Blueborne Fix - Samsung Galaxy S8+ Questions & Answers

So has samsung released a security update for it yet?

cantenna said:
So has samsung released a security update for it yet?
Click to expand...
Click to collapse
September patch for G8 allegedly fixes but at least one user says that a scanner still indicates unit is susceptible to Blueborne!

Garcol said:
September patch for G8 allegedly fixes but at least one user says that a scanner still indicates unit is susceptible to Blueborne!
Click to expand...
Click to collapse
Thanks forbthe news, pretty pathetic really with the timeliness turnaround, doesnt this defeat the purpose of knox security and safteynet entirely? shouldnt theses two sevices be regarded as non functional on units that are not patched? You would think so.
on linux atleast, vulnerability is two, the kernel (patching a buffer overflow) and bluZ (bluetooth software) Perhaps it is the same on andeoid and samsung just addressed one ofbthe two vulnerability invsept update.
well perhaps we can now get a new jailbreak using blueborne exploit for every non supported ios device now on the market and possibly a cydia patch to patch blueborne.

I had a chat with a Samsung Agent a little over a week ago. Attaching a screenshot that will hopefully be helpful.

Related

The Flex 2 MM 05/2016 upgrade has Stagefright vulnerabilities.

I will stick with my Nexus 5 until Flex 2 gets patched.
datanomad said:
I will stick with my Nexus 5 until Flex 2 gets patched.
Click to expand...
Click to collapse
Based on "Stagefright Detector" app, all those CVE's detected on MM are from http://source.android.com/security/bulletin/2016-06-01.html so this bulletin was "Published June 06, 2016", so 13 days ago, how could you imagine that it could be fixed by this release?
Maybe those vulns could lead to temp root somehow?
Hi,
And the same security bulletin states "Partners were notified about the issues described in the bulletin on May 02, 2016 or earlier."
Reckon LG is not a partner then Or perhaps Orange and Vodafone just decided to give it a go anyways.
datanomad said:
Hi,
And the same security bulletin states "Partners were notified about the issues described in the bulletin on May 02, 2016 or earlier."
Reckon LG is not a partner then Or perhaps Orange and Vodafone just decided to give it a go anyways.
Click to expand...
Click to collapse
Oh, haven't noticed it. There are no public exploits for these available as of now, so I guess you should not worry so much, maybe there is in black market, who knows. But nevertheless, if those will be fixed, new ones will will be found, it's constant game between developers and hackers. You can't be safe completely all the time and won't get all the latest updates all the time. I bet that there are non public exploits in the wild we just don't know about them.
why does it matter, Lollipop 15c has at least one too.
How about "Android OS" ram usage?
datanomad said:
I will stick with my Nexus 5 until Flex 2 gets patched.
Click to expand...
Click to collapse
F510x reported to have high "Android OS" ram usage...
I've heard that LG had noticed it and have some plan to fix it.

Why there so many updates for CyanogenMod rom and no or hardly any update 4 stock

