<?xml version="1.0" encoding="utf-8" ?>
<rss version="2.0" xmlns:osnews="http://www.osnews.com/rss2#">
	<channel>
		<title>OSNews: </title>
		<link>http://www.osnews.com/story/26403/TouchWiz_exploit_factory_resets_some_Samsung_phones</link>
		<description>Exploring the Future of Computing</description>
		<language>en-us</language>
		<copyright>Copyright 2001-2013, David Adams</copyright>
		<webMaster>adam+nospam@osnews.com</webMaster>
		<lastBuildDate>Thu, 20 Jun 2013 06:30:25 GMT</lastBuildDate>
		<image>
			<url>http://www.osnews.com/images/osnews.gif</url>
			<title>OSNews.com</title>
			<link>http://www.osnews.com</link>
		</image>
		<item>
			<title>Eh... How come you are buying an iMac at this time?</title>
			<link>http://www.osnews.com/thread?536467</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?536467</guid>
			<description>When a refresh is expected soon...</description>
			<pubDate>Tue, 25 Sep 2012 21:24:00 GMT</pubDate>
			<author>donotreply@osnews.com (someone)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE: Eh... How come you are buying an iMac at this time?</title>
			<link>http://www.osnews.com/thread?536468</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?536468</guid>
			<description>1) I need it now (work depends on it).<br />
2) no early adopter issues.<br />
3) those new ones can easily be 4-5-6 weeks away for Dutch folk. Can't go that long without income.<br />
4) there's always something new right around the corner. I don't live my life based on that.<br />
<br />
Yes, I had three computers die in a few months' time.</description>
			<pubDate>Tue, 25 Sep 2012 21:28:00 GMT</pubDate>
			<author>donotreply@osnews.com (Thom_Holwerda)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>Another, simpler solution</title>
			<link>http://www.osnews.com/thread?536469</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?536469</guid>
			<description>Just use another browser. I've personally been using Opera for years and I see no reason whatsoever to switch. Especially so since I can't use CyanogenMod.</description>
			<pubDate>Tue, 25 Sep 2012 21:36:00 GMT</pubDate>
			<author>donotreply@osnews.com (WereCatf)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE: Another, simpler solution</title>
			<link>http://www.osnews.com/thread?536470</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?536470</guid>
			<description><div class="cquote">Just use another browser. I've personally been using Opera for years and I see no reason whatsoever to switch. Especially so since I can't use CyanogenMod. </div><br />
<br />
? <br />
<br />
The same goes for QR scans and NFC â" Samsungâs TouchWiz UI makes the dialer automatically execute the sequence, which can potentially force a factory reset code onto your unsuspecting phone, and wipe your data.<br />
<br />
It's not browser based..<br />
<br />
This sucks because regular users have no clue how to use a ROM and almost no one buys nexus phones, Samsung barely markets theirs.</description>
			<pubDate>Tue, 25 Sep 2012 21:45:00 GMT</pubDate>
			<author>donotreply@osnews.com (Windows Sucks)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE: Another, simpler solution</title>
			<link>http://www.osnews.com/thread?536471</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?536471</guid>
			<description><div class="cquote">Just use another browser. </div><br />
In this case, I don't think another browser would help. If I understand the exploit correctly, Samsung's modified dialer is the issue here, not the browser itself. In other words, unless your browser does not do phone number detection (which will pass phone numbers to the dialer when clicked) then you can be hit by this no matter which browser you are using. There's no safety for this one if you're using one of these, except plain old common sense. The old rule still holds: If you suspect a malicious link, don't click it.</description>
			<pubDate>Tue, 25 Sep 2012 21:49:00 GMT</pubDate>
			<author>donotreply@osnews.com (darknexus)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[2]: Another, simpler solution</title>
			<link>http://www.osnews.com/thread?536472</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?536472</guid>
			<description><div class="cquote">This sucks because regular users have no clue how to use a ROM and almost no one buys nexus phones, Samsung barely markets theirs. </div><br />
Yeah, and we all know just how amazing Samsung is at providing security updates for their Android phones.</description>
			<pubDate>Tue, 25 Sep 2012 21:53:00 GMT</pubDate>
			<author>donotreply@osnews.com (darknexus)</author>
			<category>Comments</category>
		</item>

		<item>
			<title> Touch Wiz must die</title>
			<link>http://www.osnews.com/thread?536473</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?536473</guid>
