1. anon(9607753)'s Avatar
    Well this is interesting....

    https://www.theregister.co.uk/2017/0...allow_overlay/

    I wonder if BlackBerry will issue a patch before Google does? We shall see...
    05-10-17 02:47 PM
  2. Bla1ze's Avatar
    tl;dr: Don't install dodgy apps from 3rd party stores and understand what it is you're installing from Google Play.
    05-10-17 03:00 PM
  3. Bla1ze's Avatar
    I wonder if BlackBerry will issue a patch before Google does? We shall see...
    BlackBerry has no ability to really do so unless it's on their side of the software fence, which, it's not. It's a core Android function, which they cannot change. Even asking the question gives the impression they could... they can't.
    05-10-17 03:03 PM
  4. Ment's Avatar
    BB can't do anything as this specific permission where you don't have to change system settings is done by Google for apps thru the Playstore. I suppose they could update DTEK with apps that don't use the permission properly but Google would have removed the apps already by then and from user devices ie BB doesn't have the resources to do what Google is already doing.
    05-10-17 03:06 PM
  5. anon(9607753)'s Avatar
    tl;dr: Don't install dodgy apps from 3rd party stores and understand what it is you're installing from Google Play.
    Perhaps...but in all seriousness, is this a line we are going to use every time an Android vulnerability comes up? Whether BlackBerry does anything about it or not, which they probably won't (but who knows right?) it doesn't seem too cool that Google would sit on this until O is released, as the article alleges. I think a little heat on Google is probably justifiable. IMHO of course, lol.
    05-10-17 03:41 PM
  6. Bla1ze's Avatar
    Perhaps...but in all seriousness, is this a line we are going to use every time an Android vulnerability comes up? Whether BlackBerry does anything about it or not, which they probably won't (but who knows right?) it doesn't seem too cool that Google would sit on this until O is released, as the article alleges. I think a little heat on Google is probably justifiable. IMHO of course, lol.
    Yes, because it's the real answer. I literally have never come across a single person infected with ANY of this garbage. It's scare tactics and crap headlines. The details are almost always buried behind the fact that you need to download certain apps, or you need to have root access or you have to have physical access to the device or some other small detail that gets overpassed due to the fact that it makes it LESS of a compelling story. I'm not even sticking up for Google or BlackBerry or Android as an OS here, I'm sticking up for the fact that people should use their brains more, have some common sense and actually read beyond the freaking headline.
    05-10-17 03:43 PM
  7. meilenstein's Avatar
    Yes, because it's the real answer. I literally have never come across a single person infected with ANY of this garbage. It's scare tactics and crap headlines. The details are almost always buried behind the fact that you need to download certain apps, or you need to have root access or you have to have physical access to the device or some other small detail that gets overpassed due to the fact that it makes it LESS of a compelling story. I'm not even sticking up for Google or BlackBerry or Android as an OS here, I'm sticking up for the fact that people should use their brains more, have some common sense and actually read beyond the freaking headline.
    Don't harsh his mellow, man. Don't bring facts into this.

    Posted via CB10
    anon(2313227) likes this.
    05-10-17 03:47 PM
  8. Ment's Avatar
    Its like Ebola. Yes billions are 'vulnerable' to it so it makes headlines but the chance for any individual person is super small.

    Yes SYSTEM_ALERT_WINDOW can be abused for apps in the Playstore but your chance for exposure is so low it doesn't rate.
    05-10-17 03:47 PM
  9. meilenstein's Avatar
    Perhaps...but in all seriousness, is this a line we are going to use every time an Android vulnerability comes up? Whether BlackBerry does anything about it or not, which they probably won't (but who knows right?) it doesn't seem too cool that Google would sit on this until O is released, as the article alleges. I think a little heat on Google is probably justifiable. IMHO of course, lol.
    "Alleges." Alleges without attestation.

    Posted via CB10
    05-10-17 03:48 PM
  10. anon(9607753)'s Avatar
    Seems like a pretty touchy subject for something that is not deserving of any serious attention. Of course, it must be the same for stupid stuff like this http://m.crackberry.com/blackberry-p...urity-bulletin and only complete idiots (like me, apparently Lol) would ever install this crap on their devices.
    Attached Thumbnails PlaySl$$
Android Screen Hijack Vulnerability-16580.jpg  
    05-10-17 04:11 PM
  11. Ment's Avatar
    Don't ever go outside you'll get hit with lightning. Everything needs perspective, take note of it use common sense measures and move on.
    05-10-17 04:17 PM
  12. conite's Avatar
    it doesn't seem too cool that Google would sit on this until O is released, as the article alleges.
    Google is not sitting on it. They are now scanning for it in the App Store, and will update Google Play services on the device to look for it as well.