hi guy wanna knw why there are so many updates on daily basis for cm 13 n hardly or no update for stock
rohanmane3 said:
hi guy wanna knw why there are so many updates on daily basis for cm 13 n hardly or no update for stock
Click to expand...
Click to collapse
CM is built nightly by auto build scripts, whether there are changes or not... Most day to changes are in the CM core and have little real effect. I recommend only updating monthly unless you are having issues.
Moto doesn't push updates except when needed, the stock rom is stable and in general doesn't need frequent updates. Moto has also made no commitment to regular security updates.
Sent from my Motorola XT1575 using XDA Labs
I'ts a shame isn't it, security patch level is 1 januari 2016
mumfordfan said:
I'ts a shame isn't it, security patch level is 1 januari 2016
Click to expand...
Click to collapse
Well, Motorola isn't Google! They didn't guarantee monthly security patches at all. At least they are offering major android upgrades, many manufacturers ignore their phones completely [emoji4]
Broadcasted from Zeta Reticuli
mumfordfan said:
I'ts a shame isn't it, security patch level is 1 januari 2016
Click to expand...
Click to collapse
And yet, I have yet to hear of a single security issues with this device...
TBH, most of these security updates are not really about technical need at all, they are about propaganda... It makes Google, and Android in general, look better, to patch any "vulnerability" in Android. All of these huge security holes like Stagefrieght, Media Server, Quadrooter, etc. are not REALLY an issue in the real world. Have you ever heard of anyone actually having a problem with any of these? No, you haven't, because there isn't a single documented case of any of these "in the wild", it's all happened in a lab.
Remember that even though we are on January 2016 update, Moto is still a leader in this area... How many other sub-$200 handsets even get updates, much less better ones than we do? Not many...
acejavelin said:
And yet, I have yet to hear of a single security issues with this device...
TBH, most of these security updates are not really about technical need at all, they are about propaganda... It makes Google, and Android in general, look better, to patch any "vulnerability" in Android. All of these huge security holes like Stagefrieght, Media Server, Quadrooter, etc. are not REALLY an issue in the real world. Have you ever heard of anyone actually having a problem with any of these? No, you haven't, because there isn't a single documented case of any of these "in the wild", it's all happened in a lab.
Remember that even though we are on January 2016 update, Moto is still a leader in this area... How many other sub-$200 handsets even get updates, much less better ones than we do? Not many...
Click to expand...
Click to collapse
If it can be done in a lab, it can be done in real life. It's important for Google to fix any security issues, and it's not just propaganda. You don't want your software that's going on billions of phones to have security issues.
But for the average person, you really don't need to worry about it, unless you're really high profile or very rich and are at risk of being targeted.
All true, Google does fix security issues the problem is most phone company's doesn't provide them to the costumers.
Fingers crossed for Nougat on the Moto G3
Someone will port it. No fear
3GotoM ym morf tneS
mumfordfan said:
All true, Google does fix security issues the problem is most phone company's doesn't provide them to the costumers.
Fingers crossed for Nougat on the Moto G3
Click to expand...
Click to collapse
We will probably get it, but G 2015 will likely be in line behind the Moto Z, G4, X Style/Pure, and X Play... Haven't heard a peep from beta testers for any device, so likely at least 3 months out still. Will probably see CM14 and other custom ROMs well before official update.
Sent from my Motorola XT1575 using XDA Labs
acejavelin said:
And yet, I have yet to hear of a single security issues with this device...
TBH, most of these security updates are not really about technical need at all, they are about propaganda... It makes Google, and Android in general, look better, to patch any "vulnerability" in Android. All of these huge security holes like Stagefrieght, Media Server, Quadrooter, etc. are not REALLY an issue in the real world. Have you ever heard of anyone actually having a problem with any of these? No, you haven't, because there isn't a single documented case of any of these "in the wild", it's all happened in a lab.
Remember that even though we are on January 2016 update, Moto is still a leader in this area... How many other sub-$200 handsets even get updates, much less better ones than we do? Not many...
Click to expand...
Click to collapse
I am curious why some versions of MotoG3 got the upgrade to 6.01 and others did not?
Is it a good assumption those who did not get 6.01 will not get any further updates unless it is 7.0?
MrTooPhone said:
I am curious why some versions of MotoG3 got the upgrade to 6.01 and others did not?
Is it a good assumption those who did not get 6.01 will not get any further updates unless it is 7.0?
Click to expand...
Click to collapse
Safe assumption... But I've seen stranger things. 6.0.1 started rolling out months ago, then just stopped with no official word as to why. Speculation is the scroll issue, where scrolls are seen as taps, got significantly worse and the roll out was stopped. Really though 6.0.0 to 6.0.1 was a very minor change.
Sent from my Motorola XT1575 using XDA Labs
acejavelin said:
Safe assumption... But I've seen stranger things. 6.0.1 started rolling out months ago, then just stopped with no official word as to why. Speculation is the scroll issue, where scrolls are seen as taps, got significantly worse and the roll out was stopped. Really though 6.0.0 to 6.0.1 was a very minor change.
Click to expand...
Click to collapse
That scroll issue was terrible, which is the main thing that got me to void my warranty and flash cm13.
Moto isn't the best anymore...
acejavelin said:
Remember that even though we are on January 2016 update, Moto is still a leader in this area... How many other sub-$200 handsets even get updates, much less better ones than we do? Not many...
Click to expand...
Click to collapse
Samsung is on the July 2016 update with the sub-$200 X Cover 3.
I am not a Samsung fanboy at all.
I really don't like all the fluff they add to Android and why they see the need to overhaul the settings.
But having Samsung best Motorola at keeping their sub-$200 handsets up-to-date makes me doubt that my next phone will be a Moto.
Which is a shame, I think...
--
Hans
hbogaards said:
Samsung is on the July 2016 update with the sub-$200 X Cover 3.
I am not a Samsung fanboy at all.
I really don't like all the fluff they add to Android and why they see the need to overhaul the settings.
But having Samsung best Motorola at keeping their sub-$200 handsets up-to-date makes me doubt that my next phone will be a Moto.
Which is a shame, I think...
--
Hans
Click to expand...
Click to collapse
Ehh... I can see that. I would still never own another Sammy, but I would take another Moto. Besides, I usually only run mine stock for about 3 months then ROM them once a few become stable.
Sent from my Motorola XT1575 using XDA Labs
acejavelin said:
Ehh... I can see that. I would still never own another Sammy, but I would take another Moto.
Sent from my Motorola XT1575 using XDA Labs
Click to expand...
Click to collapse
Me too. I can even tolerate an iPhone to a Samsung. Its good for sammy if they give updates, I agree on that.
Broadcasted from Zeta Reticuli