			<description>I recently bought a Samsung 7.7 Tab. I have a Galaxy Phone as well, which I rooted and put a custom ROM on long ago. I forgot   how misarable and downright shitty Touchwiz is. It adds *nothing* to stock Android. Id be willing top pay 10 euro s more for a clean device  so I would nt have the hassle of flashing and so on, to take off the unneeded bloat that.s called TouchWiz</description>
			<pubDate>Tue, 25 Sep 2012 22:00:00 GMT</pubDate>
			<author>donotreply@osnews.com (PieterGen)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[3]: Another, simpler solution</title>
			<link>http://www.osnews.com/thread?536474</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?536474</guid>
			<description>Indeed...</description>
			<pubDate>Tue, 25 Sep 2012 22:01:00 GMT</pubDate>
			<author>donotreply@osnews.com (PieterGen)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[3]: Another, simpler solution</title>
			<link>http://www.osnews.com/thread?536475</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?536475</guid>
			<description><div class="cquote">[q]Yeah, and we all know just how amazing Samsung is at providing security updates for their Android phones.  </div><br />
<br />
Or any updates for that matter.</description>
			<pubDate>Tue, 25 Sep 2012 22:32:00 GMT</pubDate>
			<author>donotreply@osnews.com (Windows Sucks)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>Comment by some1</title>
			<link>http://www.osnews.com/thread?536481</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?536481</guid>
			<description>There are a lot of conflicting reports on this. From this Google's commit:<br />
<a href="https://android.googlesource.com/platform/packages/apps/Contacts/+/39948dc7e34dc2041b801058dada28fedb80c388" rel="nofollow">https://android.googlesource.com/platform/packages/apps/Contacts/+/3...</a><br />
it seems like this was a stock Android dialer bug that was fixed in June. This is consistent with the claim here: <a href="http://securitywatch.pcmag.com/none/303097-dirty-ussd-hack-wipes-samsung-phones-is-yours-vulnerable" rel="nofollow">http://securitywatch.pcmag.com/none/303097-dirty-ussd-hack-wipes-sa...</a><br />
that it was reported to Samsung and Google in June.<br />
There are reports that this fix was shipped in 4.0.4 and 4.1 stock builds and Samsung pushed OTA updates where it could. Of course, those using carrier-provided ROMs can be out of luck.</description>
			<pubDate>Wed, 26 Sep 2012 00:34:00 GMT</pubDate>
			<author>donotreply@osnews.com (some1)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE:  Touch Wiz must die</title>
			<link>http://www.osnews.com/thread?536485</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?536485</guid>
			<description>Speaking of Touch Wiz, instead of this exploit wiping the entire phone, it's too bad it just doesn't wipe Touch Wiz off the device. Then they could charge money for the service <img src="/images/emo/smile.gif" alt=";)" />  hehe</description>
			<pubDate>Wed, 26 Sep 2012 01:15:00 GMT</pubDate>
			<author>donotreply@osnews.com (WorknMan)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[2]: Eh... How come you are buying an iMac at this time?</title>
			<link>http://www.osnews.com/thread?536498</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?536498</guid>
			<description>How about buying computers you can easily repair yourself? (makes sense when your work depends on it IMO)</description>
			<pubDate>Wed, 26 Sep 2012 05:11:00 GMT</pubDate>
			<author>donotreply@osnews.com (kragil)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[2]: Eh... How come you are buying an iMac at this time?</title>
			<link>http://www.osnews.com/thread?536506</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?536506</guid>
			<description>And, out of curiosity too, why switch back to Mac now ? Considering Apple's recent actions, it doesn't sound like the perfect timing to reward them with money.</description>
			<pubDate>Wed, 26 Sep 2012 06:41:00 GMT</pubDate>
			<author>donotreply@osnews.com (Neolander)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>Not only Samsung, and not related to TouchWizz *at all*</title>
			<link>http://www.osnews.com/thread?536510</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?536510</guid>
			<description>The root bug is in the stock Android Dialer app, and was fixed in 4.0.4. An hotfix patch was pushed toward custom ROMs makers, but it seems that phone markers were more busy polishing their custom look &amp; feel than fixing venulverality holes.<br />
<br />
Meanwhile, install and make it default TEL handler this proxy dialer quickly hacked by XDA developers last night:<br />
<br />
<a href="https://play.google.com/store/apps/details?id=org.mulliner.telstop" rel="nofollow">https://play.google.com/store/apps/details?id=org.mulliner.telstop</a></description>
			<pubDate>Wed, 26 Sep 2012 07:49:00 GMT</pubDate>
			<author>donotreply@osnews.com (phoudoin)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE: Comment by some1</title>
			<link>http://www.osnews.com/thread?536511</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?536511</guid>
