AOSP Browser Security Hole - Nexus 4 General

Rootzwiki published a report on supposed security issues with the stock AOSP browser, specially with saving the users passwords. You can read the article here.
What do you guys think? Should we switch to a different browser for now or until Google releases a fix together with a new Android release?

Well we don't have aosp, its chrome.
Sent from my Nexus 4 using xda app-developers app

Oh OK. I guess I'm addressing the thread to users like me who have installed AOSP-based custom ROMs.

In other news, rooting your device is a security risk. More news at 11

styckx said:
In other news, rooting your device is a security risk. More news at 11
Click to expand...
Click to collapse
You've got a point there.

I have noticed the same problem. Not just for AOSP browser, but Chrome for desktop aswell.. Might as well write em on the back of my hand.

Related

Android 5.0 KLP. What do you want out of it?

What does everyone want out of the newest major version of Android what do we want removed from it I thought I would start this thread just to see peoples opinions of key lime pie.
Nexus 4 CyanogenMod 10.1.0
Don't mean to be rude. However there is already a thread on this.
Sent from my Nexus 4 using xda premium
Apparently what Google want from it is support for older or less powerful devices as that's what they're concentrating on (or so the rumours go so far), it's supposedly going to run well on any device with 512MB or more.
-Better battery management
-Major UI overhaul (Holo is a bit gloomy)
-The ability to sync app data across multiple devices.
-"Guest mode", multiuser with restricted access.
-Last but not least, the ability to summon demons at will
Sent from my blazing fast Nexus 4
-Money?!
.
.
.
.
-Peace in the world...
I hope that Google devs will rush to this thread just to take our ideas, wants and needs for KLP as clearly in your logic they haven't planned anything yet and most likely this is not in the pipeline of Android development.
And also I don't have anything against threads like this just I don't really think there's a purpose to discuss what we would like to have - we will get what Google has planned for us.
Sent from my Nexus 4 using xda app-developers app
uchihakurtz said:
-Better battery management
-Major UI overhaul (Holo is a bit gloomy)
-The ability to sync app data across multiple devices.
-"Guest mode", multiuser with restricted access.
-Last but not least, the ability to summon demons at will
Sent from my blazing fast Nexus 4
Click to expand...
Click to collapse
Well there is a mod to summon demons just travel to the 7th level of hell and connect your phone to Satan's computer and do the ADB push command it's still in Beta so I would be careful
Nexus 4 CyanogenMod 10.1.0
Yaaaay, another thread about 5.0 when 4.3 is not even out yet. How delightful.
only one thing
0 BUGS
Smoothness, battery compsumption improvement and bug-free
Use the already existing thread please
Sent from my iPad using Tapatalk HD
Android 5.0 (keylime pie?) Countdown thread
Closed

No new Google maps for us?

I was wondering if any one on the Samsung official ICE Rom (4.0.4) received the new Google maps with the streamlined UI. Google play says it'll be rolled out to all 4.0.3+ devices, but I don't see an update on mine.
Furthermore, when I switch to unofficial AOKP Rom (jelly bean), I do get the update, but then the map keeps stalling and crashing.
I am beginning to fear that this is another instance of the limitations of tegra2, especially the lack of NEON, but I'm no developer and was hoping others more knowledgeable would be able to help us.
The new Google maps, especially for tablets, is really sleek, and it'd be tragic not to be able to update to it. I am for the first time in a long while seriously thinking about jumping ship cause of this.
Sent from my GT-P7310 using xda premium
Jnn1 said:
I was wondering if any one on the Samsung official ICE Rom (4.0.4) received the new Google maps with the streamlined UI. Google play says it'll be rolled out to all 4.0.3+ devices, but I don't see an update on mine.
Furthermore, when I switch to unofficial AOKP Rom (jelly bean), I do get the update, but then the map keeps stalling and crashing.
I am beginning to fear that this is another instance of the limitations of tegra2, especially the lack of NEON, but I'm no developer and was hoping others more knowledgeable would be able to help us.
The new Google maps, especially for tablets, is really sleek, and it'd be tragic not to be able to update to it. I am for the first time in a long while seriously thinking about jumping ship cause of this.
Sent from my GT-P7310 using xda premium
Click to expand...
Click to collapse
Mine was just updated today, works buttery smooth, took it's sweet time getting here though.
jay2the1 said:
Mine was just updated today, works buttery smooth, took it's sweet time getting here though.
Click to expand...
Click to collapse
Many thanks! Good news to hear. I went over to the unofficial AOKP, but glad to know I can go back to Samsung stock Rom when needed, and not worry about missing Google maps 7.0 !
Sent from my GT-P7310 using xda premium

[Request] Hardening AOKP security?

