Archive for October, 2016

Ouch

Friday, October 28th, 2016

Sept 2016:

Talking about MMS:
“In Android Nougat, we’ve both hardened and re-architected mediaserver, one of the main system services that processes untrusted input. First, by incorporating integer overflow sanitization, part of Clang’s UndefinedBehaviorSanitizer, we prevent an entire class of vulnerabilities, which comprise the majority of reported libstagefright bugs. As soon as an integer overflow is detected, we shut down the process so an attack is stopped,” Xiaowen Xin of the Android security team said.

Oct 2016:

“The Tencent Keen Security Lab Team from China has won a total prize money of $215,000 in the 2016 Mobile Pwn2Own contest run by Trend Micro’s Zero Day Initiative (ZDI) in Tokyo, Japan.”

…by sending an MMS message to a fully patched Google Nexus 6P (no user interaction required) 🙁 Well, at least the code didn’t go public yet and Google will probably fix it as soon as possible.

Like father, like son

Friday, October 28th, 2016

Having the same Footlocker exclusive Nike model for a good chuck of 2 decades (obviously, a new color everytime, starting with gold/greenish, going through several blue-ish shades with light blue, with red streaks, and black variants), they now have this model in kid sizes too. Another 2 decades to follow…?

20161026_131358