			<description>Indeed, the issue is most carrier-subsidized phones with custom ROM don't support them as they should, allowing such hole to be unfixed for months.<br />
<br />
Unfortunatly, considering the price of a smartphone, many owners get a carrier-subsidized one...</description>
			<pubDate>Wed, 26 Sep 2012 07:56:00 GMT</pubDate>
			<author>donotreply@osnews.com (phoudoin)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[2]: Another, simpler solution</title>
			<link>http://www.osnews.com/thread?536513</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?536513</guid>
			<description><div class="cquote">The old rule still holds: If you suspect a malicious link, don't click it. </div><br />
<br />
Not safe enough : an URL can be resolved automatically without user interaction, like an HTML frame src URL, or a QRCode reader.<br />
Or a RSS app: RSS Republic &amp; co does it and, ironically, many android users actually notice the exploit news article and experience what it can do actually at the same times, thanks to their news feed app ;-).</description>
			<pubDate>Wed, 26 Sep 2012 08:04:00 GMT</pubDate>
			<author>donotreply@osnews.com (phoudoin)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[2]:  Touch Wiz must die</title>
			<link>http://www.osnews.com/thread?536514</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?536514</guid>
			<description>LOL. Maybe time for someone to develop the most beloved piece of malware known to man: TouchWizKilla ;-) Kills only Touchwiz but leaves the rest on&quot;touched&quot; :-)</description>
			<pubDate>Wed, 26 Sep 2012 08:06:00 GMT</pubDate>
			<author>donotreply@osnews.com (PieterGen)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE:  Touch Wiz must die</title>
			<link>http://www.osnews.com/thread?536524</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?536524</guid>
			<description>TouchWiz is called CheezeWiz at times because it is the cheesiest of android customizations ever. When was the last time you've heard of MotoBlur or even SenseUI being this downright ridiculous?</description>
			<pubDate>Wed, 26 Sep 2012 10:16:00 GMT</pubDate>
			<author>donotreply@osnews.com (adkilla)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[2]: Comment by some1</title>
			<link>http://www.osnews.com/thread?536532</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?536532</guid>
			<description>Androidpolice says most US carriers likely pushed a fix last week: <a href="http://www.androidpolice.com/2012/09/25/video-most-galaxy-s-iii-devices-are-not-vulnerable-to-ussd-wiping-exploit-it-was-already-fixed-in-an-update/" rel="nofollow">http://www.androidpolice.com/2012/09/25/video-most-galaxy-s-iii-dev...</a><br />
This is for S3, don't know about other models.</description>
			<pubDate>Wed, 26 Sep 2012 12:26:00 GMT</pubDate>
			<author>donotreply@osnews.com (some1)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[3]: Comment by some1</title>
			<link>http://www.osnews.com/thread?536533</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?536533</guid>
			<description><div class="cquote">Androidpolice says most US carriers likely pushed a fix last week. </div><br />
<br />
They didn't pushed a *fix*, but a full upgrade to Android 4.0.4 or sooner, which already include the fix.<br />
I'll bet that they didn't even knew that the issue existed on the first place and that only this upgrade comes with the fix. May Jelly Bean was not ready to broadcast, I'm pretty sure no official fix will be available yet.</description>
			<pubDate>Wed, 26 Sep 2012 12:35:00 GMT</pubDate>
			<author>donotreply@osnews.com (phoudoin)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[4]: Comment by some1</title>
			<link>http://www.osnews.com/thread?536537</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?536537</guid>
			<description>Or maybe they knew. They rarely push updates at the same time otherwise. And who cares if this was one patch or 4.0.4 update, which is just a few patches itself. The point is that most S3s are already patched, even those with carrier ROMs.</description>
			<pubDate>Wed, 26 Sep 2012 12:43:00 GMT</pubDate>
			<author>donotreply@osnews.com (some1)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>Like good old times</title>
			<link>http://www.osnews.com/thread?536542</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?536542</guid>
			<description>This reminds me of these iOS exploits that one used for jailbreaking back in the old days. You just opened a specially crafted web page or PDF document and boom ! Out came root access !<br />
<br />
Seriously, mobile OS security is such a joke, I can only wonder why all the flaws of our beloved gadgets haven't been used for large-scale cyber-warfare yet.</description>
			<pubDate>Wed, 26 Sep 2012 14:09:00 GMT</pubDate>
			<author>donotreply@osnews.com (Neolander)</author>
			<category>Comments</category>
		</item>
	</channel>
</rss>