Dear Developers of AOKP,
first of all: Thank you so much for this awesome ROM which I am using since 3 years by now! Since security has been in the media periodically for quite some time now, I feel like this is the right time to ask: Would you please harden AOKP to include the very latest security enhancements? What bothers me in particular is that it seems even though so much development is being done, vulnerabilities like Mempodroid still seem to be present in the latest builds (using AOKP 4.4.2 for M7UL). A good way to check this is to use the X-RAY Security Scanner. Please fix these vulnerabilities.
Furthermore, would you please implement a feature to toggle hardening like triggered with the app SecDroid? This neat little project unfortunately has been abandoned, but yet the idea should be clear. The developer of SecDroid also released a Guide on how to harden Android. Maybe AOKP can use the Source of SecDroid somehow?
For me, AOKP always will be the best ROM out there. I can proudly say that having donated to the project makes me feel great and I'm looking foward to see AOKP implementing the latest and greatest security enhancements out there. Thank you ahead!
SecUpwN said:
Dear Developers of AOKP,
first of all: Thank you so much for this awesome ROM which I am using since 3 years by now! Since security has been in the media periodically for quite some time now, I feel like this is the right time to ask: Would you please harden AOKP to include the very latest security enhancements? What bothers me in particular is that it seems even though so much development is being done, vulnerabilities like Mempodroid still seem to be present in the latest builds (using AOKP 4.4.2 for M7UL). A good way to check this is to use the X-RAY Security Scanner. Please fix these vulnerabilities.
Furthermore, would you please implement a feature to toggle hardening like triggered with the app SecDroid? This neat little project unfortunately has been abandoned, but yet the idea should be clear. The developer of SecDroid also released a Guide on how to harden Android. Maybe AOKP can use the Source of SecDroid somehow?
For me, AOKP always will be the best ROM out there. I can proudly say that having donated to the project makes me feel great and I'm looking foward to see AOKP implementing the latest and greatest security enhancements out there. Thank you ahead!
Click to expand...
Click to collapse
A few of us are interested in this and we'll see what can be done
BytecodeMe said:
A few of us are interested in this and we'll see what can be done
Click to expand...
Click to collapse
Awesome! What are you planning to do?
SecUpwN said:
Dear Developers of AOKP,
first of all: Thank you so much for this awesome ROM which I am using since 3 years by now! Since security has been in the media periodically for quite some time now, I feel like this is the right time to ask: Would you please harden AOKP to include the very latest security enhancements? What bothers me in particular is that it seems even though so much development is being done, vulnerabilities like Mempodroid still seem to be present in the latest builds (using AOKP 4.4.2 for M7UL). A good way to check this is to use the X-RAY Security Scanner. Please fix these vulnerabilities.
Furthermore, would you please implement a feature to toggle hardening like triggered with the app SecDroid? This neat little project unfortunately has been abandoned, but yet the idea should be clear. The developer of SecDroid also released a Guide on how to harden Android. Maybe AOKP can use the Source of SecDroid somehow?
For me, AOKP always will be the best ROM out there. I can proudly say that having donated to the project makes me feel great and I'm looking foward to see AOKP implementing the latest and greatest security enhancements out there. Thank you ahead!
Click to expand...
Click to collapse
Even if every vulnerability fix was included in source, (for now) it will still not be secured. Unless you compile your own builds with a different platform key, your builds will not be secure. This applies to nearly every AOSP-based custom ROM.
We've talked about it, and we might implement something for milestone releases. But security is a huge huge problem to take on with custom ROMs and there are a lot of heads to the dragon to take down
Sent from my HTC One using Tapatalk
Romanbb said:
We've talked about it, and we might implement something for milestone releases. But security is a huge huge problem to take on with custom ROMs and there are a lot of heads to the dragon to take down.
Click to expand...
Click to collapse
True point. But I'm sure that folks who can add unicorn sparkles to a ROM will even discover and implement some really cool security enhancements & fixes for the already known vulnerabilities. After all, this is a suggestion and to be seen without pressure. Waiting for your next awesome release for M7UL, @Romanbb! You're doing a great job!
SecUpwN said:
True point. But I'm sure that folks who can add unicorn sparkles to a ROM will even discover and implement some really cool security enhancements & fixes for vulnerabilities. After all, this is a suggestion and to be seen without pressure. Waiting for your next awesome release for M7UL, @Romanbb!
Click to expand...
Click to collapse
For sure. I'm definitely not against security enhancements by any measure.
Why isn't it possible to create a tool that can repackage ROMs with custom keys, say, using a Windows computer or Xposed Framework?
Also, isn't Mempodroid what allows us to give apps SU permission?
pan.droid said:
Also, isn't Mempodroid what allows us to give apps SU permission?
Click to expand...
Click to collapse
No. Mempodroid is an EXPLOIT and a vulnerability, please don't mistaken it with SuperSU.
SecUpwN said:
please don't mistaken it with SuperSU.
Click to expand...
Click to collapse
Okay. Just so long as you don't *mistake* 'SU' with SuperSU=)
AOKP Kitkat Rom
The Android Open Kang Project (AOKP) team has released nightly builds for a number of Android running device which bring Android 4.4.2 KitKat update for these devices. One such build is also available for Sony Xperia Z, which runs Android 4.3 Jelly Bean.
gteknet said:
The Android Open Kang Project (AOKP) team has released nightly builds for a number of Android running device which bring Android 4.4.2 KitKat update for these devices.
Click to expand...
Click to collapse
As you might have guessed, AOKP runs through all my veins. I'd probebly never use anything else, if not forced to. As soon as a new nightly is out, I'm using it. But what exactly is the AOKP team doing to make their build more secure?
One of the features that I'd LOVE to have would be encrypted calls between AOKP builds without having to be online or installing additional software. Would such be possible somehow?
Thread cleaned
I suggest several members use the ignore user option if they want to remain members on XDA
I will be keeping an eye on posting. Cut out the infantile crap or you will be removed
This is a development site, take your garbage to a social media site
Senior Moderator
@kennyglass123, thanks for cleaning it up. I really appreciate your effort. Unfortunately though, no member of the AOKP team has answered my initial question yet. Could someone please do so?
SecUpwN said:
As you might have guessed, AOKP runs through all my veins. I'd probebly never use anything else, if not forced to. As soon as a new nightly is out, I'm using it. But what exactly is the AOKP team doing to make their build more secure?
Click to expand...
Click to collapse
Sadly, this question is still open. Since I'm using M7 (Gerneric GSM), maybe @Whitehawkx can answer this?

