{"id":1532,"date":"2015-08-16T11:52:33","date_gmt":"2015-08-16T16:52:33","guid":{"rendered":"https:\/\/sodpit.com\/?p=1532"},"modified":"2017-12-23T02:03:06","modified_gmt":"2017-12-23T08:03:06","slug":"stagefright-the-end","status":"publish","type":"post","link":"https:\/\/sodpit.com\/?p=1532","title":{"rendered":"Stagefright&#8230; The End?"},"content":{"rendered":"<p><a href=\"https:\/\/sodpit.com\/wp-content\/uploads\/2015\/07\/stagefright_v2_breakdown-e1438001259526-1024x266.jpg\"><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"1510\" data-permalink=\"https:\/\/sodpit.com\/?attachment_id=1510\" data-orig-file=\"https:\/\/sodpit.com\/wp-content\/uploads\/2015\/07\/stagefright_v2_breakdown-e1438001259526-1024x266.jpg\" data-orig-size=\"604,404\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"stagefright_v2_breakdown-e1438001259526-1024&amp;#215;266.jpg\" data-image-description=\"\" data-image-caption=\"\" data-medium-file=\"https:\/\/sodpit.com\/wp-content\/uploads\/2015\/07\/stagefright_v2_breakdown-e1438001259526-1024x266-300x201.jpg\" data-large-file=\"https:\/\/sodpit.com\/wp-content\/uploads\/2015\/07\/stagefright_v2_breakdown-e1438001259526-1024x266.jpg\" class=\"alignnone size-full wp-image-1510\" src=\"https:\/\/sodpit.com\/wp-content\/uploads\/2015\/07\/stagefright_v2_breakdown-e1438001259526-1024x266.jpg\" alt=\"stagefright_v2_breakdown-e1438001259526-1024x266.jpg\" width=\"604\" height=\"404\" srcset=\"https:\/\/sodpit.com\/wp-content\/uploads\/2015\/07\/stagefright_v2_breakdown-e1438001259526-1024x266.jpg 604w, https:\/\/sodpit.com\/wp-content\/uploads\/2015\/07\/stagefright_v2_breakdown-e1438001259526-1024x266-300x201.jpg 300w\" sizes=\"auto, (max-width: 604px) 100vw, 604px\" \/><\/a><\/p>\n<p>I&#8217;m hoping this will be my final post on the Stagefright Hack\/Bug.<\/p>\n<p><!--more--><\/p>\n<p><strong>Update<\/strong><\/p>\n<p>Zimperium Inc. updated their\u00a0<a href=\"https:\/\/play.google.com\/store\/apps\/details?id=com.zimperium.stagefrightdetector\" target=\"_blank\" rel=\"noopener noreferrer\">Stagefright Detector App<\/a>\u00a0for Android. You should make sure to keep this app updated and occasionally check your device to see if any recent upgrades for your operating system might have fixed this problem.<\/p>\n<p>So <a style=\"text-decoration: none;\" href=\"http:\/\/elitist-gaming.com\/lol\/elo-boost\/\"><span style=\"text-decoration: none; color: #000000;\">check this out<\/span><\/a>, if your device is patched then you can whichever\u00a0messaging app you like best and you can re-enable the auto-retrieve setting for MMS messages.<\/p>\n<p><strong>New Mitigation Method&#8230; Much Better!<\/strong><\/p>\n<p>In previous posts\u00a0I mentioned disabling the auto-retrieve setting for MMS messages. This is somewhat effective but overwhelmingly annoying, especially for users who receive a lot of group or picture messages. I&#8217;m tired of having to tap &#8220;Download&#8221; 20 times a day.<\/p>\n<p>I have recently found two third-party SMS\/MMS applications that either don&#8217;t use the Stagefright engine or are somehow protected from the Stagefright exploit.<\/p>\n<p>If your phone hasn&#8217;t been upgraded to a proven SAFE\u00a0version that has the patched Stagefright engine I strongly recommend installing and using either of these as your primary messaging app:<\/p>\n<p>Textra SMS <a href=\"https:\/\/play.google.com\/store\/apps\/details?id=com.textra\" target=\"_blank\" rel=\"noopener noreferrer\">Android App<\/a> (free but offers in-app purchases) \/\u00a0<a href=\"http:\/\/www.textra.me\/\" target=\"_blank\" rel=\"noopener noreferrer\">Textra SMS Website<\/a><\/p>\n<p>QKSMS Quick Text Messenger <a href=\"https:\/\/play.google.com\/store\/apps\/details?id=com.moez.QKSMS\" target=\"_blank\" rel=\"noopener noreferrer\">Android App<\/a> (free but offers in-app purchases) \/\u00a0<a href=\"https:\/\/plus.google.com\/communities\/104505769539048913485\" target=\"_blank\" rel=\"noopener noreferrer\">QKSMS Google+ Community<\/a><\/p>\n<p>I have tested and use both interchangeably. They are both decent and effective and I no longer have to click a stupid download button.<\/p>\n<p>There might be other SMS\/MMS solutions out there that protect you from the Stagefright problem, these are just a few suggestions that I know work. If you find any, let me know!<\/p>\n<p><strong>Stagefright Patch Status<\/strong><\/p>\n<p>I have created a spreadsheet (not intended to be exhaustive by any means) which shows the current status of some phones that are patched (or not):\u00a0<a href=\"https:\/\/docs.google.com\/spreadsheets\/d\/1-u4_e2YJw43F7LPs5-2so1pOOS4VMiUcb1iWyqwwhu4\/edit#gid=0\" target=\"_blank\" rel=\"noopener noreferrer\">Stagefright Patch Status<\/a>.