Samsung Zero-Day Vuln Under Active Exploit, Google Warns (www.darkreading.com)
from kid@sh.itjust.works to cybersecurity@sh.itjust.works on 23 Oct 11:26
https://sh.itjust.works/post/27041785

#cybersecurity

threaded - newest

linearchaos@lemmy.world on 23 Oct 11:54 next collapse

Here’s the scope of it

A National Institute of Standards and Technology (NIST) advisory on the bug describes it as “an issue [that] was discovered in the m2m scaler driver in Samsung Mobile Processor and Wearable Processor Exynos 9820, 9825, 980, 990, 850, and W920.” A use-after-free bug in the mobile processor ultimately leads to privilege escalation, the agency added.

Ajen@sh.itjust.works on 23 Oct 16:19 next collapse

Looks like they’re mainly used in Galaxy S phones and tables…

sunzu2@thebrainbin.org on 23 Oct 18:01 collapse

The bootloader is locked for your own good, boy!

burgersc12@mander.xyz on 23 Oct 20:02 collapse

Its a good thing people already knew Exynos sucks. Made me steer well clear of those chips.

SomeGuy69@lemmy.world on 23 Oct 12:39 collapse

Urrg! I have one of those CPUs. (Exynos 9820) I don’t want to upgrade with an expensive new phone. I get no longer security updates.

sunzu2@thebrainbin.org on 23 Oct 15:35 next collapse

Pixel and grapheneos...

About as good as normie can get currently

Buy used to dent google direct profit and it is cheaper

SomeGuy69@lemmy.world on 23 Oct 16:18 next collapse

My banking app sadly doesn’t work on a rooted phone.

Ajen@sh.itjust.works on 23 Oct 16:22 next collapse

Grapheneos isn’t rooted by default, and they recommend re-locking the bootloader after installing it, so most banking apps work.

sunzu2@thebrainbin.org on 23 Oct 16:22 collapse

Custom roms dont require rooting. It is a bad security practice and not necessary.

GrapheneOS uses sandboxed google play store and most banking apps work fine with exception like CashApp and other bankspy type shops.

Gerudo@lemm.ee on 23 Oct 17:38 collapse

Is there a confirmed list of apps that will not function in Graphene? I searched around, and all I get is “some bank apps dont work” but your the first I see mention cashapp specifically. I could probably work around Cashapp, but I’d at least need zelle/venmo etc. Due to my credit union app more than likely not being compatible.

I really want to move to the platform, but I don’t currently have a Pixel, so I can’t just try it out. Before going out, buying a Pixel, loading Graphene and finding out I can’t use my banking app or the very least the other money apps I’d just like a heads up.

In the end if I need a backup phone then so be it.

sunzu2@thebrainbin.org on 23 Oct 17:43 next collapse

I think there lists out there but i never seen them, maybe somebody can post.

My friend tried the switch and cashapp was deal breaker for him so thats how i know.

It is trial and error and my understanding, some banks are actively working to brick custom roms

Cash app used to work according to reddit posts i saw.

I am abit more hardcore about it. If bank fucks around, i will fucking move. I know we cant exepct most people to do this.

But with privacy/security first mentality it is doable.

smpl@discuss.tchncs.de on 24 Oct 21:34 collapse

I am abit more hardcore about it. If bank fucks around, i will fucking move.

Thank you. That’s someone willing to make a change.

Appoxo@lemmy.dbzer0.com on 23 Oct 20:22 collapse

I think this might apply to your request: privsec.dev/…/banking-applications-compatibility-…
Linked by this article: grapheneos.org/usage#banking-apps

Gerudo@lemm.ee on 23 Oct 20:42 collapse

Almost. It doesn’t list cashapp, venmo, zelle. I use a local credit union, so my bank app would likely never be listed.

Maybe I just keep an eye out for a cheap Pixel and just try it.

Lucidlethargy@sh.itjust.works on 23 Oct 17:51 collapse

Pixel phones can have hardware quality issues. Samsung arguably makes the best hardware. Their cameras and screens have always been way ahead of every other phone.

sunzu2@thebrainbin.org on 23 Oct 18:01 collapse

I have heard about that. Samsung prolly does have better quality but their US models got locked bootloaders and theu dont really get any support from calyx and graphene, so i cant recommend them.

As idiotic as it is, googles phone is the besy choice if you are privacy/security first type

ilhamagh@lemmy.world on 23 Oct 18:07 next collapse

Ugh, I’m in the same boat. s10e, I have zero complaint other than the EOL security update. Bought it 2nd hand two years ago.

There’s nothing in the market with similar price with the spec and size of my current phone.

Appoxo@lemmy.dbzer0.com on 23 Oct 20:18 collapse

Lineage might extend that life a little bit

corsicanguppy@lemmy.ca on 25 Oct 00:07 collapse

I’d try it, but this is essentially an emergency signalling device and not something I’d like to render inoperable.

Appoxo@lemmy.dbzer0.com on 26 Oct 10:26 collapse

Certainly understandable. Wouldnt risk it on my current main device either. Only on a future new or old backup phone