[Discussion] No stagefright fix for the Nexus 7...

Cannot find any news or rumors on a stagefright ota fix for the nakasi/nakasig. I'm surprised it appeared for all the other devices except this one...
I would understand if they don't update it to M (still not happy, my ipad 2 is still updating..), but not fixing this security problem on a device in the last android release seems odd.
Cannot find any news or rumors on a stagefright ota fix for the nakasi/nakasig. I'm surprised it appeared for all the other devices except this one...
I would understand if they don't update it to M (still not happy, my ipad 2 is still updating..), but not fixing this security problem on a device in the last android release seems odd.
Click to expand...
Click to collapse
Nope no update for you as the tablet is 3 weeks out of it's security patches window... And google doesn't care enough to fix one of THE biggest security thread in existence on a device 3 weeks out of the security patch period!
Sent from my Nexus 7 2013 using XDA Free mobile app
No need for a fix as Stagefright affects phones only.
No MMS no bug!
@cylgalad probably you should become more familiar with the bug before commenting ...
They should fix this for EVERY nexus device, regardless of it's age.
Sent from my D6603 using Tapatalk
noahvt said:
Nope no update for you as the tablet is 3 weeks out of it's security patches window... And google doesn't care enough to fix one of THE biggest security thread in existence on a device 3 weeks out of the security patch period!
Sent from my Nexus 7 2013 using XDA Free mobile app
Click to expand...
Click to collapse
Si my device that is on 5.1.1 and they just need a VERY LITTLE EFFORT to patch must remain unpatched because it just passed out the 3 years window? An EPIC security bug unfixed for this reason?
cylgalad said:
No need for a fix as Stagefright affects phones only.
No MMS no bug!
Click to expand...
Click to collapse
You're very wrong. MMs is just one attack vector of a lot of options.
gorgooger said:
They should fix this for EVERY nexus device, regardless of it's age.
Sent from my D6603 using Tapatalk
Click to expand...
Click to collapse
On every device, but specially on every Nexus, and specially one that is on 5.1.1 already...
Really Google?
RusherDude said:
Si my device that is on 5.1.1 and they just need a VERY LITTLE EFFORT to patch must remain unpatched because it just passed out the 3 years window? An EPIC security bug unfixed for this reason?
You're very wrong. MMs is just one attack vector of a lot of options.
On every device, but specially on every Nexus, and specially one that is on 5.1.1 already...
Really Google?
Click to expand...
Click to collapse
Yes... that's basicly the reason why it's not getting the update, If you guys are running 5.1.1 anyway, I advise everyone using it to start using cm12.1(or a recent rom based on that) as it is already patched for most devices
Hi all, according to CM's blog @ 2015/08/13, new build which including stagefright fix will be released upon CM11 and above. Could anyone help to confirm if our Nexus 7 2012 will get this build or not? Especially for CM11!

