It's bad when a security researcher finds a critical security flaw in your software. But when he finds about 40—all of them critical?Hong Kong Archives Well, then you might consider rewriting the entire thing from scratch.
That's exactly what's happening to none other than Samsung and its Tizen operating system, which the company uses on a number of its devices, including phones, smartwatches, and smart TVs.
SEE ALSO: Say hi to Samsung Bixby, the new voice assistant in the Galaxy S8Israeli security researcher Amihai Neiderman laid out the numerous, previously unknown security flaws in Tizen in a report detailed at Kaspersky's Security Analyst Summit at St. Marteen Monday. Neiderman claims all of the holes he found are critical and would allow hackers to control a Samsung device remotely.
Some, however, are worse than others. A particularly nasty flaw would let an attacker take over the TizenStore app -- an app store for Tizen -- and hijack it to inject malicious software into a Tizen device. Since this particular app can access and change any part of the system, a malicious hacker exploiting the flaw would have absolute and total control over your Tizen device.
Neiderman, who started looking into Tizen's security after purchasing a Samsung smart TV last year, calls the Tizen code the "worst" he has "ever seen."
"You can see that nobody with any understanding of security looked at this code or wrote it."
"Everything you can do wrong there, they do it. You can see that nobody with any understanding of security looked at this code or wrote it. It's like taking an undergraduate and letting him program your software," he told Motherboard.
Neiderman claims he contacted Samsung about the security flaws months ago, but received nothing besides an automated response. However, Samsung did tellMotherboard that it's now working with Neidermanto "mitigate any potential vulnerabilities."
According to Samsung, the open-source Tizen powered 50 million Samsung devices as of Nov. 2016. These include Samsung's Gear S3 smartwatch; they also include the company's lineup of smart TVs, which recently came into focus after a WikiLeaks leak of CIA's hacking tools unearthed an exploit that enables the agency to eavesdrop on someone through a Samsung smart TV.
Samsung has big plans for Tizen; the company likely won't launch flagship phones based on the OS any time soon, but it does plan to use it on many future Internet-of-Things devices. If this report is accurate, however, it might put a big dent in those plans.
Mashablehas contacted Samsung about these security issues and we will update the post if we hear from them.
UPDATE: April 5, 2017, 8:16 a.m. CEST A Samsung spokesperson got back to us with what is possibly the blandest response ever.
"Samsung Electronics takes security and privacy very seriously. We regularly check our systems and if at any time there is a credible potential vulnerability, we act promptly to investigate and resolve the issue. We continually provide software updates to consumers to safeguard their products. We are fully committed to cooperating with Mr. Neiderman to mitigate any potential vulnerabilities," it said.
Topics Cybersecurity Samsung
Previous:Cops on Campus
Next:Dublin in My Tears
'Magic: The Gathering' Double Masters set brings back a ridiculously powerful card3 ways to stream movies and TV for free through your local libraryElon Musk announces next Tesla factory locationFox Sports will fill empty baseball stadiums with very creepy 'virtual fans'Man invents tsunami sensor, internet obsesses over his dogHBO Max's 'The Dog House' matches abandoned pets with owners: ReviewSamsung officially confirms the Galaxy Z Flip 5GGoogle to replace certain Nest thermostats that can't connect to WiWornOnTV: The charming fashion blog tracking all your favorite TV outfitsInstacart insists it's probably your fault if your account got hackedNo royal wants to be king or queen says Prince HarrySo many men resigned from Uber that it basically has gender parity in its leadership nowKelly Clarkson helps this couple propose during a meet and greetThe Atlantic Ocean is now hurricane fuel, inviting big stormsGarmin confirms massive cyber attack connected to Russian hackersRihanna DMs breakup advice to heartbroken fan and, honestly, we're pretty jealousWNBA teams walk out during anthem, dedicate season to Breonna TaylorASUS ROG 3 phone handsInstacart insists it's probably your fault if your account got hacked'Vicariously' app lets you snoop on other people's Twitter timelines Teachers are using facial recognition to see if students are paying attention Whoa. Double texting might actually get your matches to respond. TV peaked exactly 4 years ago today, with this one 'Game of Thrones' episode How an ancient methane 'blow 'ARMS' kicks ass while embracing its weirdness Walmart has employees deliver packages on their way home from work Man can't handle women 6 innovations that help artists control their environment Brave women destroy body Rihanna was the MVP of Game 1 of the NBA Finals Spelling Bee winning word gets the whole internet Googling what on earth 'marocain' is The Ambiclimate is an easy way to make your dumb air conditioner smart Puzzle time: Can you find the Caesar in the salad? Pornhub reveals the top typos people make when, um, typing with one hand Chloë Grace Moretz 'appalled' by new movie's fat Oreo releases a tasty new flavor just in time for National Doughnut Day 'League of Legends' takes a page out of pro sports with league overhaul Dad has adorable sendoff for his daughter's last day of high school Stuck subway passengers throw impromptu graduation for student missing his ceremony Lorde's 'Perfect Places' is luminous pop escapism
1.4347s , 10130.6875 kb
Copyright © 2025 Powered by 【Hong Kong Archives】,Wisdom Convergence Information Network