huge security vulnerability, still going to buy?General


Last Updated:

  1. redraider1

    redraider1 Banned This Topic's Starter

    Joined:
    Mar 15, 2011
    Messages:
    1,532
    Likes Received:
    195

    Advertisement
  2. trophynuts

    trophynuts Well-Known Member

    Joined:
    Jul 6, 2010
    Messages:
    5,630
    Likes Received:
    1,792
    doesn't bother me. my info is probably already out in the wild anyways.
     
  3. redraider1

    redraider1 Banned This Topic's Starter

    Joined:
    Mar 15, 2011
    Messages:
    1,532
    Likes Received:
    195
    Yeah but not everything that this leaks like your messages and what not. I just am surprised it has only come up now and will be interesting to see what htc does and how long it takes them to fix this.
     
  4. ASC

    ASC I'm Shy VIP Member

    Joined:
    Mar 27, 2010
    Messages:
    458
    Likes Received:
    316
    Root and remove /system/app/HtcLoggers.apk Problem solved?
     
    Crashumbc likes this.
  5. redraider1

    redraider1 Banned This Topic's Starter

    Joined:
    Mar 15, 2011
    Messages:
    1,532
    Likes Received:
    195
    That is the thing though you shouldn't have to root the phone to prevent this security risk. I mean yes you can root but not everyone wants to root their phone.
     
  6. ASC

    ASC I'm Shy VIP Member

    Joined:
    Mar 27, 2010
    Messages:
    458
    Likes Received:
    316
    Agreed. But until HTC Get's their heads out of their butt's, there is a "fix" for users who do want to go that route.
     
  7. Telexen

    Telexen Well-Known Member

    Joined:
    Nov 1, 2009
    Messages:
    234
    Likes Received:
    13
    This really isn't a gigantic deal everyone's making it out to be. If you're the kind of person who doesn't pay attention to permissions of that apps you're installing you've already opened yourself up to the risk. If you are - you're probably the kind of person who roots your phone anyway and can fix it.
     
  8. jikhead

    jikhead Well-Known Member

    Joined:
    Apr 8, 2010
    Messages:
    777
    Likes Received:
    180
    I'm not doing anything that I should be worried about getting stolen (data) or whatnot.

    I'm pretty sure nearly ALL phones are doing something similar. It's big business and $$ when it comes to collecting information on users...look at the iPhone thing that was found to track people's movement. Every business wants to know how to better market their products to you better in order to sell you something.
     
  9. BabyBlues

    BabyBlues Trouble Just Finds Me! VIP Member

    Joined:
    Jun 3, 2010
    Messages:
    13,125
    Likes Received:
    9,766
    Exactly. There was something similar found in one of the other phone brands recently as well (not apple). You get the warnings that apps are asking for permissions and while most of the time it's harmless, there is always that chance that it's not.
     
  10. Puppa

    Puppa Well-Known Member

    Joined:
    Apr 25, 2010
    Messages:
    318
    Likes Received:
    92
    This security flaw doesn't even exist for non-root users. Just tried it on my thunderbolt...app CANNOT connect to the logger (permission denied).

    For root users, you're running at your own risk. Running all phone software with open root permission exposes you to all kinds of crap. If you're worried about this one, simply remove the app. If that's too tough for you, don't root.

    The site that posted this "news" is completely irresponsible, pajama-boy garbage. Listing the "Vigor" (even with a weasel-like question mark, which nobody pays attention to), when "confirmed" models don't even have the vulnerability.
     
  11. rrhartjr

    rrhartjr Well-Known Member

    Joined:
    Apr 21, 2011
    Messages:
    144
    Likes Received:
    45
    Reading through the comments on androidpolice show at least half of the users trying the proof of concept fail to replicate the problem. Very few who actually try it are confirming the issue.
     
    compchick813 likes this.
  12. NightAngel79

    NightAngel79 Bounty Hunter Administrator Moderator

    Joined:
    May 11, 2010
    Messages:
    22,102
    Likes Received:
    7,415
    Yea, i aint buying this as a credible threat....
     
    lawnboy likes this.
  13. hovercraftdriver

    hovercraftdriver Member

    Joined:
    Apr 7, 2010
    Messages:
    7
    Likes Received:
    1
  14. jamor

    jamor Well-Known Member

    Joined:
    Apr 13, 2010
    Messages:
    3,688
    Likes Received:
    761
    Damn this is bad news
     
  15. blackepoxy

    blackepoxy Well-Known Member

    Joined:
    Jan 14, 2011
    Messages:
    1,086
    Likes Received:
    247
    Is hTC Droid incredible 2 on the list?
    I just looked where it said the logger file was stored with es on my non rooted dinc2 running 2.3.4, I couldn't find it.
    I guess it said all Android phones running hTC sense...
     
  16. blkbeltkid17

    blkbeltkid17 Well-Known Member Contributor

    Joined:
    Nov 16, 2010
    Messages:
    4,383
    Likes Received:
    690
    I know i am still gonna buy HTC phones no matter what i have seen the hell my parrents have gone trough with samsung and moto phones
    and i am running a inc2 rooted couldnt find the .apk in my rooted rom and stock backup
     
  17. jbh00jh

    jbh00jh Well-Known Member

    Joined:
    Apr 30, 2010
    Messages:
    392
    Likes Received:
    45
  18. hovercraftdriver25

    hovercraftdriver25 Well-Known Member

    Joined:
    Apr 8, 2010
    Messages:
    252
    Likes Received:
    76
    Some folks aren't that tech savvy...regardless, why should the consumer have to worry about it in the first place?

    BTW, where's that Vigor announcement that was supposed to happen yesterday that you posted about on XDA?
     
  19. BabyBlues

    BabyBlues Trouble Just Finds Me! VIP Member

    Joined:
    Jun 3, 2010
    Messages:
    13,125
    Likes Received:
    9,766
    I saw stuff that there is an announcement today. Not sure when but I'm keeping my fingers crossed
     
    hovercraftdriver25 likes this.
  20. hovercraftdriver25

    hovercraftdriver25 Well-Known Member

    Joined:
    Apr 8, 2010
    Messages:
    252
    Likes Received:
    76
    US or UK? UK is having an event, supposedly Beats related and probably formal announcement of Sensation XE/XL or whatever it is called.
     
  21. BabyBlues

    BabyBlues Trouble Just Finds Me! VIP Member

    Joined:
    Jun 3, 2010
    Messages:
    13,125
    Likes Received:
    9,766
    Damn, looks like the UK. Sad face for me.
     
  22. jbh00jh

    jbh00jh Well-Known Member

    Joined:
    Apr 30, 2010
    Messages:
    392
    Likes Received:
    45
    All you have to do is go into settings/applications with System App Remover and uninstall the two apks. If they are tech savvy enough to root a phone they can do that.
     
  23. blkbeltkid17

    blkbeltkid17 Well-Known Member Contributor

    Joined:
    Nov 16, 2010
    Messages:
    4,383
    Likes Received:
    690
    I wanna see the announcement for this now
     

Share This Page

Loading...