Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.mobile.android > #56151 > unrolled thread

Anti-virus?

Started byAlek <alek.trishan@gmail.com>
First post2018-10-01 13:54 -0400
Last post2018-10-04 13:14 +0100
Articles 20 on this page of 90 — 16 participants

Back to article view | Back to comp.mobile.android


Contents

  Anti-virus? Alek <alek.trishan@gmail.com> - 2018-10-01 13:54 -0400
    Re:Anti-virus? Libor Striz <poutnik4REMOVEnntp@CAPITALSgmail.com> - 2018-10-01 20:05 +0200
      Re: Anti-virus? Alek <alek.trishan@gmail.com> - 2018-10-01 14:15 -0400
        Re: Anti-virus? Calum <com.gmail@nospam.scottishwildcat> - 2018-10-01 19:55 +0100
      Re: Anti-virus? Joerg Lorenz <hugybear@gmx.ch> - 2018-10-01 22:11 +0200
        Re: Anti-virus? Libor Striz <poutnik4REMOVEnntp@CAPITALSgmail.com> - 2018-10-02 02:14 +0200
          Re: Anti-virus? Joerg Lorenz <hugybear@gmx.ch> - 2018-10-02 06:18 +0200
        Re: Anti-virus? Libor Striz <poutnik4REMOVEnntp@CAPITALSgmail.com> - 2018-10-02 02:34 +0200
    Re: Anti-virus? Hergen Lehmann <hlehmann.expires.5-11@snafu.de> - 2018-10-01 20:49 +0200
      Re: Anti-virus? Alek <alek.trishan@gmail.com> - 2018-10-01 16:03 -0400
        Re: Anti-virus? Arlen   H  Holder <arlenh.older@no.spam.net> - 2018-10-02 02:52 +0000
        Re: Anti-virus? Hergen Lehmann <hlehmann.expires.5-11@snafu.de> - 2018-10-02 10:29 +0200
          Re: Anti-virus? "Carlos E. R." <robin_listas@es.invalid> - 2018-10-03 13:30 +0200
            Re: Anti-virus? Hergen Lehmann <hlehmann.expires.5-11@snafu.de> - 2018-10-03 15:09 +0200
              Re: Anti-virus? "Carlos E. R." <robin_listas@es.invalid> - 2018-10-03 15:31 +0200
                Re: Anti-virus? Hergen Lehmann <hlehmann.expires.5-11@snafu.de> - 2018-10-03 16:33 +0200
      Re: Anti-virus? Arlen   H  Holder <arlenh.older@no.spam.net> - 2018-10-02 02:50 +0000
        Re: Anti-virus? Hergen Lehmann <hlehmann.expires.5-11@snafu.de> - 2018-10-02 10:55 +0200
          Re: Anti-virus? Arlen   H  Holder <arlenh.older@no.spam.net> - 2018-10-02 12:32 +0000
            Re: Anti-virus? 123456789 <12345@12345.com> - 2018-10-02 09:45 -0700
              Re: Anti-virus? Frank Slootweg <this@ddress.is.invalid> - 2018-10-02 17:54 +0000
                Re: Anti-virus? 123456789 <12345@12345.com> - 2018-10-02 13:15 -0700
                  Re: Anti-virus? Arlen   H  Holder <arlenh.older@no.spam.net> - 2018-10-03 02:38 +0000
                  Re: Anti-virus? Frank Slootweg <this@ddress.is.invalid> - 2018-10-03 10:49 +0000
                    Re: Anti-virus?  Arlen    Holder <a%rlenh.older@no.spam.net> - 2018-10-03 12:11 +0000
                    Re: Anti-virus? 123456789 <12345@12345.com> - 2018-10-03 08:42 -0700
                      Re: Anti-virus?  Arlen    Holder <a%rlenh.older@no.spam.net> - 2018-10-03 16:16 +0000
                      Re: Anti-virus? Frank Slootweg <this@ddress.is.invalid> - 2018-10-03 17:32 +0000
                        Re: Anti-virus? Java Jive <java@evij.com.invalid> - 2018-10-03 19:02 +0100
                        Re: Anti-virus? Hergen Lehmann <hlehmann.expires.5-11@snafu.de> - 2018-10-03 20:13 +0200
                          Re: Anti-virus? Frank Slootweg <this@ddress.is.invalid> - 2018-10-03 20:09 +0000
                            Re: Anti-virus? Hergen Lehmann <hlehmann.expires.5-11@snafu.de> - 2018-10-03 23:23 +0200
                              Re: Anti-virus?  Arlen    Holder <a%rlenh.older@no.spam.net> - 2018-10-04 13:06 +0000
                              Re: Anti-virus? Frank Slootweg <this@ddress.is.invalid> - 2018-10-04 15:02 +0000
                                Google does *not* track *you*! (was: Anti-virus?) Frank Slootweg <this@ddress.is.invalid> - 2018-10-04 15:44 +0000
                                  Re: Google does *not* track *you*! 123456789 <12345@12345.com> - 2018-10-04 09:10 -0700
                                    Re: Google does *not* track *you*! "Carlos E.R." <robin_listas@es.invalid> - 2018-10-07 22:03 +0200
                                      Re: Google does *not* track *you*! 123456789 <12345@12345.com> - 2018-10-07 14:23 -0700
                                  Re: Google does *not* track *you*! Frank Slootweg <this@ddress.is.invalid> - 2018-10-04 17:07 +0000
                                Re: Anti-virus? 123456789 <12345@12345.com> - 2018-10-04 09:10 -0700
                Re: Anti-virus? Arlen   H  Holder <arlenh.older@no.spam.net> - 2018-10-03 02:36 +0000
              Re: Anti-virus? Arlen   H  Holder <arlenh.older@no.spam.net> - 2018-10-03 02:34 +0000
                Re: Anti-virus? 123456789 <12345@12345.com> - 2018-10-02 20:33 -0700
                  Re: Anti-virus?  Arlen    Holder  <a%rlenh.older@no.spam.net> - 2018-10-03 04:30 +0000
