cancel
Showing results for 
Search instead for 
Did you mean: 
1

Ask

2

Reply

3

Solution

Meltdown & Spectre

jb3
2: Seeker
2: Seeker

There doesn't seem to be a single mention on the Voda forums of the worst security vulnerability to ever affect our smart phones (let alone everything else)?

 

So, what’s the latest? Will our phones receive a critical update at some point or will they become worthless doorstops once exploits are rife?

 

From my perspective I’d like to know about the Smart Ultra 6.

3 REPLIES 3

jb3
2: Seeker
2: Seeker

https://www.androidauthority.com/meltdown-spectre-kpti-827527/

Suggests the ARM Cortex A53 is not affected so guess I am in the clear. Not so for Platinum 7 (and others?)

BandOfBrothers
17: Community Champion
17: Community Champion

Hi @jb3

 

Thank you for sharing.

These issues are concerning but in my own experience i've yet to meet / discuss with anyone who has been directly affected by this and previous media reported vulnerabilities.

I in no way being flippant and dismiss this. 

I'm using a Samsung Galaxy s8 with the November 17 Security Patch and have no concerns personally. 

Over the many years i've used many of the phones and Os available both sandboxed and open sourced with no anti virus and haven't yet been affected on a Mobile Phone. 

That said it goes without saying that the companies involved need to be fast at plugging up such issues if even just to instill confidence into the product. 

Current Phone  >

Samsung Galaxy s²³ Ultra 512gb Phantom Black.

 

 

Not to be overly pessimistic, but now details of the vulnerabilities (including a JavaScript PoC) are in the wild you can safely bet there will be unscrupulous people working hard to exploit them (however difficult that is to achieve) and whatever related loopholes transpire. I would imagine this is just the beginning of a new class of exploits until new CPU architecture is adopted and BIOS/FW updates for related security vulnerabilities will need to become a regular norm (especially for PCs) in addition to the OS and App updates most people are already used to.

Should also be mindful (however the CPU vendors talk down the issues) that a previously assumed impenetrable separation of data is no longer the case. There aren’t many examples that set precedent for what’s been exposed with Meltdown and Spectre so far.

BTW - how many people are aware that they aren’t protected until BIOS/firmware is patched with microcode as well as the OS/App updates that have been rushed out? How many people actually know how to do that for, say, a PC? How many people know that in many cases vendors haven’t and may never provide the former (like my old Vaio laptop)?

Finger’s crossed there’s some better support from the industry coming to inform on these things before exploits come into the wild. I guess at least it is easier to push firmware updates to mobile/tablet devices IF they are provided.

I would say that for anyone on an affected device that hasn’t yet been patched (both BIOS/FW and OS as applicable), maybe it is time to install mobile anti-virus/anti-phishing as a precaution.