[ROM] [Work in Progress] [Mantis] LineageOS 14.1 for Fire TV Stick 4K

Hi community!
There is a WIP (Work in Progress) ROM being mainly developed by @Rortiz2 and @diegocr: https://github.com/LOSMantis
Current ROM Status:
- Not Stable
Not Working:
- Sound
- OMX
- Maybe more...
Developers out there that would like to join development are welcome!...
Notice: This is a WIP ROM. It needs to be compile from the source (build steps could be adapted from the Nexus Player https://wiki.lineageos.org/devices/fugu/build) if someone wants to try it out. Ready to flash builds would maybe be available when the ROM is more stable. Please do not ask for ETA, it is being developed in the spare time of the developers!
michael.santos said:
Hi community!
Anyone already seen this project on github: https://github.com/LOSMantis ?
It is a shame that this project are not being discussed here on XDA so more devs could help on this project...
Hope this post will "awake" some devs (maybe @Pretoriano80?) for this project...
This can be the project that will free our Fire TV Stick 4k from the crappy FireOS!
Click to expand...
Click to collapse
'I believe @diegocr and @Rotiz2 were working on it some and couldn't get the sound to work. Not sure if actively though...
This can be the project that will free our Fire TV Stick 4k from the crappy FireOS!
Click to expand...
Click to collapse
FireOS is very well maintained, even the oldest fireTVs/sticks getting still proper updates...
Sus_i said:
FireOS is very well maintained, even the oldest fireTVs/sticks getting still proper updates...
Click to expand...
Click to collapse
Yes, but full of bloatware, with some blocking mechanisms or black listed apps, no Google Play Store...
We are not allowed to change the home app easily, to use the standard Android settings without Amazon home app, not install already purchased apps on the Google Play Store and so on...
With root you can disable remove the "bloatware", although personally i dont think there is much i dont use. The fireOS TV is fairly smooth and easy to navigate. The android TV version is worse (IMO, I have a NVidea). You can disable the NIMH app, although i have yet to find any app it is blocking. The play store for androidTV is horrible. LauncherX is fairly easy to install. As with tank and sloan, i would expect issues with roms.
...
Rortiz2 said:
Can you and other people (that did this aswell) stop creating threads like this?
We're working on mantis yes but this takes its time...
For now all is working except OMX and Audio so it's not worth to release anything.
We will create the ROM thread when it's enough usable.
Just wait...
Regards.
Click to expand...
Click to collapse
Hi Rortiz2,
Why are you so mad about this thread? We did not ask for a working ROM or any release dates and we appreciate all your time and dedication to the project...
As I wrote in the subject, this is a WIP (Work in Progress) ROM... Have seen so many threads like this in other forums here on XDA where the ROM only boots but nothing works...
I have created this thread to allow other devs to join the project (if nobody talks about it, than nobody knows that a project already exists and can not help).
But if you would like to do this project alone, just tell me an I will delete this thread...
Best regards,
Michael
...
I got really excited when I saw this thread. I cannot wait for stock Android for the Firestick 4K. I will 100% donate to the dev's who get this working!!
Rortiz2 said:
It's ok, leave the thread here. If somebody wants to help there's no problem.
Click to expand...
Click to collapse
Just throwing out an idea here but would getting some kind of test build out help? Perhaps getting some catlogs from the community could help find a solution? Again just throwing an idea out.
AngryManMLS said:
Just throwing out an idea here but would getting some kind of test build out help? Perhaps getting some catlogs from the community could help find a solution? Again just throwing an idea out.
Click to expand...
Click to collapse
+1 for a test build, I've got a bricked 4k that boots both the hacked bootloader and TWRP, but whatever image I install has no display...
So I would like to try anything else even if stuff is broken on it (just to see if I can get a display).
thx.
michael.santos said:
Hi community!
Anyone already seen this project on github: https://github.com/LOSMantis ?
It is a shame that this project are not being discussed here on XDA so more devs could help on this project...
