.0 is clearly preventing the > installation of "anti-virus-malware". Majority of Android malware does not care about vulnerable code. Users install it themselves. > > BTW: This av-crap is typical windows-thinking. The weakest part of Linux is a part of its user base. The above is their typical rhetorics. In contrary to Linux, there is plenty of Android malware in the wild, and no brain of an ordinary user can distinguish seed and weed. Most of them come from official repositories. -- Libor Striz aka Poutnik ( a pilgrim/wanderer/wayfarer) "Humour is the only effective weapon against stupidity." Miloš Forman ----Android NewsGroup Reader---- http://usenet.sinaapp.com/
[toc] | [prev] | [next] | [standalone]
| From | Hergen Lehmann <hlehmann.expires.5-11@snafu.de> |
|---|---|
| Date | 2018-10-01 20:49 +0200 |
| Message-ID | <dq6a8f-nvf.ln1@hergen.dyndns.org> |
| In reply to | #56151 |
Am 01.10.2018 um 19:54 schrieb Alek: > Is there really any reason to use an AV app on an Android device? > > If so, what is the reason? - There is certainly malware around. - Most Android device manufacturers certainly have a problem rolling out security patches in a timely manner and for their whole product line, which is a real feast for each malware programmer. > If not, why not? - AV software (on an Android device as well an on a PC) is snakeoil. No app is capable of detecting all current malware and most apps do introduce additional risks not present in the bare OS. - Android devices are designed to steal personal data. A whole, major Category of malware is basically courted by the operating system manufacturer itself and no AV software will be able to change that.
[toc] | [prev] | [next] | [standalone]
| From | Alek <alek.trishan@gmail.com> |
|---|---|
| Date | 2018-10-01 16:03 -0400 |
| Message-ID | <potui9$t02$1@dont-email.me> |
| In reply to | #56157 |
Hergen Lehmann wrote on 10/1/2018 2:49 PM: > Am 01.10.2018 um 19:54 schrieb Alek: > >> Is there really any reason to use an AV app on an Android device? >> >> If so, what is the reason? > > - There is certainly malware around. My understanding is that the biggest threat comes from side-loaded apps. > - Most Android device manufacturers certainly have a problem rolling out > security patches in a timely manner and for their whole product line, > which is a real feast for each malware programmer. How does an Android device get infected? > >> If not, why not? > > - AV software (on an Android device as well an on a PC) is snakeoil. No > app is capable of detecting all current malware and most apps do > introduce additional risks not present in the bare OS. Defend that, will you? > - Android devices are designed to steal personal data. Really? What data? Who gets it? > A whole, major > Category of malware is basically courted by the operating system > manufacturer itself and no AV software will be able to change that. We're talking about different things. There are so many programs that collect data (including Windows) that your statement makes no sense to me. So in the last analysis, should an Android user have an AV app running or not?
[toc] | [prev] | [next] | [standalone]
| From | Arlen H Holder <arlenh.older@no.spam.net> |
|---|---|
| Date | 2018-10-02 02:52 +0000 |
| Message-ID | <poumgg$14h$1@news.mixmin.net> |
| In reply to | #56158 |
On Mon, 1 Oct 2018 16:03:16 -0400, Alek wrote: > My understanding is that the biggest threat comes from side-loaded apps. Are you intimating that the FOSS apps on, oh, say, F-Droid, are the "biggest threat"? Really? How do you justify that statement? Put another way, why would a FOSS app on F-Droid be any less or more secure than a proprietary app on Google Play?