                    Re: Anti-virus? 123456789 <12345@12345.com> - 2018-10-02 22:13 -0700
                      Re: Anti-virus?  Arlen    Holder <a%rlenh.older@no.spam.net> - 2018-10-03 12:52 +0000
                        Re: Anti-virus? "Carlos E. R." <robin_listas@es.invalid> - 2018-10-03 15:09 +0200
                          Re: Anti-virus?  Arlen    Holder <a%rlenh.older@no.spam.net> - 2018-10-03 15:40 +0000
                        Re: Anti-virus? 123456789 <12345@12345.com> - 2018-10-03 08:42 -0700
                          Re: Anti-virus?  Arlen    Holder <a%rlenh.older@no.spam.net> - 2018-10-03 16:16 +0000
                            Re: Anti-virus? 123456789 <12345@12345.com> - 2018-10-03 15:52 -0700
                              Re: Anti-virus?  Arlen    Holder <a%rlenh.older@no.spam.net> - 2018-10-03 23:31 +0000
                                Re: Anti-virus? 123456789 <123456@123456.com> - 2018-10-03 21:21 -0700
                                  Re: Anti-virus?  Arlen    Holder <a%rlenh.older@no.spam.net> - 2018-10-04 13:07 +0000
                                    Re: Anti-virus? 123456789 <12345@12345.com> - 2018-10-04 09:10 -0700
                Re: Anti-virus? "Carlos E. R." <robin_listas@es.invalid> - 2018-10-03 13:37 +0200
                  Re: Anti-virus? nospam <nospam@nospam.invalid> - 2018-10-03 08:44 -0400
                  Re: Anti-virus?  Arlen    Holder <a%rlenh.older@no.spam.net> - 2018-10-03 12:52 +0000
                    Re: Anti-virus? "Carlos E. R." <robin_listas@es.invalid> - 2018-10-03 15:06 +0200
                      Re: Anti-virus?  Arlen    Holder <a%rlenh.older@no.spam.net> - 2018-10-03 15:40 +0000
                        Re: Anti-virus? "Carlos E.R." <robin_listas@es.invalid> - 2018-10-07 20:41 +0200
                          Re: Anti-virus?  Arlen    Holder <a%rlenh.older@no.spam.net> - 2018-10-08 15:00 +0000
            Re: Anti-virus? Hergen Lehmann <hlehmann.expires.5-11@snafu.de> - 2018-10-02 20:42 +0200
              Re: Anti-virus? "Carlos E. R." <robin_listas@es.invalid> - 2018-10-03 13:44 +0200
                Re: Anti-virus?  Arlen    Holder <a%rlenh.older@no.spam.net> - 2018-10-03 12:52 +0000
                  Re: Anti-virus? "Carlos E. R." <robin_listas@es.invalid> - 2018-10-03 15:14 +0200
                    Re: Anti-virus? Hergen Lehmann <hlehmann.expires.5-11@snafu.de> - 2018-10-03 15:31 +0200
                      Re: Anti-virus? "Carlos E. R." <robin_listas@es.invalid> - 2018-10-03 17:47 +0200
                        Re: Anti-virus?  Arlen    Holder <a%rlenh.older@no.spam.net> - 2018-10-03 16:16 +0000
                        Re: Anti-virus? Hergen Lehmann <hlehmann.expires.5-11@snafu.de> - 2018-10-03 18:20 +0200
                          Re: Anti-virus?  Arlen    Holder <a%rlenh.older@no.spam.net> - 2018-10-03 17:18 +0000
                    Re: Anti-virus?  Arlen    Holder <a%rlenh.older@no.spam.net> - 2018-10-03 15:39 +0000
                      Re: Anti-virus? "Carlos E. R." <robin_listas@es.invalid> - 2018-10-03 17:49 +0200
                        Re: Anti-virus?  Arlen    Holder <a%rlenh.older@no.spam.net> - 2018-10-03 16:16 +0000
                Re: Anti-virus? Hergen Lehmann <hlehmann.expires.5-11@snafu.de> - 2018-10-03 15:28 +0200
                  Re: Anti-virus?  Arlen    Holder <a%rlenh.older@no.spam.net> - 2018-10-03 15:39 +0000
                  Re: Anti-virus? "Carlos E.R." <robin_listas@es.invalid> - 2018-10-07 20:48 +0200
                    Re: Anti-virus? Hergen Lehmann <hlehmann.expires.5-11@snafu.de> - 2018-10-07 21:40 +0200
        Re: Anti-virus? Alek <alek.trishan@gmail.com> - 2018-10-02 19:33 -0400
          Re: Anti-virus? Arlen   H  Holder <arlenh.older@no.spam.net> - 2018-10-03 02:40 +0000
            Re: Anti-virus? Alek <alek.trishan@gmail.com> - 2018-10-03 13:55 -0400
              Re: Anti-virus? nospam <nospam@nospam.invalid> - 2018-10-03 14:08 -0400
                Re: Anti-virus?  Arlen    Holder <a%rlenh.older@no.spam.net> - 2018-10-04 13:07 +0000
                  Re: Anti-virus? nospam <nospam@nospam.invalid> - 2018-10-04 10:03 -0400
                    Re: Anti-virus?  Arlen    Holder <a%rlenh.older@no.spam.net> - 2018-10-06 02:56 +0000
                  Re: Anti-virus? "Carlos E.R." <robin_listas@es.invalid> - 2018-10-07 20:50 +0200
                    Re: Anti-virus?  Arlen    Holder <a%rlenh.older@no.spam.net> - 2018-10-08 15:00 +0000
              Re: Anti-virus? "Carlos E.R." <robin_listas@es.invalid> - 2018-10-07 20:54 +0200
    Re: Anti-virus? Arlen   H  Holder <arlenh.older@no.spam.net> - 2018-10-02 02:47 +0000
    Re: Anti-virus? Andy Burns <usenet@andyburns.uk> - 2018-10-04 13:14 +0100