    Android O will simply revert to how they dealt with this permission in the past, thus removing a convenience feature which brought about unintended consequences.
    Last edited by conite; 05-10-17 at 04:30 PM.
    05-10-17 04:20 PM
  13. Bla1ze's Avatar
    Seems like a pretty touchy subject for something that is not deserving of any serious attention. Of course, it must be the same for stupid stuff like this Priv security update patches sixteen holes for safety's sake | CrackBerry.com and only complete idiots (like me, apparently Lol) would ever install this crap on their devices.
    Now you're just being dramatic.
    05-10-17 04:22 PM
  14. anon(9607753)'s Avatar
    Now you're just being dramatic.
    Geez! Its as if people think I posted this intending to raise some kind of dire apocalyptic polemic slamming Android. It was just a discussion topic! But sure everybody, let's join in and take a swing at kputock for being such a fear-mongering-alarmist-fake-news-troll.
    05-10-17 04:37 PM
  15. Bla1ze's Avatar
    Geez! Its as if people think I posted this intending to raise some kind of dire apocalyptic polemic slamming Android. It was just a discussion topic! But sure everybody, let's join in and take a swing at kputock for being such a fear-mongering-alarmist-fake-news-troll.
    PlaySl$$
Android Screen Hijack Vulnerability-e5urs0m.gif
    BigBadWulf likes this.
    05-10-17 04:45 PM
  16. anon(9607753)'s Avatar
    Mocked with cartoons on a BlackBerry forum. It doesn't get much lower than this, Lol.
    05-10-17 06:23 PM
  17. thurask's Avatar
    I'm not even sticking up for Google or BlackBerry or Android as an OS here, I'm sticking up for the fact that people should use their brains more, have some common sense and actually read beyond the freaking headline.
    But that's haaaaaaaaaard!
    05-10-17 07:06 PM
  18. Tsepz_GP's Avatar
    Yes, because it's the real answer. I literally have never come across a single person infected with ANY of this garbage. It's scare tactics and crap headlines. The details are almost always buried behind the fact that you need to download certain apps, or you need to have root access or you have to have physical access to the device or some other small detail that gets overpassed due to the fact that it makes it LESS of a compelling story. I'm not even sticking up for Google or BlackBerry or Android as an OS here, I'm sticking up for the fact that people should use their brains more, have some common sense and actually read beyond the freaking headline.
    Yep!

    I've been on Android since it's "Wild West" Days, from Android 1.6 Cupcake, when it had next to no security and we've been reading and seeing these scare tactics since then with nobody actually getting affected.
    05-10-17 09:43 PM
  19. Jerry Hildenbrand's Avatar
    I expected better from The Guardian. They left out one very important tidbit of information:

    Every app downloaded and installed from Google Play is scanned when it's installed. If the application has an odd behavior, like displaying a screen overlay with no user-visible activity or input (screen overlays are harmful because they can display transparent buttons) it won't be installed without you being notified of its questionable behavior or won't be installed at all. Then it gets removed from the store altogether. This is a feature of Play Services, so every single Android phone with access to google play is covered here.

    Apps not downloaded from a Google Play Store server require permission to draw over your screen. Read before you click yes.

    And Bla1ze is right. It's all a bit of a scam to suck you in. Writing about Android malware is sort of like writing about "the death of BlackBerry" because it's guaranteed to get people to click and keep coming back so they can fight in the comments.

    We should totally do more of it, Bla1ze. We could buy yachts with all that malware money and sail to islands where clothes are optional and drinking at 10 am is encouraged.
    howarmat and Bla1ze like this.
    05-10-17 10:23 PM
  20. DrBoomBotz's Avatar
    Mocked with cartoons on a BlackBerry forum. It doesn't get much lower than this, Lol.
    Is this what rage quit looks like?
    05-11-17 09:22 AM
  21. cribble2k's Avatar
    Why didn't anyone's DTEK software warn them about this vulnerability before it was reported?

    Thought the point was to protect against current and future threats.

    🤔
    DrBoomBotz likes this.
    05-11-17 12:18 PM
  22. conite's Avatar
    Why didn't anyone's DTEK software warn them about this vulnerability before it was reported?

    Thought the point was to protect against current and future threats.

    🤔
    DTEK monitors the integrity of the OS.

    This situation is simply an app that will display malware.
    05-11-17 01:04 PM
  23. bakron1's Avatar
    Yep!

    I've been on Android since it's "Wild West" Days, from Android 1.6 Cupcake, when it had next to no security and we've been reading and seeing these scare tactics since then with nobody actually getting affected.
    Same here, common sense, don't download third party apps and using strong passwords goes a long way.

    Most of the folks I know who get hacked use simple passwords and download to much crap off the web and open attachments they shouldn't be, just asking for trouble.

    As I have said many times, common sense goes a long way and it surprises me how many folks forget about that until it's too late.
    05-11-17 01:24 PM
  24. Tsepz_GP's Avatar
    Same here, common sense, don't download third party apps and using strong passwords goes a long way.

    Most of the folks I know who get hacked use simple passwords and download to much crap off the web and open attachments they shouldn't be, just asking for trouble.

    As I have said many times, common sense goes a long way and it surprises me how many folks forget about that until it's too late.
    Exactly!

    Funny thing, one of our colleagues has had her Skype account hacked after opening a dodgy message from a friend elsewhere who was hacked, her account sent weird messages to all in the office today. Most of us picked up on it and avoided clicking, butba few fell right into it.

    Many people lack commonsense and just click away.
    05-11-17 01:42 PM
  25. jyoule2017's Avatar
    Sense is not common btw.
    05-16-17 11:58 AM

Similar Threads

  1. KEYOne Dim Screen
    By JOHNGAETANO in forum BlackBerry KEYone
    Replies: 22
    Last Post: 05-17-17, 01:40 PM
  2. Replies: 6
    Last Post: 05-12-17, 10:13 AM
  3. Android app notifications in hub
    By irra7ional in forum BlackBerry 10 OS
    Replies: 1
    Last Post: 05-10-17, 03:23 PM
  4. What makes BlackBerry Android OS so secure?
    By MPdeH in forum BlackBerry Android OS
    Replies: 6
    Last Post: 05-10-17, 03:16 PM
  5. Priv Android update version
    By CrackBerry Question in forum Ask a Question
    Replies: 3
    Last Post: 05-10-17, 07:55 AM
LINK TO POST COPIED TO CLIPBOARD