TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Cyanogenmod Updater vulnerable to MITM attack

75 pointsby mfinchamover 11 years ago

7 comments

kyhwana2over 11 years ago
(Whoops, I fucked up a few http/https there. It should say that CM are only using HTTP, they aren't using ANY HTTPS at all. I had a misplaced sed there)
tga_dover 11 years ago
So much for a greater emphasis on security. How is this not one of the first things checked on? Providing encrypted messaging and permissions tuning on apps doesn't mean a whole lot if these sorts of bugs exist.
StavrosKover 11 years ago
Yay! How do people make rookie mistakes like these? <i>Always</i> verify certificates, and, even better, hardcode the cert&#x2F;CA fingerprint in your client (so it can&#x27;t get replaced with a valid cert upstream).
评论 #7251496 未加载
sleepyKover 11 years ago
CM&#x27;s commitment to bringing support to legacy devices is admirable, but they bundle some very annoying, redundant and as OP says unsecured applications with their ROM packages.<p>CM Account, CM Updater, Movie Studio, File Manager and CM Wallpaper are all apps that I uninstall as soon as I flash a ROM to one of my devices.<p>Their CM File Manager for one is a totally redundant application that hasn&#x27;t been updated in a long time, despite being broken (it doesn&#x27;t work in Super User mode without done juggling about)<p>Their CM Account is one other thing that I find totally pointless.<p>CM would be better off bringing more innovative features to Android instead of just copying drivers from CAF and changing headers to say CM instead of CAF or AOSP.<p>The innovation in the Android ROM community has been coming from Paranoid Android, AOKP, Omni and Slim ROMs, and from the Xposed community.<p>They&#x27;ve been reduced to being a repo shepherd for certain devices, but most of their user base comes from people running &quot;Unofficial&quot; builds compiled by independent developers.<p>I think, as a start up, they&#x27;d be better off if they focused on features instead of just trying to market CM Phones that essentially run a Nexus like build of plain vanilla Android.
arca_voragoover 11 years ago
All I want is a fully open source phone from the radio firmware up. Android has been such a disappointment for me as a security conscious person, between googles questionable open source policies to the carrier hell it gets forced into and into the blackbox of radio protocols like GSM that far too often have DMA to the same segments of the CPU.<p>The whole point of FOSS is to be able to see what&#x27;s going on, for freedom and control to the user. At this point I barely see Android as any better than IOS, aka, a very pretty jail for the user.
评论 #7252869 未加载
评论 #7253075 未加载
ender89over 11 years ago
... So what youre saying is that my galaxy nexus&#x27; inability to list cm11 &quot;M&quot; releases (and forcing me to download them manually when they come out) is actually a security feature?
voltagex_over 11 years ago
Another day, another block category.<p>&gt; Content Blocked (content_filter_denied) &gt; Content Category: &quot;Malicious Sources&#x2F;Malnets&quot;<p>Any idea why this site would be blocked at $BIGCORP?