TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Cyanogenmod Updater vulnerable to MITM attack

75 点作者 mfincham超过 11 年前

7 条评论

kyhwana2超过 11 年前
(Whoops, I fucked up a few http/https there. It should say that CM are only using HTTP, they aren't using ANY HTTPS at all. I had a misplaced sed there)
tga_d超过 11 年前
So much for a greater emphasis on security. How is this not one of the first things checked on? Providing encrypted messaging and permissions tuning on apps doesn't mean a whole lot if these sorts of bugs exist.
StavrosK超过 11 年前
Yay! How do people make rookie mistakes like these? <i>Always</i> verify certificates, and, even better, hardcode the cert&#x2F;CA fingerprint in your client (so it can&#x27;t get replaced with a valid cert upstream).
评论 #7251496 未加载
sleepyK超过 11 年前
CM&#x27;s commitment to bringing support to legacy devices is admirable, but they bundle some very annoying, redundant and as OP says unsecured applications with their ROM packages.<p>CM Account, CM Updater, Movie Studio, File Manager and CM Wallpaper are all apps that I uninstall as soon as I flash a ROM to one of my devices.<p>Their CM File Manager for one is a totally redundant application that hasn&#x27;t been updated in a long time, despite being broken (it doesn&#x27;t work in Super User mode without done juggling about)<p>Their CM Account is one other thing that I find totally pointless.<p>CM would be better off bringing more innovative features to Android instead of just copying drivers from CAF and changing headers to say CM instead of CAF or AOSP.<p>The innovation in the Android ROM community has been coming from Paranoid Android, AOKP, Omni and Slim ROMs, and from the Xposed community.<p>They&#x27;ve been reduced to being a repo shepherd for certain devices, but most of their user base comes from people running &quot;Unofficial&quot; builds compiled by independent developers.<p>I think, as a start up, they&#x27;d be better off if they focused on features instead of just trying to market CM Phones that essentially run a Nexus like build of plain vanilla Android.
arca_vorago超过 11 年前
All I want is a fully open source phone from the radio firmware up. Android has been such a disappointment for me as a security conscious person, between googles questionable open source policies to the carrier hell it gets forced into and into the blackbox of radio protocols like GSM that far too often have DMA to the same segments of the CPU.<p>The whole point of FOSS is to be able to see what&#x27;s going on, for freedom and control to the user. At this point I barely see Android as any better than IOS, aka, a very pretty jail for the user.
评论 #7252869 未加载
评论 #7253075 未加载
ender89超过 11 年前
... So what youre saying is that my galaxy nexus&#x27; inability to list cm11 &quot;M&quot; releases (and forcing me to download them manually when they come out) is actually a security feature?
voltagex_超过 11 年前
Another day, another block category.<p>&gt; Content Blocked (content_filter_denied) &gt; Content Category: &quot;Malicious Sources&#x2F;Malnets&quot;<p>Any idea why this site would be blocked at $BIGCORP?