[toc] | [prev] | [next] | [standalone]
| From | Hergen Lehmann <hlehmann.expires.5-11@snafu.de> |
|---|---|
| Date | 2018-10-02 10:29 +0200 |
| Message-ID | <nsmb8f-bfa.ln1@hergen.dyndns.org> |
| In reply to | #56158 |
Am 01.10.2018 um 22:03 schrieb Alek: >> - There is certainly malware around. > > My understanding is that the biggest threat comes from side-loaded apps. Unlikely. Side-loading is disabled by default on android and most users do not even know how to enable it. Also, popular side-loading platforms like F-Droid enjoy a rather high level of trust, much higher than the official app store. > How does an Android device get infected? In most cases by installing that new, popular game which contains some kind of malware and hasn't been pulled from the store yet. Google isn't exactly fast in doing this and is rather indifferent about spyware. Infected media files and web sites also are a common vector of attack. Android used to have many, many security holes in it's multimedia sub-system; almost every security update contains some fixed in there. Some devices (especially no-name china brands) do come with malware already pre-installed at the factory. In business environments, email attachments also pose a major risk, especially if combined with social engineering. >> - AV software (on an Android device as well an on a PC) is snakeoil. No >> app is capable of detecting all current malware and most apps do >> introduce additional risks not present in the bare OS. > > Defend that, will you? There were many instances in the past, where AV software actually introduced an attack vector. Use google. Also, AV software claiming to secure internet connections usually does break the encryption (otherwise it wouldn't be able to look into them), making it easy for other bad guys to jump on the bandwagon. >> - Android devices are designed to steal personal data. > > Really? What data? Who gets it? Advertising networks, which forward the data (or personal profiles created from the data) to their many, many, unnamed partners. If you didn't notice it yet: Google is an advertising company, and the whole reason they provide Android for free is to feed their database with tracking and behavioral data. Same goes for facebook&Co. >> A whole, major >> Category of malware is basically courted by the operating system >> manufacturer itself and no AV software will be able to change that. > > We're talking about different things. There are so many programs that > collect data (including Windows) that your statement makes no sense to me. That's exactly why this is an argument against using AV software: you can't prevent that kind of malware on an android device, even with the best AV solution installed. > So in the last analysis, should an Android user have an AV app running > or not? Do other (not data-stealing) types of malware pose a risk for you? Are you the guy who clicks on every link thrown at you without thinking first? Do you consider yourself to be too inexperienced to recognize sudden, strange behavior of your device? If yes, AV software may help you to feel better. Just don't expect it to protect you. ^_-
[toc] | [prev] | [next] | [standalone]
| From | "Carlos E. R." <robin_listas@es.invalid> |
|---|---|
| Date | 2018-10-03 13:30 +0200 |
| Message-ID | <g1jniaFknuvU1@mid.individual.net> |
| In reply to | #56171 |
On 02/10/2018 10.29, Hergen Lehmann wrote:
> Am 01.10.2018 um 22:03 schrieb Alek:
>
>>> - There is certainly malware around.
>>
>> My understanding is that the biggest threat comes from side-loaded apps.
>
> Unlikely. Side-loading is disabled by default on android and most users
> do not even know how to enable it. Also, popular side-loading platforms
> like F-Droid enjoy a rather high level of trust, much higher than the
> official app store.
>
>> How does an Android device get infected?
>
> In most cases by installing that new, popular game which contains some
> kind of malware and hasn't been pulled from the store yet. Google isn't
> exactly fast in doing this and is rather indifferent about spyware.
Then they would be Trojans, not virii.
> Infected media files and web sites also are a common vector of attack.
I don't think I have seen any :-?
> Android used to have many, many security holes in it's multimedia
> sub-system; almost every security update contains some fixed in there.
>
> Some devices (especially no-name china brands) do come with malware
> already pre-installed at the factory.
Not virii.
> In business environments, email attachments also pose a major risk,
> especially if combined with social engineering.
Not virii
:-)
>>> - Android devices are designed to steal personal data.
>>
>> Really? What data? Who gets it?
>
> Advertising networks, which forward the data (or personal profiles
> created from the data) to their many, many, unnamed partners.
>
> If you didn't notice it yet: Google is an advertising company, and the
> whole reason they provide Android for free is to feed their database
> with tracking and behavioral data. Same goes for facebook&Co.
Right.
--
Cheers,
Carlos E.R.
