Android Browser Flaw A “Privacy Disaster”

HardOCP News

[H] News
Joined
Dec 31, 1969
Messages
0
If you are an Android user you should definitely read this.

A bug quietly reported on September 1 appears to have grave implications for Android users. Android Browser, the open source, WebKit-based browser that used to be part of the Android Open Source Platform (AOSP), has a flaw that enables malicious sites to inject JavaScript into other sites. Those malicious JavaScripts can in turn read cookies and password fields, submit forms, grab keyboard input, or do practically anything else.
 
Good thing I use Dolphin Browser with the Dolphin JetPack which is their own browser rendering engine which bypasses Google's rendering engine.
 
The sad thing is, most devices in the wild wont ever get a fix for this... and because of that, there are A LOT of potential targets out there.

I scratch my head in amazement that Google still lets carriers and manufacturers call the shots with their OS.
 
I still don't understand why this surprises anyone. Using Android is like getting thrown back into Win9x in terms of its security paradigms...
 
And then the Android people bash iOS for having maybe 2-3 non-serious vulnerabilities that require jailbreaking to even work lol.
 
No sarcastic comments on the frontpage? Ahhh yes, it's not an Apple story... :eek:
 
No sarcastic comments on the frontpage? Ahhh yes, it's not an Apple story... :eek:

Probably because, unlike Apple/iOS, Google/Android doesn't tout it's product as being perfection and without flaws.
Apple wouldn't get so much flack if it wasn't always spreading propaganda about itself as being the end-all-be-all of technology solutions.
 
Who the hell uses "Browser" at this point? Chrome/Firefox/Opera/Dolphin/Penguin are all superior and run on anything in the last 3 or 4 years :/
 
Who the hell uses "Browser" at this point? Chrome/Firefox/Opera/Dolphin/Penguin are all superior and run on anything in the last 3 or 4 years :/

Firefox is a POS on Android
Dolphin absolutely shreds my battery and annoying GUI quirks
Haven't touched Opera since my Touch Pro2
Chrome another bloated POS.
Haven't tried Penguin.
 
Who the hell uses "Browser" at this point? Chrome/Firefox/Opera/Dolphin/Penguin are all superior and run on anything in the last 3 or 4 years :/

Everyone over 40 in my experience.

Probably because, unlike Apple/iOS, Google/Android doesn't tout it's product as being perfection and without flaws.
Apple wouldn't get so much flack if it wasn't always spreading propaganda about itself as being the end-all-be-all of technology solutions.

So it is OK for Android to be less secure because they don't mention it? When you sign up for an Android device, are you just supposed to accept the platform has inherently flawed security because Google doesn't force firmware updates for their platform?

Apple patched the 4.5 year old 3GS earlier this year to fix Heartbleed. Many Android devices don't even have a Heartbleed fix and won't ever get one at this point.
 
The sad thing is, most devices in the wild wont ever get a fix for this... and because of that, there are A LOT of potential targets out there.

I scratch my head in amazement that Google still lets carriers and manufacturers call the shots with their OS.

Sadly, this is exactly why I'm considering an iPhone for my next phone if the Nexus 6 has any major issues (e.g. terrible battery like the new Moto X). I don't even like the iPhone UI, but Samsung has seriously wrecked my opinion of non Nexus Android phones.

Firefox is a POS on Android
Dolphin absolutely shreds my battery and annoying GUI quirks
Haven't touched Opera since my Touch Pro2
Chrome another bloated POS.
Haven't tried Penguin.

Yes. Firefox Android is a POS. Dolphin had some process which refused to go to sleep and killed my battery. Don't care for Chrome at all.

I'm using CM browser now which seems decent. Disappointing the amount of searching and playing around I had to do just to find a browser. And in 3 months CM will suddenly require some new level of access to my phone that I cannot disable without rooting.

Android, you're making it hard for me to love you!
 
I really wish google would press the issue with carriers for the whole fragmentation now, they have so much market share now i dont think the carriers coudl fight them if they wanted to
 
No sarcastic comments on the frontpage? Ahhh yes, it's not an Apple story... :eek:

butthurt.jpg
 
First time I've heard of Chrome being a bloated browser, but then again I'm on a Nexus 5 so I haven't had any speed issues with anything as of yet...
 
Sadly, this is exactly why I'm considering an iPhone for my next phone if the Nexus 6 has any major issues (e.g. terrible battery like the new Moto X). I don't even like the iPhone UI, but Samsung has seriously wrecked my opinion of non Nexus Android phones.



Yes. Firefox Android is a POS. Dolphin had some process which refused to go to sleep and killed my battery. Don't care for Chrome at all.