May Security Update but not 8.1

According to miui forum page, it says that the May security update did not come with 8.1. ?
Source ; https://c.mi.com/thread-1059592-1-0.html
ozgurubuntu said:
According to miui forum page, it says that the May security update did not come with 8.1. ?
Source ; https://c.mi.com/thread-1059592-1-0.html
Click to expand...
Click to collapse
Yes, it's true.
They took almost one month for an 80 MB update, and today, 20 May, it's not released for all users but only for a bit of them.
It's really...normal .
Enjoy your update
So what?
Xiaomi is cheating on us. This is really bullsh*t, it is Android One phone and should get NEWEST android ASAP. Im starting to hate Xiaomi.
TrueMS said:
Xiaomi is cheating on us. This is really bullsh*t, it is Android One phone and should get NEWEST android ASAP. Im starting to hate Xiaomi.
Click to expand...
Click to collapse
It is no crap, unless you show me a contract you signed in which it says they have to Release it in x months after it is publicly available.
Or show me a device starting with nougat which already has it.
Other than that people would complain if it has bugs. With Samsung, the note 8 hasn't even got 8.0 yet because it is too buggy.
So basically your post is bulls*** as we almost always get our security updates in the same month. Galaxy s9 is still on February afaik. Besides that 8.1 is still Oreo and not really worth that much anyway. Then again if it helps yourself with whining keep going but don't annoy others with it
Well it is kinda the point of Andoid One to always be up to date. Without all the manufacturer crap this should really be faster.
lolmensch said:
It is no crap, unless you show me a contract you signed in which it says they have to Release it in x months after it is publicly available.
Or show me a device starting with nougat which already has it.
Other than that people would complain if it has bugs. With Samsung, the note 8 hasn't even got 8.0 yet because it is too buggy.
So basically your post is bulls*** as we almost always get our security updates in the same month. Galaxy s9 is still on February afaik. Besides that 8.1 is still Oreo and not really worth that much anyway. Then again if it helps yourself with whining keep going but don't annoy others with it
Click to expand...
Click to collapse
S9+ currently at April security update, Android 8.0.0. Still no signs of May update & 8.1 too. ?
TrueMS said:
Xiaomi is cheating on us. This is really bullsh*t, it is Android One phone and should get NEWEST android ASAP. Im starting to hate Xiaomi.
Click to expand...
Click to collapse
+1
---------- Post added at 06:29 AM ---------- Previous post was at 06:28 AM ----------
LouisMuruu said:
S9+ currently at April security update, Android 8.0.0. Still no signs of May update & 8.1 too.
Click to expand...
Click to collapse
Is not an android one phone
The late updates have been going on five months now. How come you're still using your phones? Sell it and get something else ?
dancress said:
Well it is kinda the point of Andoid One to always be up to date. Without all the manufacturer crap this should really be faster.
Click to expand...
Click to collapse
Itemt said:
+1
---------- Post added at 06:29 AM ---------- Previous post was at 06:28 AM ----------
Is not an android one phone
Click to expand...
Click to collapse
Nope.
The point of Android One is to have an android version closer to the specifications of Google, meaning zero or very little customization from the manufacturer.
Has nothing to do with updates. If you want updates, buy a Pixel.
Most devices are abandoned even before they are available to buy, and you complain because you have May update in... May?
What are you going to do with 8.1 that's so important? Besides, it's coming! We already have a beta for it. So what's the big deal?
Go buy a Motorola phone and enjoy 0 updates.
bornlivedie said:
Nope.
The point of Android One is to have an android version closer to the specifications of Google, meaning zero or very little customization from the manufacturer.
Has nothing to do with updates. If you want updates, buy a Pixel.
Most devices are abandoned even before they are available to buy, and you complain because you have May update in... May?
What are you going to do with 8.1 that's so important? Besides, it's coming! We already have a beta for it. So what's the big deal?