[toc] | [prev] | [next] | [standalone]
| From | Hergen Lehmann <hlehmann.expires.5-11@snafu.de> |
|---|---|
| Date | 2018-10-03 15:09 +0200 |
| Message-ID | <ukre8f-m02.ln1@hergen.dyndns.org> |
| In reply to | #56200 |
Am 03.10.2018 um 13:30 schrieb Carlos E. R.: >>> How does an Android device get infected? >> >> In most cases by installing that new, popular game which contains some >> kind of malware and hasn't been pulled from the store yet. Google isn't >> exactly fast in doing this and is rather indifferent about spyware. > > Then they would be Trojans, not virii. Not sure about that. Malware distributed through the store does rely heavily on word-of-mouth propaganda to spread quickly before being pulled. Quite likely some will try to spread actively, either by forging recommendations in the store, or by sending messages to contacts found in the contact list. Anyway, most AV software claims to protect against all kind of malware, not only virii, so it's rather pointless to try some demarcation here. >> Infected media files and web sites also are a common vector of attack. > > I don't think I have seen any :-? Well, i'm not visiting media piracy sites too much either. ;-) But there has been a lot of fuzz about this attack vector, especially when stagefright was discovered. >> Some devices (especially no-name china brands) do come with malware >> already pre-installed at the factory. > > Not virii. Not sure about that. As this is mainly a problem with malware found on chinese phones and targeted at the chinese market, it is almost impossible to find any details on purpose and distribution channels. But it would be strange, if not at least some of these will try to actively spread, too. >> In business environments, email attachments also pose a major risk, >> especially if combined with social engineering. > > Not virii Most of these *will* be virii. After the attacker has successfully penetrated the security of a company or governmental institution at some point (most likely the smartphone or desktop PC of some simple-minded non-technical employee), his success heavily depends on spreading out to more important computers in the local area network as fast as possible.
[toc] | [prev] | [next] | [standalone]
| From | "Carlos E. R." <robin_listas@es.invalid> |
|---|---|
| Date | 2018-10-03 15:31 +0200 |
| Message-ID | <g1julsFm4mjU1@mid.individual.net> |
| In reply to | #56212 |
On 03/10/2018 15.09, Hergen Lehmann wrote:
> Am 03.10.2018 um 13:30 schrieb Carlos E. R.:
>
>>>> How does an Android device get infected?
>>>
>>> In most cases by installing that new, popular game which contains some
>>> kind of malware and hasn't been pulled from the store yet. Google isn't
>>> exactly fast in doing this and is rather indifferent about spyware.
>>
>> Then they would be Trojans, not virii.
>
> Not sure about that. Malware distributed through the store does rely
> heavily on word-of-mouth propaganda to spread quickly before being
> pulled. Quite likely some will try to spread actively, either by forging
> recommendations in the store, or by sending messages to contacts found
> in the contact list.
>
> Anyway, most AV software claims to protect against all kind of malware,
> not only virii, so it's rather pointless to try some demarcation here.
Well, I, as others, wonder about how actual virus can propagate on
Android devices.
On the other hand, I doubt how much an Antivirus can do against
"trojans", ie, software distributed through official sources that do bad
things. Can they be really faster than google, with the huge amount of
apps out there?
>
>>> Infected media files and web sites also are a common vector of attack.
>>
>> I don't think I have seen any :-?
>
> Well, i'm not visiting media piracy sites too much either. ;-)
> But there has been a lot of fuzz about this attack vector, especially
> when stagefright was discovered.
Ah... those media files.
I would not use Android for those - Nor Windows. :-p
>
>>> Some devices (especially no-name china brands) do come with malware
>>> already pre-installed at the factory.
>>
>> Not virii.
>
> Not sure about that. As this is mainly a problem with malware found on
> chinese phones and targeted at the chinese market, it is almost
> impossible to find any details on purpose and distribution channels.
> But it would be strange, if not at least some of these will try to
> actively spread, too.
>
>>> In business environments, email attachments also pose a major risk,
>>> especially if combined with social engineering.
>>
>> Not virii
>
> Most of these *will* be virii.
How can they spread to another phone? Sending another email? Because
that looks rather like a social engineering trojan. :-p
> After the attacker has successfully penetrated the security of a company
> or governmental institution at some point (most likely the smartphone or
> desktop PC of some simple-minded non-technical employee), his success
> heavily depends on spreading out to more important computers in the
> local area network as fast as possible.