<\/p>\n<p>Another tab on this spreadsheet\u00a0shows a comparison between Apple iOS and Google Android for\u00a0Common Vulnerabilities And Exposures (CVEs): <a href=\"https:\/\/docs.google.com\/spreadsheets\/d\/1-u4_e2YJw43F7LPs5-2so1pOOS4VMiUcb1iWyqwwhu4\/edit#gid=498931562\" target=\"_blank\" rel=\"noopener noreferrer\">CVE:\u00a0Apple iOS vs. Google Android<\/a>.<\/p>\n<p><a href=\"https:\/\/sodpit.com\/wp-content\/uploads\/2015\/08\/stagefright_2015-08-12_083545.png\"><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"1533\" data-permalink=\"https:\/\/sodpit.com\/?attachment_id=1533\" data-orig-file=\"https:\/\/sodpit.com\/wp-content\/uploads\/2015\/08\/stagefright_2015-08-12_083545.png\" data-orig-size=\"1398,290\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"stagefright_2015-08-12_083545\" data-image-description=\"\" data-image-caption=\"\" data-medium-file=\"https:\/\/sodpit.com\/wp-content\/uploads\/2015\/08\/stagefright_2015-08-12_083545-300x62.png\" data-large-file=\"https:\/\/sodpit.com\/wp-content\/uploads\/2015\/08\/stagefright_2015-08-12_083545-1024x212.png\" class=\"alignnone wp-image-1533\" src=\"https:\/\/sodpit.com\/wp-content\/uploads\/2015\/08\/stagefright_2015-08-12_083545.png\" alt=\"\" width=\"609\" height=\"126\" srcset=\"https:\/\/sodpit.com\/wp-content\/uploads\/2015\/08\/stagefright_2015-08-12_083545.png 1398w, https:\/\/sodpit.com\/wp-content\/uploads\/2015\/08\/stagefright_2015-08-12_083545-300x62.png 300w, https:\/\/sodpit.com\/wp-content\/uploads\/2015\/08\/stagefright_2015-08-12_083545-1024x212.png 1024w, https:\/\/sodpit.com\/wp-content\/uploads\/2015\/08\/stagefright_2015-08-12_083545-900x187.png 900w\" sizes=\"auto, (max-width: 609px) 100vw, 609px\" \/><\/a><\/p>\n<p>The summary is that there are 10 times as many vulnerabilities in iOS and most of them were more severe than the Android exploits.\u00a0<a href=\"http:\/\/www.cvedetails.com\/product\/15556\/Apple-Iphone-Os.html?vendor_id=49\" target=\"_blank\" rel=\"noopener noreferrer\">Apple iOS had 537 CVEs from 2007 to 2015<\/a>.\u00a0<a href=\"http:\/\/www.cvedetails.com\/product\/19997\/Google-Android.html?vendor_id=1224\" target=\"_blank\" rel=\"noopener noreferrer\">Google Android had 54 CVEs from 2009 to 2015<\/a>.<\/p>\n<p>Recently an (supposed)\u00a0<a href=\"http:\/\/motherboard.vice.com\/read\/goodbye-android\" target=\"_blank\" rel=\"noopener noreferrer\">Android fan told the world he was finally saying goodbye to Android and switching to an iPhone<\/a>, a hasty decision in my opinion. As the CVE comparison above shows, even though\u00a0Apple might currently be the quickest to patch problems, they are still 10 times more likely to wind up with\u00a0problems in the first place &#8211; and subsequently they are more vulnerable to attacks; most of which are also much more severe.<\/p>\n<p>In closing, the Stagefright Bug really bothered me and it still does&#8230; but in my opinion there are no safer or better solutions than Android right now.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>I&#8217;m hoping this will be my final post on the Stagefright Hack\/Bug.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":true,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","enabled":false},"version":2}},"categories":[4],"tags":[],"class_list":["post-1532","post","type-post","status-publish","format-standard","hentry","category-main"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p2FmUa-oI","jetpack_likes_enabled":false,"_links":{"self":[{"href":"https:\/\/sodpit.com\/index.php?rest_route=\/wp\/v2\/posts\/1532","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/sodpit.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/sodpit.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/sodpit.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/sodpit.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1532"}],"version-history":[{"count":3,"href":"https:\/\/sodpit.com\/index.php?rest_route=\/wp\/v2\/posts\/1532\/revisions"}],"predecessor-version":[{"id":1598,"href":"https:\/\/sodpit.com\/index.php?rest_route=\/wp\/v2\/posts\/1532\/revisions\/1598"}],"wp:attachment":[{"href":"https:\/\/sodpit.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1532"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/sodpit.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1532"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/sodpit.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1532"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}