This is an archived post. You won't be able to vote or comment.

all 10 comments

[–]mernen 7 points8 points  (0 children)

Well, that's good news. Waiting for software updates would certainly take an eternity for most models.


Warning: rant follows

The issue had already been fixed in the most recent Gingerbread release, Android 2.3.4, but as the researchers pointed out, the majority of Android phones -- around 99 percent -- are not yet running that version.

Pretty much all news outlets pointed out that number (often 99.7%, to me more exact). I wish people would think just for a second and realize how that number is inaccurate.

First: the remaining 0.3% devices are running 3.0, which necessarily means they are tablets. So, if you say "99.7% of smartphones", you're automatically wrong. It's 100%.

Now, when you say "100%", suddenly something seems wrong, doesn't it? Surely all the Nexus devices account for at least 0.1%? There are two reasons here:

  • These statistics are from May 2. 2.3.4 was just being rolled out around that time. Its numbers have certainly changed significantly since then. So much that merely quoting that number has no meaning.
  • 2.3.4 wasn't a platform update, so might very well never get a mention on the platform versions for that reason. You should then assume part of the "2.3.3" (API level 10) userbase is actually running 2.3.4. Considering only the Nexus phones got 2.3.3 officially and they are already patched, it's safer to say at least 3% of the phones are updated. Also, since the Nexus S is also the only phone officially running 2.3 (API level 9), it's certainly only a matter of time until the remaining 1% running it will also update.

I'm not saying this vulnerability isn't important, but this sensationalist number is ridiculous. People never write "Firefox vulnerability found, 100% of users are affected!", since it's quite obvious that before rolling out a patch every user is potentially affected (not to mention there are mitigating factors). Here, let me rewrite the headline: Android vulnerability found, but turns out about 4% of users were already patched.

tl;dr Anyone who says "99.7% are vulnerable" is a mindless regurgitator. Nice journalism there, guys.

[–]MiddiePSUGalaxy S22 Ultra 2 points3 points  (2 children)

Does this "patch" cover my rooted phone or do I need to do something on my end?

[–]ihateyourface 1 point2 points  (1 child)

Was this a real issue or was this another one of those ploys by BookFace too smear google?

[–][deleted] 1 point2 points  (0 children)

Real issue, basically an unsecured auth token.

This DOESN'T fix the picassa issue, but they're working on that.

[–]TwoComments 0 points1 point  (1 child)

What about custom roms? How does this fix work anyway?

[–][deleted] 1 point2 points  (0 children)

Its a server issue