Yes, computers, yes. But I have not seen phones using samba or opening
ports :-?
--
Cheers,
Carlos E.R.
[toc] | [prev] | [next] | [standalone]
| From | Hergen Lehmann <hlehmann.expires.5-11@snafu.de> |
|---|---|
| Date | 2018-10-03 16:33 +0200 |
| Message-ID | <ej0f8f-gb4.ln1@hergen.dyndns.org> |
| In reply to | #56214 |
Am 03.10.2018 um 15:31 schrieb Carlos E. R.: >> Anyway, most AV software claims to protect against all kind of malware, >> not only virii, so it's rather pointless to try some demarcation here. > > Well, I, as others, wonder about how actual virus can propagate on > Android devices. Spyware in most cases through massive advertising and deliberate mis-use of the store algorithms. The store favors apps, which have been downloaded a lot in the past hours, which in turn triggers even more downloads. Social engineering (e.g. forged message from a friend saying "you must try out this new game i found") may also be used. "Real" viruses likely through web sites or message attachments and the many unpatched exploits found in the outdated android versions present on the vast majority of devices. > On the other hand, I doubt how much an Antivirus can do against > "trojans", ie, software distributed through official sources that do bad > things. Can they be really faster than google, with the huge amount of > apps out there? As already said, google isn't exactly fast in pulling apps and they tend to turn a blind eye towards spyware, as long as they benefit from it by selling ads. But i agree, it is doubtful whether a third-party AV solution will be much of an improvement here. >> After the attacker has successfully penetrated the security of a company >> or governmental institution at some point (most likely the smartphone or >> desktop PC of some simple-minded non-technical employee), his success >> heavily depends on spreading out to more important computers in the >> local area network as fast as possible. > > Yes, computers, yes. But I have not seen phones using samba or opening > ports :-? I guess, a phone (or some other appliance) will likely only be the door opener to the LAN in this scenario, with the actual damage being inflicted to the PCs and servers. But i don't know statistics about that. Companies don't like to talk about being infected.
[toc] | [prev] | [next] | [standalone]
| From | Arlen H Holder <arlenh.older@no.spam.net> |
|---|---|
| Date | 2018-10-02 02:50 +0000 |
| Message-ID | <poumdb$11k$1@news.mixmin.net> |
| In reply to | #56157 |
On Mon, 1 Oct 2018 20:49:17 +0200, Hergen Lehmann wrote: > Android devices are designed to steal personal data. A whole, major > Category of malware is basically courted by the operating system > manufacturer itself and no AV software will be able to change that. There is no doubt "personal data" on Android, that may not be on desktop systems, such as your "contact list", which is an integral part of a phone application suite. But, other than your contact list (i.e., other than the people you communicate with and those conversations), what other "personal data" is on a phone, that isn't already on all the other platforms? I realize you'll say "banking", but only a fool does banking on the phone. You'll say web browsing, but again, a phone is a terrible place to browse the web from. Hence, other than contacts & associated communications, what "personal data" is on a phone, that isn't on any other device? HINT: This question is Android/iOS agnostic.
[toc] | [prev] | [next] | [standalone]
| From | Hergen Lehmann <hlehmann.expires.5-11@snafu.de> |
|---|---|
| Date | 2018-10-02 10:55 +0200 |
| Message-ID | <4cob8f-dta.ln1@hergen.dyndns.org> |
| In reply to | #56166 |
Am 02.10.2018 um 04:50 schrieb Arlen H Holder: > But, other than your contact list (i.e., other than the people you > communicate with and those conversations), what other "personal data" is on > a phone, that isn't already on all the other platforms? Location data. How is your daily routine? Where were you going when diverting from your routine that day? Which stores do you usually visit? Which demonstrations did you participate in and what does this give away about your political views? ... Communication details. Which persons from your contact list do you actually communicate with? Is there a correlation relation between you visiting a certain location and previous communication? ... Photos. Were did you take them, what are they showing? What personal interests can be derived from them? Which people did you meet? All major social networks do feature some kind of automatic image analysis with facial detection. And they did not spent millions into developing this for the users - they did spent the money to provide even better data to their paying customers, which include advertising partners as well as governmental institutions. Aside from these phone-specific things, the smartphone is just the platform most people use these days for most of their personal data processing needs. It contains more and more attractive data then that old rusty PC sitting around in the corner most of the time. > I realize you'll say "banking", but only a fool does banking on the phone. I agree. Still many people are doing it and many banking institutes did even develop apps and do advertise them. > You'll say web browsing, but again, a phone is a terrible place to browse > the web from. I agree. Still the long, boring commute to/from work is when i have actually the time to look up things.