Go buy a Motorola phone and enjoy 0 updates.
Click to expand...
Click to collapse
Each update that comes just changes Build No. And security patch date, you can't feel any changes expect that. Whats the point of such updates, they Fu*king just don't release a changelog, so only they the the changes they did.
I had moto G3, it had got 6.0.1 and got security patch till April 17, i don't know which Moto phone you are talking about.
lolmensch said:
It is no crap, unless you show me a contract you signed in which it says they have to Release it in x months after it is publicly available.
Or show me a device starting with nougat which already has it.
Other than that people would complain if it has bugs. With Samsung, the note 8 hasn't even got 8.0 yet because it is too buggy.
So basically your post is bulls*** as we almost always get our security updates in the same month. Galaxy s9 is still on February afaik. Besides that 8.1 is still Oreo and not really worth that much anyway. Then again if it helps yourself with whining keep going but don't annoy others with it
Click to expand...
Click to collapse
Fully agree with you, bro.
Ritik99 said:
Each update that comes just changes Build No. And security patch date, you can't feel any changes expect that. Whats the point of such updates, they Fu*king just don't release a changelog, so only they the the changes they did.
I had moto G3, it had got 6.0.1 and got security patch till April 17, i don't know which Moto phone you are talking about.
Click to expand...
Click to collapse
What should they do? It is a monthly security patch update... Seems like u want a new version of Android every month...
faffu41 said:
What should they do? It is a monthly security patch update... Seems like u want a new version of Android every month...
Click to expand...
Click to collapse
Nope, i didn't mean that. Their are few bugs left you can find them on Forum,but they don't fix them first, secondly they adda new bugs, like the charging time has increased after April Patch by atleast 30-40 mins. Xiaomi just fails when it comes to answer question relating to updates ,features and anything, they just don't reply to them, with even a simple NO.
If any of you went to android one program webpage and actually read of it, there wouldn't be any stupid discussions.
It should have 8.1 few months ago already. Meanwhile were getting stupid security patches and nothing else.
Ritik99 said:
Nope, i didn't mean that. Their are few bugs left you can find them on Forum,but they don't fix them first, secondly they adda new bugs, like the charging time has increased after April Patch by atleast 30-40 mins. Xiaomi just fails when it comes to answer question relating to updates ,features and anything, they just don't reply to them, with even a simple NO.
Click to expand...
Click to collapse
About the charging time, I fail to see how an update could do that, or they changed something in the kernel (which I highly doubt). Seems to me like a hardware matter
Agreed.
ГАСООП said:
If any of you went to android one program webpage and actually read of it, there wouldn't be any stupid discussions.
It should have 8.1 few months ago already. Meanwhile were getting stupid security patches and nothing else.
Click to expand...
Click to collapse
The security patches are also legit or not thats big question. Who know's we possibly are getting updates with build number changed only?
You want fast updates? Buy a Pixel!
Xiaomi is known for it´s great specs/ price relation but it´s terrible in the update department, this varying given model x or y. As for our Mi A1, yes, updates are a little slow but still on time .
Ritik99 said:
Each update that comes just changes Build No. And security patch date, you can't feel any changes expect that. Whats the point of such updates, they Fu*king just don't release a changelog, so only they the the changes they did.
I had moto G3, it had got 6.0.1 and got security patch till April 17, i don't know which Moto phone you are talking about.
Click to expand...
Click to collapse
I had a Moto G³ too. I've always used custom ROMs with it. It was amazing but stock really sucked.
Xiaomi has the worst community in the world, no doubt.
Anyway, seems like the pre-oreo update, less than 100mb and after 3/4 days Oreo was released.