Page 1 of 5  [1] 2 3 4 5  Next page →


#56151 — Anti-virus?

FromAlek <alek.trishan@gmail.com>
Date2018-10-01 13:54 -0400
SubjectAnti-virus?
Message-ID<potn0c$8hq$1@dont-email.me>
Is there really any reason to use an AV app on an Android device?

If so, what is the reason?

If not, why not?

Thanks.

[toc] | [next] | [standalone]


#56154

FromLibor Striz <poutnik4REMOVEnntp@CAPITALSgmail.com>
Date2018-10-01 20:05 +0200
Message-ID<potnl8$c3b$1@dont-email.me>
In reply to#56151
Alek <alek.trishan@gmail.com> Wrote in message:
> Is there really any reason to use an AV app on an Android device?
> 
> If so, what is the reason?
> 
> If not, why not?
> 
> Thanks.
> 
Is there any reason to believe there  are no malicious
 applications for Android ? They may not  spread themselves
 automatically, but some of them were installed by millions of
 users.

-- 
Libor Striz aka Poutnik ( a pilgrim/wanderer/wayfarer)

"Humour is the only effective weapon against stupidity."
Miloš Forman


----Android NewsGroup Reader----
http://usenet.sinaapp.com/

[toc] | [prev] | [next] | [standalone]


#56155

FromAlek <alek.trishan@gmail.com>
Date2018-10-01 14:15 -0400
Message-ID<poto8p$gc8$1@dont-email.me>
In reply to#56154
Can you name three?

Libor Striz wrote on 10/1/2018 2:05 PM:
> Alek <alek.trishan@gmail.com> Wrote in message:
>> Is there really any reason to use an AV app on an Android device?
>> 
>> If so, what is the reason?
>> 
>> If not, why not?
>> 
>> Thanks.
>> 
> Is there any reason to believe there  are no malicious
>  applications for Android ? They may not  spread themselves
>  automatically, but some of them were installed by millions of
>  users.
> 

[toc] | [prev] | [next] | [standalone]


#56156

FromCalum <com.gmail@nospam.scottishwildcat>
Date2018-10-01 19:55 +0100
Message-ID<potqjn$1b9p$1@gioia.aioe.org>
In reply to#56155
On 01/10/2018 19:15, Alek wrote:
> Can you name three?

HenBox, Guerilla, ZooPark. And they were just from the first half of 
this year.

> 
> Libor Striz wrote on 10/1/2018 2:05 PM:
>> Alek <alek.trishan@gmail.com> Wrote in message:
>>> Is there really any reason to use an AV app on an Android device?
>>>
>>> If so, what is the reason?
>>>
>>> If not, why not?
>>>
>>> Thanks.
>>>
>> Is there any reason to believe there  are no malicious
>>   applications for Android ? They may not  spread themselves
>>   automatically, but some of them were installed by millions of
>>   users.
>>

[toc] | [prev] | [next] | [standalone]


#56159

FromJoerg Lorenz <hugybear@gmx.ch>
Date2018-10-01 22:11 +0200
Message-ID<potv1u$ll$1@dont-email.me>
In reply to#56154
Am 01.10.18 um 20:05 schrieb Libor Striz:
> Alek <alek.trishan@gmail.com> Wrote in message:
>> Is there really any reason to use an AV app on an Android device?
>>
>> If so, what is the reason?
>>
>> If not, why not?
>>
>> Thanks.
>>
> Is there any reason to believe there  are no malicious
>   applications for Android ? They may not  spread themselves
>   automatically, but some of them were installed by millions of
>   users.
> 
This is not an answer at all!
There is no reason to believe snake oil would have prevented that 
installation.