[toc] | [prev] | [next] | [standalone]
| From | Arlen H Holder <arlenh.older@no.spam.net> |
|---|---|
| Date | 2018-10-02 12:32 +0000 |
| Message-ID | <povoh7$leb$1@news.mixmin.net> |
| In reply to | #56173 |
On Tue, 2 Oct 2018 10:55:00 +0200, Hergen Lehmann wrote: > Location data. Ah. Very good point. I missed that, but there's a reason I missed it. HINT: I have location turned off, plus reporting of BSSIDs turned off. But you're right. It's not a threat to me, but for most people it is. HINT: My SSIDs are set to *_nomap > How is your daily routine? Where were you going when > diverting from your routine that day? Which stores do you usually visit? > Which demonstrations did you participate in and what does this give away > about your political views? ... Yes. Agreed. Most people have their phone set up wrong (the default). So the two biggest threats we've identified on the phone are: a. Contact communication, and, b. Location information. > Communication details. Which persons from your contact list do you > actually communicate with? Is there a correlation relation between you > visiting a certain location and previous communication? ... Yes. See above. > Photos. Were did you take them, what are they showing? What personal > interests can be derived from them? Which people did you meet? Another good one (my photos don't save GPS, but I do take photos). So that's three things: 1. Communication data. 2. Location data. 3. Photographic data. > All major social networks do feature some kind of automatic image > analysis with facial detection. And they did not spent millions into > developing this for the users - they did spent the money to provide even > better data to their paying customers, which include advertising > partners as well as governmental institutions. In addition to facial recognition algorithms... We published a report that showed a _single_ photo can fingerprint a phone. > Aside from these phone-specific things, the smartphone is just the > platform most people use these days for most of their personal data > processing needs. It contains more and more attractive data then that > old rusty PC sitting around in the corner most of the time. Agreed. Except taxes! :) >> I realize you'll say "banking", but only a fool does banking on the phone. > > I agree. Still many people are doing it and many banking institutes did > even develop apps and do advertise them. True. > >> You'll say web browsing, but again, a phone is a terrible place to browse >> the web from. > > I agree. Still the long, boring commute to/from work is when i have > actually the time to look up things. Here, in most of the USA, a commute is on four wheels, where it's unlikely but on a bus or train or airplane (or the wait between them), it's common. Thanks for _adding value_ to the equation! It's rare that anyone can do that.
[toc] | [prev] | [next] | [standalone]
| From | 123456789 <12345@12345.com> |
|---|---|
| Date | 2018-10-02 09:45 -0700 |
| Message-ID | <pp07bs$18jj$1@gioia.aioe.org> |
| In reply to | #56174 |
On 10/2/2018 5:32 AM, Arlen H Holder wrote: > HINT: I have location turned off Hint: Google tracks users even with location data turned off. https://economictimes.indiatimes.com/magazines/panache/google-confirms-that-it-tracks-users-even-with-location-data-turned-off/articleshow/65435086.cms > True. [only a fool does banking on the phone.] What is a safer way to bank online than using the banks own Android app? > Here, in most of the USA, a commute is on four wheels, where it's > [phone browsing] unlikely... During the commute rush hour here when the freeway is going zero to 10 MPH (even in the HOV lane) I see lots of phone browsers, most (but not all) are passengers...
[toc] | [prev] | [next] | [standalone]
Page 1 of 5 [1] 2 3 4 5 Next page →
Back to top | Article view | comp.mobile.android
csiph-web