Hope this post will "awake" some devs (maybe @Pretoriano80?) for this project...
This can be the project that will free our Fire TV Stick 4k from the crappy FireOS!
Click to expand...
Click to collapse
It's at developer's discretion to discuss or release test builds here and considering that this particular rom still has some major bugs (call them deal breakers if you want), then i personally agree with the devs not releasing it yet.
Also, i didn't tested personally, but probably a custom rom like this may also break some features available on stock rom.
This being said, i'm sure that it will be released as soon as the guys behind it will consider it stable enough.
P. S. BTW, thread title is misleading and probably aldo violates XDA rules.
Pretoriano80 said:
It's at developer's discretion to discuss or release test builds here and considering that this particular rom still has some major bugs (call them deal breakers if you want), then i personally agree with the devs not releasing it yet.
Click to expand...
Click to collapse
I totally understand and respect that. I did bring up having some kind of developer/user test build done just in case that could help further along getting said bugs fixed by getting catlogs that might help narrow down what is causing the issues. But if the devs feel that doing that would only slow things down (or even not help at all) then I respect that decision.
Also, i didn't tested personally, but probably a custom rom like this may also break some features available on stock rom.
Click to expand...
Click to collapse
That's the nature of things when it comes to Lineage OS ROMs (and AOSP in general). Sometimes devs are able to get the ROMs to have nearly all the functionality of the device working... and sometimes not. But I generally prefer Lineage myself due to the overall experience being faster since LOS tends to not have all the bloat that stock ROMs sometimes have - especially Amazon devices which feel so bloated down with garbage I will never use.
Pretoriano80 said:
It's at developer's discretion to discuss or release test builds here and considering that this particular rom still has some major bugs (call them deal breakers if you want), then i personally agree with the devs not releasing it yet.
Also, i didn't tested personally, but probably a custom rom like this may also break some features available on stock rom.
This being said, i'm sure that it will be released as soon as the guys behind it will consider it stable enough.
P. S. BTW, thread title is misleading and probably aldo violates XDA rules.
Click to expand...
Click to collapse
Hi Pretoriano80,
As I already replied to one of the devs, I never asked for a release date or ROM for flashing. The title also is marked as WIP (Work in Progress), that means that the ROM is in development and not ready for use...
I have seen that you already made a great job with the custom kernel. Thanks! Would you also like to help this project as it seems it also can use your kernel? Kernel dev with ROM devs would be the best team!
Thanks again to all devs that work hard for releasing new stuff for the Amazon devices...
How's the progress so far?
Looks like nothing much: https://github.com/LOSMantis/android_vendor_amazon_mantis
Too bad !!
dead project ?
I made a test build (with many warnings). Also I used the kernel from @Pretoriano80.
You can download it here: https://www.androidfilehost.com/?w=files&flid=324510
Please note that I couldn't test this out yet, so be careful of what you do. (Will try it out for myself soon)
Ungeskriptet said:
I made a test build (with many warnings). Also I used the kernel from @Pretoriano80.
You can download it here: https://www.androidfilehost.com/?w=files&flid=324510
Please note that I couldn't test this out yet, so be careful of what you do. (Will try it out for myself soon)
Click to expand...
Click to collapse
it's not worth to test since it's a dead project, it would be more usefull to begin a new project developing LineageOS 16 rom , At least we will be able to use the new Android/Google TV UI.
robin994 said:
it's not worth to test since it's a dead project, it would be more usefull to begin a new project developing LineageOS 16 rom , At least we will be able to use the new Android/Google TV UI.
Click to expand...
Click to collapse
LineageOS 16 won't ever be able to happen for the Mantis version because it doesn't support treble, the most it could do is LOS 14.1 since it's a legacy device.

Categories

Resources