Widevine L1 coming in Q4, first to be enabled in MiUI beta

It seems that Xiaomi is planning to soon release an update which will bring the widevine L1 support to POCO F1. The update is expected to be rolled out to MIUI Beta ROM users first by Q4, 2018, i.e. by the end of this month.
The company had recently released an update to fix the notification icon issue on the status bar. It is also developing 4K 60fps support for the rear camera. Additionally, users of POCO launcher will also have an option to customise desktop grid size and icon size in the future.
Click to expand...
Click to collapse
https://www.gizmochina.com/2018/10/23/poco-f1-widevine-l1-support/
https://en.miui.com/thread-4272498-1-1.html
As announced on Oct-23-2018
josinpaul said:
https://www.gizmochina.com/2018/10/23/poco-f1-widevine-l1-support/
https://en.miui.com/thread-4272498-1-1.html
As announced on Oct-23-2018
Click to expand...
Click to collapse
What they actually said is
Still developing with Google and Qualcomm, will try to release the Beta within Q4 .
Within Q4 could be any point up to the end of December
fards said:
What they actually said is
Still developing with Google and Qualcomm, will try to release the Beta within Q4 .
Within Q4 could be any point up to the end of December
Click to expand...
Click to collapse
And it will comes on first January release.
Yeah. At least they released it.
Sent from my POCOPHONE F1 using Tapatalk
They hope to release the fix in Q4, it means they can do it via an ota update. So the secure key is already present in our system unless they could not have said so. That's a positive thing.
josinpaul said:
They hope to release the fix in Q4, it means they can do it via an ota update. So the secure key is already present in our system unless they could not have said so. That's a positive thing.
Click to expand...
Click to collapse
The key is probably not present in the device, because according to their statements, they don't even know about Widevine and since the phone is available in China, and most Chinese manufacturer don't care about VoD services, so forget about OTA. If it would be the case above, then it would've been solved already.
They are just stalling it, just like they stalled the multitouch issue.
shailendra1993 said:
The key is probably not present in the device, because according to their statements, they don't even know about Widevine and since the phone is available in China, and most Chinese manufacturer don't care about VoD services, so forget about OTA. If it would be the case above, then it would've been solved already.
They are just stalling it, just like they stalled the multitouch issue.
Click to expand...
Click to collapse
" Still developing with Google and Qualcomm, will try to release the Beta within Q4"
Click to expand...
Click to collapse
this is the statement made in their official miui forum. if they dont want to fix it they could have kept mum. You can see their approach with multi touch issue, they are not even admitting such an issue exists. Lets wait and see.:angel:
josinpaul said:
this is the statement made in their official miui forum. if they dont want to fix it they could have kept mum. You can see their approach with multi touch issue, they are not even admitting such an issue exists. Lets wait and see.:angel:
Click to expand...
Click to collapse
So, WideVine L1 cert can be enabled using a software patch? Got this from OnePlus forum "Xperia XZ2 already ships from factory with the required device-unique secret key in the TrustZone for Widevine L1 support, and their stock firmware plays HD content just fine. It was only the Android P Developer Preview builds that hadn't L1 support enabled on software-side before Beta 3 build. OnePlus 5T on the other hand ships without the required secret key in the TrustZone, and that's something that can't be "fixed" with an OTA update, that's why you have to send your phone to them if you want L1 support." So, is that true that's Pocophone F1 has already got secret key in their TrustZone? Or they're finding a way to send them via an OTA software update?
maXDAmn said:
So, WideVine L1 cert can be enabled using a software patch? Got this from OnePlus forum "Xperia XZ2 already ships from factory with the required device-unique secret key in the TrustZone for Widevine L1 support, and their stock firmware plays HD content just fine. It was only the Android P Developer Preview builds that hadn't L1 support enabled on software-side before Beta 3 build. OnePlus 5T on the other hand ships without the required secret key in the TrustZone, and that's something that can't be "fixed" with an OTA update, that's why you have to send your phone to them if you want L1 support." So, is that true that's Pocophone F1 has already got secret key in their TrustZone? Or they're finding a way to send them via an OTA software update?
Click to expand...
Click to collapse
I think that the trustzone can be reflashed if the efuse hasn't triggered to prevent re-flashing of that partition.