AV-software increases the vulnerable code base. There is only one 
effective protection: Brain 1.0. And brain 1.0 is clearly preventing the 
installation of "anti-virus-malware".

BTW: This av-crap is typical windows-thinking.

[toc] | [prev] | [next] | [standalone]


#56163

FromLibor Striz <poutnik4REMOVEnntp@CAPITALSgmail.com>
Date2018-10-02 02:14 +0200
Message-ID<poud8e$kp2$1@dont-email.me>
In reply to#56159
Joerg Lorenz <hugybear@gmx.ch> Wrote in message:
> Am 01.10.18 um 20:05 schrieb Libor Striz:
>> Alek <alek.trishan@gmail.com> Wrote in message:
>>> Is there really any reason to use an AV app on an Android device?
>>>
>>> If so, what is the reason?
>>>
>>> If not, why not?
>>>
>>> Thanks.
>>>
>> Is there any reason to believe there  are no malicious
>>   applications for Android ? They may not  spread themselves
>>   automatically, but some of them were installed by millions of
>>   users.
>> 
> This is not an answer at all!
> There is no reason to believe snake oil would have prevented that 
> installation.
> 
> AV-software increases the vulnerable code base. There is only one 
> effective protection: Brain 1.0. And brain 1.0 is clearly preventing the 
> installation of "anti-virus-malware".
> 
> BTW: This av-crap is typical windows-thinking.
> 

Then use the Brain 1.0 little more.
And no, it is not an effective protection.

-- 
Libor Striz aka Poutnik ( a pilgrim/wanderer/wayfarer)

"Humour is the only effective weapon against stupidity."
Miloš Forman


----Android NewsGroup Reader----
http://usenet.sinaapp.com/

[toc] | [prev] | [next] | [standalone]


#56168

FromJoerg Lorenz <hugybear@gmx.ch>
Date2018-10-02 06:18 +0200
Message-ID<pourj5$dh9$1@dont-email.me>
In reply to#56163
Am 02.10.18 um 02:14 schrieb Libor Striz:
> Joerg Lorenz <hugybear@gmx.ch> Wrote in message:
>> AV-software increases the vulnerable code base. There is only one
>> effective protection: Brain 1.0. And brain 1.0 is clearly preventing the
>> installation of "anti-virus-malware".
>>
>> BTW: This av-crap is typical windows-thinking.
>>
> 
> Then use the Brain 1.0 little more.
> And no, it is not an effective protection.

Certainly better than any av-software. By concept this snake oil can 
only find malware it knows. By definition it is always lagging. Brain 
1.0 is preventing even not yet known threats.

[toc] | [prev] | [next] | [standalone]


#56164

FromLibor Striz <poutnik4REMOVEnntp@CAPITALSgmail.com>
Date2018-10-02 02:34 +0200
Message-ID<poueen$pos$1@dont-email.me>
In reply to#56159
Joerg Lorenz <hugybear@gmx.ch> Wrote in message:
> Am 01.10.18 um 20:05 schrieb Libor Striz:
>> Alek <alek.trishan@gmail.com> Wrote in message:
>>> Is there really any reason to use an AV app on an Android device?
>>>
>>> If so, what is the reason?
>>>
>>> If not, why not?
>>>
>>> Thanks.
>>>
>> Is there any reason to believe there  are no malicious
>>   applications for Android ? They may not  spread themselves
>>   automatically, but some of them were installed by millions of
>>   users.
>> 
> This is not an answer at all!
> There is no reason to believe snake oil would have prevented that 
> installation.

The true snake oil is to pave the way for malware to have pleasant
 journey.

I have not said it will prevent the installation. OTOH, the
 malware will not prevent its detection.
> 
> AV-software increases the vulnerable code base. There is only one 
> effective protection: Brain 1.0. And brain 1.0 is clearly preventing the 
> installation of "anti-virus-malware".

Majority of Android malware does not care about vulnerable code.
Users install it themselves.
> 
> BTW: This av-crap is typical windows-thinking.

The weakest part of Linux
is a part  of its user base.

The above is their typical rhetorics.

In contrary to Linux, there is plenty of Android malware in the wild,
and no brain of an ordinary user
can distinguish seed and weed.
Most of them come from official repositories.
 

