TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

99% of Android phones leak secret account credentials

81 点作者 joeshaw大约 14 年前

3 条评论

Xuzz大约 14 年前
As the post below says, this may not actually be an important leak. But, it does highlight the issues with the "fragmentation" issue in a much more real way than we've seen before.<p>What happens to all these Android handsets sold that don't get updated if a major security hole is found in Android 2.2? Almost none of them have official upgrade routes to 2.3 at this point, and I find it hard to imagine that they would be able to get out a 2.3 release to fix security hole in a reasonable amount of time if they haven't been able to get it out in general for about six months now.<p>I obviously hope there isn't any security holes that are discovered. But it would be interesting to see how the Android vendors would react to that situation — especially if it was something Google couldn't fix easily in an Android Market-distributed patch, like the "malware" earlier this year.<p>(Apple is no better here, fwiw: the iPhone 2G was excluded from any fix to the remote "JailbreakMe" exploit, and the iPhone 3G never got any fix to the location "tracking" controversy.)
评论 #2556509 未加载
评论 #2555623 未加载
drivebyacct2大约 14 年前
Oh for the love of God.<p>This just in, 99% of websites on the Internet leak secret account credentials. Can we please ban The Register here?<p>Account credentials != Auth Token. And this is a result of not using SSL to share the auth token back. Is it a mistake? Yes. Is it nearly as bad as this headline or the article implies? No.
评论 #2555482 未加载
yanw大约 14 年前
El Reg is link-baiting again. They are hardly 'leaking account credentials'.<p>A patch could be pushed separately, the phones don't all have to get 2.3.4 to fix a venerability, they've done so before.