Question No security updates since upgrading to Android 13

Just curious has anyone received security updates since upgrading? Here it is the middle of Dec no update yet.. I have Factory unlock, and usually have a update within the first week.
On my unlocked S22 Ultra, I went from the Android 13 One UI beta 5 to the stable release on October 25th and I received a security update on November 21st. My cellular provider is Google Fi.
I got the Nov security update on Nov 15, just checked and Dec is not available for me yet.
S22U, VZW, US.
Go t the Dec 1 update 3 days ago.
In my case I'm still on November 1st security update.....S22U carrier unlocked in Argentina. I understand that main software updates can depend on carrier agreements, but the security patch?? I fail to see why some of the S22u users would get a december patch and others no....
Still on July's update here.. lol
Marcelocohenarg said:
In my case I'm still on November 1st security update.....S22U carrier unlocked in Argentina. I understand that main software updates can depend on carrier agreements, but the security patch?? I fail to see why some of the S22u users would get a december patch and others no....
Click to expand...
Click to collapse
Ya I think it is a carrier agreement thing.. It should not have anything do with being carrier specific. Security is security. But if money talks, then that is probably how it goes.
PapaDocta said:
Still on July's update here.. lol
Click to expand...
Click to collapse
That's real sad.
Got the December patch a couple of weeks ago. My daughter's unlocked S22 got it last week.
Android security patch level it's December 1st 2022, and that should be available for most of S22s running Android 13. However the Play System updates it's outdated for a number of users and shows 1st of July (especially for the ones that factory reset when going to Android 13).
dec 1 patch, canadian carrier bell mobile here
kraven001 said:
Android security patch level it's December 1st 2022, and that should be available for most of S22s running Android 13. However the Play System updates it's outdated for a number of users and shows 1st of July (especially for the ones that factory reset when going to Android 13).
Click to expand...
Click to collapse
Exactly..
Do we know the reason for that? How can we manually update?
sardelisp said:
Exactly..
Do we know the reason for that? How can we manually update?
Click to expand...
Click to collapse
As of now there are only theories that it's Google's servers that are not providing us with updates.
Others think that Samsung is to blame.
There is no clear route for manual update, the "solution" on the internet with the module components apk seems to be only a cosmetic fix (doesn't actually install the updates).
kraven001 said:
Android security patch level it's December 1st 2022, and that should be available for most of S22s running Android 13. However the Play System updates it's outdated for a number of users and shows 1st of July (especially for the ones that factory reset when going to Android 13).
Click to expand...
Click to collapse
There is another discussion thread about this. This is not just a S22 series problem. My Tab S7 was stuck on the September 1 update.
cant update google play system
i saw many articles about this iisue but nothing help im on the snapdragon model and on the latest formware 1 december but still im on 7 jully google play service update and when i check for update it say its up to date what can i do any help thx?
forum.xda-developers.com
There are multiple theories, some Android 13/OneUI 5 related, but this has been an on and off problem prior to Android 13 being released. I've found articles and forums that go back to 2020 and earlier.
Your Galaxy device may be stuck on the July 2022 Play system update
The Android OS and monthly security patches aren't the only updates that your device gets. Play system updates are also ...
www.sammobile.com
How to Fix Google Play Services Won’t Update Issue
Fed up of the ‘Google Play Services has stopped or won’t update’ error? Here’s how to fix it and update the Google Play Services on Android.
www.guidingtech.com
I have same problem, but after updated manually with "Main components.apk", Google Play System updated to November 1 2022 patch.
Got the play system update today, jumping from July to November.
Hi, there is another thread for the Google Play System update. In my case now I'm on November 1st both in Google Play System and in security patch. But the two were misaligned before, so I understand that they are separate processes. So, as for Security, are you also in November patch?
kraven001 said:
Got the play system update today, jumping from July to November.
Click to expand...
Click to collapse
Me too ...very well

Categories

Resources