-- 
Libor Striz aka Poutnik ( a pilgrim/wanderer/wayfarer)

"Humour is the only effective weapon against stupidity."
Miloš Forman


----Android NewsGroup Reader----
http://usenet.sinaapp.com/

[toc] | [prev] | [next] | [standalone]


#56157

FromHergen Lehmann <hlehmann.expires.5-11@snafu.de>
Date2018-10-01 20:49 +0200
Message-ID<dq6a8f-nvf.ln1@hergen.dyndns.org>
In reply to#56151
Am 01.10.2018 um 19:54 schrieb Alek:

> Is there really any reason to use an AV app on an Android device?
> 
> If so, what is the reason?

- There is certainly malware around.

- Most Android device manufacturers certainly have a problem rolling out 
security patches in a timely manner and for their whole product line, 
which is a real feast for each malware programmer.

> If not, why not?

- AV software (on an Android device as well an on a PC) is snakeoil. No 
app is capable of detecting all current malware and most apps do 
introduce additional risks not present in the bare OS.

- Android devices are designed to steal personal data. A whole, major 
Category of malware is basically courted by the operating system 
manufacturer itself and no AV software will be able to change that.

[toc] | [prev] | [next] | [standalone]


#56158

FromAlek <alek.trishan@gmail.com>
Date2018-10-01 16:03 -0400
Message-ID<potui9$t02$1@dont-email.me>
In reply to#56157
Hergen Lehmann wrote on 10/1/2018 2:49 PM:
> Am 01.10.2018 um 19:54 schrieb Alek:
> 
>> Is there really any reason to use an AV app on an Android device?
>> 
>> If so, what is the reason?
> 
> - There is certainly malware around.

My understanding is that the biggest threat comes from side-loaded apps.

> - Most Android device manufacturers certainly have a problem rolling out 
> security patches in a timely manner and for their whole product line, 
> which is a real feast for each malware programmer.

How does an Android device get infected?

> 
>> If not, why not?
> 
> - AV software (on an Android device as well an on a PC) is snakeoil. No 
> app is capable of detecting all current malware and most apps do 
> introduce additional risks not present in the bare OS.

Defend that, will you?

> - Android devices are designed to steal personal data. 

Really? What data? Who gets it?

>
A whole, major
> Category of malware is basically courted by the operating system 
> manufacturer itself and no AV software will be able to change that.

We're talking about different things. There are so many programs that
collect data (including Windows) that your statement makes no sense to me.

So in the last analysis, should an Android user have an AV app running
or not?

[toc] | [prev] | [next] | [standalone]


#56167

FromArlen H Holder <arlenh.older@no.spam.net>
Date2018-10-02 02:52 +0000
Message-ID<poumgg$14h$1@news.mixmin.net>
In reply to#56158
On Mon, 1 Oct 2018 16:03:16 -0400, Alek wrote:

> My understanding is that the biggest threat comes from side-loaded apps.

Are you intimating that the FOSS apps on, oh, say, F-Droid, are the
"biggest threat"?

Really?
How do you justify that statement?

Put another way, why would a FOSS app on F-Droid be any less or more secure
than a proprietary app on Google Play?

[toc] | [prev] | [next] | [standalone]


#56171

FromHergen Lehmann <hlehmann.expires.5-11@snafu.de>
Date2018-10-02 10:29 +0200
Message-ID<nsmb8f-bfa.ln1@hergen.dyndns.org>
In reply to#56158
Am 01.10.2018 um 22:03 schrieb Alek:

>> - There is certainly malware around.
> 
> My understanding is that the biggest threat comes from side-loaded apps.

Unlikely. Side-loading is disabled by default on android and most users 
do not even know how to enable it. Also, popular side-loading platforms 
like F-Droid enjoy a rather high level of trust, much higher than the 
official app store.

> How does an Android device get infected?

In most cases by installing that new, popular game which contains some 
kind of malware and hasn't been pulled from the store yet. Google isn't 
exactly fast in doing this and is rather indifferent about spyware.

Infected media files and web sites also are a common vector of attack. 
Android used to have many, many security holes in it's multimedia 
sub-system; almost every security update contains some fixed in there.

Some devices (especially no-name china brands) do come with malware 
already pre-installed at the factory.

In business environments, email attachments also pose a major risk, 
especially if combined with social engineering.

>> - AV software (on an Android device as well an on a PC) is snakeoil. No
>> app is capable of detecting all current malware and most apps do
>> introduce additional risks not present in the bare OS.
> 
> Defend that, will you?

There were many instances in the past, where AV software actually 
introduced an attack vector. Use google.

Also, AV software claiming to secure internet connections usually does 
break the encryption (otherwise it wouldn't be able to look into them), 
making it easy for other bad guys to jump on the bandwagon.

>> - Android devices are designed to steal personal data.
> 
> Really? What data? Who gets it?

Advertising networks, which forward the data (or personal profiles 
created from the data) to their many, many, unnamed partners.

If you didn't notice it yet: Google is an advertising company, and the 
whole reason they provide Android for free is to feed their database 
with tracking and behavioral data. Same goes for facebook&Co.

>> A whole, major
>> Category of malware is basically courted by the operating system
>> manufacturer itself and no AV software will be able to change that.
> 
> We're talking about different things. There are so many programs that
> collect data (including Windows) that your statement makes no sense to me.