I'm using CM browser now which seems decent. Disappointing the amount of searching and playing around I had to do just to find a browser. And in 3 months CM will suddenly require some new level of access to my phone that I cannot disable without rooting.

Android, you're making it hard for me to love you!

I'm giving UC a try. Seems decent but still can't import/export in a native format. Comment in a review said they are working on it.
 
Firefox is a POS on Android
Dolphin absolutely shreds my battery and annoying GUI quirks
Haven't touched Opera since my Touch Pro2
Chrome another bloated POS.
Haven't tried Penguin.

Have to agree. Chrome wont display forums properly with one post having huge text and the next post having tiny unreadable text. Cant use that. Firefox is just awful and never works right. Opera isnt much better than Chrome. Dolphin is pretty solid and the one I usually use. The stock browser on my Note 2 is the best in terms of displaying websites properly and working better. The UI isnt as good as Dolphin which is the only reason I dont use it all the time, but yeah, the stock browser at least on my Note 2 is very good and UI aside (and its not horrible) its the best performing browser.
 
chrome doesn't use webkit any more. It uses a custom derived version call blink

http://en.wikipedia.org/wiki/Google_Chrome#Release_history
Chrome is not the Android Browser.

The Android Browser is usually the built in base browser when you first flip on the phone unless the carrier added Chrome.

If you have a POS phone with a thimble for storage, you save space by not installing other browsers if you don't have to. I guess for a while, you have to.
 
First time I've heard of Chrome being a bloated browser, but then again I'm on a Nexus 5 so I haven't had any speed issues with anything as of yet...
I think its unclear what the Android Browser does. But guaranteed that Chrome Browser phones the mothership. There's that for those who care.


Also annoying. I was checking out a frappening type event a while back and hand my 10 year old nephew a cheap POS prepaid I use as a remote. Thanks, to Google my browsing history was in the ad hoc remote. Fortunately it never came up. But I'm sure Mom would have had a thing to say.
 
Also annoying. I was checking out a frappening type event a while back and hand my 10 year old nephew a cheap POS prepaid I use as a remote. Thanks, to Google my browsing history was in the ad hoc remote. Fortunately it never came up. But I'm sure Mom would have had a thing to say.

You did that to yourself though, Chrome doesn't automatically sync across multiple devices unless you tell it to.
 
BFD. Majority use Chrome and all my devices including from 2012 and even 2010 are running Android 4.4 which are not affected.
 
BFD. Majority use Chrome and all my devices including from 2012 and even 2010 are running Android 4.4 which are not affected.

According to Google themselves, less than 25% of android users are running 4.4... so it is sort of a big deal.

My boss's Android phone, which he got last year from our company for example, is running Android 4.1.2 and he's only been using the stock browser that it came with (until I gave him the heads up). The vast majority of Android users... just like iOS and WP users, aren't tech savy. The power users are a small minority
 
Also annoying. I was checking out a frappening type event a while back and hand my 10 year old nephew a cheap POS prepaid I use as a remote. Thanks, to Google my browsing history was in the ad hoc remote. Fortunately it never came up. But I'm sure Mom would have had a thing to say.

That's why you use the Google porn feature...I mean, Incognito window.
 
My boss's Android phone, which he got last year from our company for example, is running Android 4.1.2 and he's only been using the stock browser that it came with (until I gave him the heads up).

Highly doubtful considering 4.1 was released in 2012 so a phone purchased in 2013 would've had 4.3 if not carrier upgraded to 4.4. What carrier, make and model of your boss' phone?
 
Highly doubtful considering 4.1 was released in 2012 so a phone purchased in 2013 would've had 4.3 if not carrier upgraded to 4.4. What carrier, make and model of your boss' phone?

Pretty sure it's the Razr Maxx HD

I know he tried doing a software update but alas, there was none available (which isn't surprising)
 
Stopped reading when I saw Ars Technica.

Closed the tab when I saw Peter Bright.
 
I'm using CM and Opera at the moment. If I had to give the nod to one or the other....Opera would probably win. Seems much faster on **my** phone.
 
AOSP Browser was great and is still the fastest thing on my phone, but I've switched over to Chrome for exactly the reason illustrated by this story.

Sadly, Chrome is not only slower as an app, but rendering feels noticeably slower than AOSP Browser too. It's one of my few big gripes with Android.
 
I've been using CM on my Maxx HD (which, btw is running 4.4.2) and it has been the best browser by far. Chrome seems to run far better on phones with >1GB of ram.

The regular android browser is fast but crappy. Worst browser is firefox which doesn't seem to render most pages correctly.

Don't know what apple people are talking about as Safari sucks pretty bad too.My gf uses chrome and dolphin on her 5.
 
Back
Top