Jolla is affected by QuadRooter
http://blog.checkpoint.com/2016/08/07/quadrooter/ https://play.google.com/store/apps/details?id=com.checkpoint.quadrooter Good time to upgrade Jolla's android.
We have moved to a new Sailfish OS Forum. Please start new discussions there.
http://blog.checkpoint.com/2016/08/07/quadrooter/ https://play.google.com/store/apps/details?id=com.checkpoint.quadrooter Good time to upgrade Jolla's android.
This should be a security issue for Jolla in general, not Android-Layer itself. We are not secure, because we are a minority compared to Android (security by obscurity...maybe they don't know us, so they don't attack us?).
Solution:
https://together.jolla.com/question/132122/upgrade-qualcomm-drivers-to-more-recent-level/
I don't know when the patch would arrive for sailfish os, but I don't have to worry much because I am using only jolla apps!
Yes, that will provide pretty good shield from most attacks.
It is of course fairly easy to implement these attacks (or pretty much anything really) as native SFOS application but a good bet is that the target population is so small it is not really worthwhile. I'd be wary anyway of any binaries not installed from the Jolla Harbour, however... :)
Best practice is to only ever install packages you have yourself built from sources that you have at least cursorely eyeballed.
juiceme ( 2016-08-10 08:26:24 +0200 )editThis thread is public, all members of Together.Jolla.Com can read this page.
Asked: 2016-08-08 16:40:22 +0200
Seen: 1,627 times
Last updated: Aug 10 '16
Word prediction should be always turned off when entering passwords in Android apps [released]
Password manager for Sailfish [answered]
Android VKB saves and suggests passwords in plaintext
[Feature-request] Track & protect my Jolla
Cloud backup should be encrypted
Guest account for demonstration [answered]
I was curious about this as well. I used the search but only found this request to update the Qualcomm drivers: https://together.jolla.com/question/132122/upgrade-qualcomm-drivers-to-more-recent-level/ No real answer is given yet though.
Jozz ( 2016-08-08 17:14:00 +0200 )editI am seriously disappointed at how Jolla fails completely to provide timely security updates. It seems like there is no infrastructure at all for quicker updates than the quarterly version updates (which are often late, too).
Federico ( 2016-08-08 17:20:50 +0200 )editBlame Qualcomm, not Jolla.
ced117 ( 2016-08-08 17:54:03 +0200 )edit@ced117 I don't expect Qualcomm to provide bug-free software, but I do expect Jolla to release security fixes when a vulnerability comes up. It's not the only one; there is another thread mentioning several glibc vulnerabilities that have been there for months when a simple fix is available upstream. I can't blame Qualcomm for those.
Federico ( 2016-08-08 18:35:17 +0200 )edit@Federico About the glibc vulnerabilities, you might be right, Jolla is "in fault" here.
But again, Jolla cant release security fixes for something that they cant fix themselves. (Access to the source code of binary blobs, blablabla...)
ced117 ( 2016-08-08 19:47:33 +0200 )edit