That's exactly why this is an argument against using AV software: you 
can't prevent that kind of malware on an android device, even with the 
best AV solution installed.

> So in the last analysis, should an Android user have an AV app running
> or not?

Do other (not data-stealing) types of malware pose a risk for you? Are 
you the guy who clicks on every link thrown at you without thinking 
first? Do you consider yourself to be too inexperienced to recognize 
sudden, strange behavior of your device?

If yes, AV software may help you to feel better. Just don't expect it to 
protect you. ^_-

[toc] | [prev] | [next] | [standalone]


#56200

From"Carlos E. R." <robin_listas@es.invalid>
Date2018-10-03 13:30 +0200
Message-ID<g1jniaFknuvU1@mid.individual.net>
In reply to#56171
On 02/10/2018 10.29, Hergen Lehmann wrote:
> Am 01.10.2018 um 22:03 schrieb Alek:
> 
>>> - There is certainly malware around.
>>
>> My understanding is that the biggest threat comes from side-loaded apps.
> 
> Unlikely. Side-loading is disabled by default on android and most users
> do not even know how to enable it. Also, popular side-loading platforms
> like F-Droid enjoy a rather high level of trust, much higher than the
> official app store.
> 
>> How does an Android device get infected?
> 
> In most cases by installing that new, popular game which contains some
> kind of malware and hasn't been pulled from the store yet. Google isn't
> exactly fast in doing this and is rather indifferent about spyware.

Then they would be Trojans, not virii.


> Infected media files and web sites also are a common vector of attack.

I don't think I have seen any :-?

> Android used to have many, many security holes in it's multimedia
> sub-system; almost every security update contains some fixed in there.
> 
> Some devices (especially no-name china brands) do come with malware
> already pre-installed at the factory.

Not virii.


> In business environments, email attachments also pose a major risk,
> especially if combined with social engineering.

Not virii

:-)


>>> - Android devices are designed to steal personal data.
>>
>> Really? What data? Who gets it?
> 
> Advertising networks, which forward the data (or personal profiles
> created from the data) to their many, many, unnamed partners.
> 
> If you didn't notice it yet: Google is an advertising company, and the
> whole reason they provide Android for free is to feed their database
> with tracking and behavioral data. Same goes for facebook&Co.

Right.


-- 
Cheers,
       Carlos E.R.

[toc] | [prev] | [next] | [standalone]


#56212

FromHergen Lehmann <hlehmann.expires.5-11@snafu.de>
Date2018-10-03 15:09 +0200
Message-ID<ukre8f-m02.ln1@hergen.dyndns.org>
In reply to#56200
Am 03.10.2018 um 13:30 schrieb Carlos E. R.:

>>> How does an Android device get infected?
>>
>> In most cases by installing that new, popular game which contains some
>> kind of malware and hasn't been pulled from the store yet. Google isn't
>> exactly fast in doing this and is rather indifferent about spyware.
> 
> Then they would be Trojans, not virii.

Not sure about that. Malware distributed through the store does rely 
heavily on word-of-mouth propaganda to spread quickly before being 
pulled. Quite likely some will try to spread actively, either by forging 
recommendations in the store, or by sending messages to contacts found 
in the contact list.

Anyway, most AV software claims to protect against all kind of malware, 
not only virii, so it's rather pointless to try some demarcation here.

>> Infected media files and web sites also are a common vector of attack.
> 
> I don't think I have seen any :-?

Well, i'm not visiting media piracy sites too much either. ;-)
But there has been a lot of fuzz about this attack vector, especially 
when stagefright was discovered.

>> Some devices (especially no-name china brands) do come with malware
>> already pre-installed at the factory.
> 
> Not virii.

Not sure about that. As this is mainly a problem with malware found on 
chinese phones and targeted at the chinese market, it is almost 
impossible to find any details on purpose and distribution channels.
But it would be strange, if not at least some of these will try to 
actively spread, too.

>> In business environments, email attachments also pose a major risk,
>> especially if combined with social engineering.
> 
> Not virii

Most of these *will* be virii.

After the attacker has successfully penetrated the security of a company 
or governmental institution at some point (most likely the smartphone or 
desktop PC of some simple-minded non-technical employee), his success 
heavily depends on spreading out to more important computers in the 
local area network as fast as possible.

[toc] | [prev] | [next] | [standalone]


#56214

From"Carlos E. R." <robin_listas@es.invalid>
Date2018-10-03 15:31 +0200
Message-ID<g1julsFm4mjU1@mid.individual.net>
In reply to#56212
On 03/10/2018 15.09, Hergen Lehmann wrote:
> Am 03.10.2018 um 13:30 schrieb Carlos E. R.:
> 
>>>> How does an Android device get infected?
>>>
>>> In most cases by installing that new, popular game which contains some
>>> kind of malware and hasn't been pulled from the store yet. Google isn't
>>> exactly fast in doing this and is rather indifferent about spyware.
>>
>> Then they would be Trojans, not virii.
> 
> Not sure about that. Malware distributed through the store does rely
> heavily on word-of-mouth propaganda to spread quickly before being
> pulled. Quite likely some will try to spread actively, either by forging
> recommendations in the store, or by sending messages to contacts found
> in the contact list.
> 
> Anyway, most AV software claims to protect against all kind of malware,
> not only virii, so it's rather pointless to try some demarcation here.

