Android Malware Comes Preinstalled From The Factory, For Your Convenience

Hacking comes from inside the house

In the past, there have been instances of questionable software pre-installed by manufacturers causing unnecessary vulnerabilities, with Superfish being a prime example. In most cases, the software wasn’t specifically designed to be malware, it just turned out to be insecure and made the product vulnerable to attack. A recent study by Trend Micro found that many low-end Android devices not only have software installed by their manufacturers that inadvertently introduce vulnerabilities, but also deliberately designed malware. It became clear.

Android malware is built into the firmware and companies are unknowingly exposing their customers to attack. The cost of buying firmware to run devices plummeted, and reputable developers who were charging money for their firmware were found out of business by predatory developers who didn’t charge much. Did. firmware. The problem is, as the science fiction writer once said, TANSTAAFL.

The free firmware comes with some pretty questionable and completely undisclosed plugins that the developers actually make money from. One example mentioned in The Register’s article is the ability to “rent” a device to him for 5 minutes by paying a certain amount to the company that provided the firmware. During that five-minute period, keystrokes, geo-location, IP address, and on-device data can be collected without the user’s knowledge.

Devices from Samsung and Google use home-developed firmware, but low-cost imitations may contain such Android vulnerabilities. Also, most IoT devices likely have firmware that contains these vulnerabilities, and since they are built directly into the firmware, they are not patchable.

If you want to completely ruin your day, read on.

Source link

Leave a Reply

Your email address will not be published. Required fields are marked *