Well, I, as others, wonder about how actual virus can propagate on
Android devices.

On the other hand, I doubt how much an Antivirus can do against
"trojans", ie, software distributed through official sources that do bad
things. Can they be really faster than google, with the huge amount of
apps out there?

> 
>>> Infected media files and web sites also are a common vector of attack.
>>
>> I don't think I have seen any :-?
> 
> Well, i'm not visiting media piracy sites too much either. ;-)
> But there has been a lot of fuzz about this attack vector, especially
> when stagefright was discovered.

Ah... those media files.
I would not use Android for those - Nor Windows. :-p

> 
>>> Some devices (especially no-name china brands) do come with malware
>>> already pre-installed at the factory.
>>
>> Not virii.
> 
> Not sure about that. As this is mainly a problem with malware found on
> chinese phones and targeted at the chinese market, it is almost
> impossible to find any details on purpose and distribution channels.
> But it would be strange, if not at least some of these will try to
> actively spread, too.
> 
>>> In business environments, email attachments also pose a major risk,
>>> especially if combined with social engineering.
>>
>> Not virii
> 
> Most of these *will* be virii.

How can they spread to another phone? Sending another email? Because
that looks rather like a social engineering trojan. :-p


> After the attacker has successfully penetrated the security of a company
> or governmental institution at some point (most likely the smartphone or
> desktop PC of some simple-minded non-technical employee), his success
> heavily depends on spreading out to more important computers in the
> local area network as fast as possible.

Yes, computers, yes. But I have not seen phones using samba or opening
ports :-?

-- 
Cheers,
       Carlos E.R.

[toc] | [prev] | [next] | [standalone]


#56217

FromHergen Lehmann <hlehmann.expires.5-11@snafu.de>
Date2018-10-03 16:33 +0200
Message-ID<ej0f8f-gb4.ln1@hergen.dyndns.org>
In reply to#56214
Am 03.10.2018 um 15:31 schrieb Carlos E. R.:

>> Anyway, most AV software claims to protect against all kind of malware,
>> not only virii, so it's rather pointless to try some demarcation here.
> 
> Well, I, as others, wonder about how actual virus can propagate on
> Android devices.

Spyware in most cases through massive advertising and deliberate mis-use 
of the store algorithms. The store favors apps, which have been 
downloaded a lot in the past hours, which in turn triggers even more 
downloads. Social engineering (e.g. forged message from a friend saying 
"you must try out this new game i found") may also be used.

"Real" viruses likely through web sites or message attachments and the 
many unpatched exploits found in the outdated android versions present 
on the vast majority of devices.

> On the other hand, I doubt how much an Antivirus can do against
> "trojans", ie, software distributed through official sources that do bad
> things. Can they be really faster than google, with the huge amount of
> apps out there?

As already said, google isn't exactly fast in pulling apps and they tend 
to turn a blind eye towards spyware, as long as they benefit from it by 
selling ads.

But i agree, it is doubtful whether a third-party AV solution will be 
much of an improvement here.

>> After the attacker has successfully penetrated the security of a company
>> or governmental institution at some point (most likely the smartphone or
>> desktop PC of some simple-minded non-technical employee), his success
>> heavily depends on spreading out to more important computers in the
>> local area network as fast as possible.
> 
> Yes, computers, yes. But I have not seen phones using samba or opening
> ports :-?

I guess, a phone (or some other appliance) will likely only be the door 
opener to the LAN in this scenario, with the actual damage being 
inflicted to the PCs and servers. But i don't know statistics about 
that. Companies don't like to talk about being infected.

[toc] | [prev] | [next] | [standalone]


#56166

FromArlen H Holder <arlenh.older@no.spam.net>
Date2018-10-02 02:50 +0000
Message-ID<poumdb$11k$1@news.mixmin.net>
In reply to#56157
On Mon, 1 Oct 2018 20:49:17 +0200, Hergen Lehmann wrote:

>  Android devices are designed to steal personal data. A whole, major 
> Category of malware is basically courted by the operating system 
> manufacturer itself and no AV software will be able to change that.

There is no doubt "personal data" on Android, that may not be on desktop
systems, such as your "contact list", which is an integral part of a phone
application suite.

But, other than your contact list (i.e., other than the people you
communicate with and those conversations), what other "personal data" is on
a phone, that isn't already on all the other platforms?

I realize you'll say "banking", but only a fool does banking on the phone.
You'll say web browsing, but again, a phone is a terrible place to browse
the web from.

Hence, other than contacts & associated communications, what "personal
data" is on a phone, that isn't on any other device?

HINT: This question is Android/iOS agnostic.

[toc] | [prev] | [next] | [standalone]


#56173

FromHergen Lehmann <hlehmann.expires.5-11@snafu.de>
Date2018-10-02 10:55 +0200
Message-ID<4cob8f-dta.ln1@hergen.dyndns.org>
In reply to#56166
Am 02.10.2018 um 04:50 schrieb Arlen H Holder:

> But, other than your contact list (i.e., other than the people you
> communicate with and those conversations), what other "personal data" is on
> a phone, that isn't already on all the other platforms?

Location data. How is your daily routine? Where were you going when 
diverting from your routine that day? Which stores do you usually visit? 
Which demonstrations did you participate in and what does this give away 
about your political views? ...

Communication details. Which persons from your contact list do you 
actually communicate with? Is there a correlation relation between you 
visiting a certain location and previous communication? ...

Photos. Were did you take them, what are they showing? What personal 
interests can be derived from them? Which people did you meet?
All major social networks do feature some kind of automatic image 
analysis with facial detection. And they did not spent millions into 
developing this for the users - they did spent the money to provide even 
better data to their paying customers, which include advertising 
partners as well as governmental institutions.

Aside from these phone-specific things, the smartphone is just the 
platform most people use these days for most of their personal data 
processing needs. It contains more and more attractive data then that 
old rusty PC sitting around in the corner most of the time.

> I realize you'll say "banking", but only a fool does banking on the phone.

I agree. Still many people are doing it and many banking institutes did 
even develop apps and do advertise them.

> You'll say web browsing, but again, a phone is a terrible place to browse
> the web from.

I agree. Still the long, boring commute to/from work is when i have 
actually the time to look up things.

[toc] | [prev] | [next] | [standalone]


#56174

FromArlen H Holder <arlenh.older@no.spam.net>
Date2018-10-02 12:32 +0000
Message-ID<povoh7$leb$1@news.mixmin.net>
In reply to#56173
On Tue, 2 Oct 2018 10:55:00 +0200, Hergen Lehmann wrote:

> Location data. 

Ah. Very good point. I missed that, but there's a reason I missed it.
HINT: I have location turned off, plus reporting of BSSIDs turned off.

But you're right. It's not a threat to me, but for most people it is.
HINT: My SSIDs are set to *_nomap

> How is your daily routine? Where were you going when 
> diverting from your routine that day? Which stores do you usually visit? 
> Which demonstrations did you participate in and what does this give away 
> about your political views? ...

Yes. Agreed. Most people have their phone set up wrong (the default).
So the two biggest threats we've identified on the phone are:
a. Contact communication, and, 
b. Location information.

> Communication details. Which persons from your contact list do you 
> actually communicate with? Is there a correlation relation between you 
> visiting a certain location and previous communication? ...

Yes. See above.

> Photos. Were did you take them, what are they showing? What personal 
> interests can be derived from them? Which people did you meet?

Another good one (my photos don't save GPS, but I do take photos).
So that's three things:

1. Communication data.
2. Location data.
3. Photographic data.

> All major social networks do feature some kind of automatic image 
> analysis with facial detection. And they did not spent millions into 
> developing this for the users - they did spent the money to provide even 
> better data to their paying customers, which include advertising 
> partners as well as governmental institutions.

In addition to facial recognition algorithms...
We published a report that showed a _single_ photo can fingerprint a phone.

> Aside from these phone-specific things, the smartphone is just the 
> platform most people use these days for most of their personal data 
> processing needs. It contains more and more attractive data then that 
> old rusty PC sitting around in the corner most of the time.

Agreed.
Except taxes! :)

>> I realize you'll say "banking", but only a fool does banking on the phone.
> 
> I agree. Still many people are doing it and many banking institutes did 
> even develop apps and do advertise them.

True.
> 
>> You'll say web browsing, but again, a phone is a terrible place to browse
>> the web from.
> 
> I agree. Still the long, boring commute to/from work is when i have 
> actually the time to look up things.

Here, in most of the USA, a commute is on four wheels, where it's unlikely
but on a bus or train or airplane (or the wait between them), it's common.

Thanks for _adding value_ to the equation!
It's rare that anyone can do that.

[toc] | [prev] | [next] | [standalone]


#56177

From123456789 <12345@12345.com>
Date2018-10-02 09:45 -0700
Message-ID<pp07bs$18jj$1@gioia.aioe.org>
In reply to#56174
On 10/2/2018 5:32 AM, Arlen H Holder wrote:

> HINT: I have location turned off

Hint: Google tracks users even with location data turned off.

https://economictimes.indiatimes.com/magazines/panache/google-confirms-that-it-tracks-users-even-with-location-data-turned-off/articleshow/65435086.cms

> True. [only a fool does banking on the phone.]

What is a safer way to bank online than using the banks own Android app?

> Here, in most of the USA, a commute is on four wheels, where it's
> [phone browsing] unlikely...

During the commute rush hour here when the freeway is going zero to 10
MPH (even in the HOV lane) I see lots of phone browsers, most (but not
all) are passengers...

[toc] | [prev] | [next] | [standalone]


Page 1 of 5  [1] 2 3 4 5  Next page →

Back to top | Article view | comp.mobile.android


csiph-web