(轉) htc 仆街再一次:軟體捅漏洞, 客戶個資如糞土!
2013/02/24 14:01:45
很不喜歡這種搧風點火的標題, 希望HTC務必改善
Android 漏洞百出也是我不喜歡的原因 😇
2013/02/24 14:23:27
大概掃了一下原文,相對於這種 充滿戲謔、情緒性文字的垃圾等級翻譯 實在是不敢領教 ... 😌😌
2013/02/24 14:59:37
2013/02/24 15:06:50
2013/02/24 23:07:25
三星也曾有過漏洞.. 不過當時他們就趕快補好..
這篇比較有詳細過程跟說明.. http://www.mobile01.com/topicdetail.php?f=568&t=2963020&p=1
HTC 卻是連保護機制都拿掉.. 還找藉口..
惹得 FTC 告上法院.. HTC 被強制判決往後 20 年.. 每兩年要被檢查手機資安狀態..
兩相比較下.. H 的應對真讓人.................... 😌😌😌
基於這是重要資訊, 需督促 H 改善, 故重發文章.. 😌😌😌 ======================= htc仆街再一次:軟體捅漏洞.客戶個資如糞土! 最近一份 Federal Trade Commission(美國聯邦貿易委員會)的調查結果公布,我們才知道這家公司竟然連客戶的個資保護,都膽敢不當一回事! 由於 htc 擅自移除了 Android 及 Windows Mobile 裡的個資保護機制,以致於手機使用者的電話號碼、簡訊內容、瀏覽紀錄、所在位置、信用卡及銀行交易等等極度敏感的資料,都處於能輕易被駭客取得的狀態;更不可思議的,是連自己與他人的通話內容,都因為htc故意將安全機制移除之緣故,而可以被竊錄!FTC消費者保護局的資深律師Lesley Fair表示「這家公司在設計產品時,根本不把資安放在眼裡;它不測試自己手機軟體上潛在的安全弱點、不遵循在撰寫程式時為業界通用的安全規範、而當對其漏洞提出警告時還根本不予理會…」(“The company didn’t design its products with security in mind,” Lesley Fair, a senior lawyer in the commission’s Bureau of Consumer Protection, wrote in a blog post. “HTC didn’t test the software on its mobile devices for potential security vulnerabilities, didn’t follow commonly accepted secure coding practices and didn’t even respond when warned about the flaws in its devices.”) htc逼不得已,只好同意FTC的要求,在往後20年間,其手機都必須接受獨立專業機構的資安檢查。 我們不知道嚴凱泰和王雪紅究竟交情深到什麼程度,得公開痛罵Apple的使用者王八蛋。現在htc蔑視手機個資保護的醜聞曝了光,恐怕用宏達電的人,才會赫然發現自己在莫名其妙之下所有敏感個資都被惡意軟體公開,而變成了王八蛋。 個人資料保護法第22條第1-4項規定「中央目的事業主管機關或直轄市、縣(市)政府為執行資料檔案安全維護、業務終止資料處理方法、國際傳輸限制或其他例行性業務檢查而認有必要或有違反本法規定之虞時,得派員攜帶執行職務證明文件,進入檢查,並得命相關人員為必要之說明、配合措施或提供相關證明資料」、「中央目的事業主管機關或直轄市、縣(市)政府為前項檢查時,對於得沒入或可為證據之個人資料或其檔案,得扣留或複製之。對於應扣留或複製之物,得要求其所有人、持有人或保管人提出或交付;無正當理由拒絕提出、交付或抗拒扣留或複製者,得採取對該非公務機關權益損害最少之方法強制為之」、「中央目的事業主管機關或直轄市、縣(市)政府為第一項檢查時,得率同資訊、電信或法律等專業人員共同為之」、及「對於第一項及第二項之進入、檢查或處分,非公務機關及其相關人員不得規避、妨礙或拒絕」。 htc從台灣之光,變成台灣之恥。政府倘若再不對宏達電依法進行上述檢查,確認其已經為所有賣出的手機填補軟體漏洞、而杜絕個資被盜的風險的話,我們非但不建議買htc的手機,恐怕還應該暫時別打電話給htc的手機使用者。您總不希望原本以為只有天知地知你知我知的商業會談或私密傳情,都變成了茶餘飯後的談話頭吧? HTC Settles Privacy Case Over Flaws in Phones [New York Times, By EDWARD WYATT, February 22, 2013] 【另可參考 FTC官方文件 / PCMagazine 之報導】 WASHINGTON — More than 18 million smartphones and other mobile devices made by HTC, a Taiwanese company that is one of the largest sellers of smartphones in the United States, had security flaws that could allow location tracking of users against their will and the theft of personal information stored on their phones, federal officials said Friday. The flaws affected HTC’s Windows-based phones. The Federal Trade Commission charged HTC with customizing the software on its Android- and Windows-based phones in ways that let third-party applications install software that could steal personal information, surreptitiously send text messages or enable the device’s microphone to record the user’s phone calls. The action is the first attempt by the commission to police a manufacturer of mobile devices. As smartphones and tablets become a common way for consumers to shop, bank and chat online, personal information and privacy will need to be guarded. HTC America, based in Bellevue, Wash., agreed to settle the civil suit with the commission by issuing software patches that close the security holes, and by creating a security program that will be monitored by an independent party for the next 20 years. The F.T.C. does not have the authority to assess fines in consumer protection cases. “The company didn’t design its products with security in mind,” Lesley Fair, a senior lawyer in the commission’s Bureau of Consumer Protection, wrote in a blog post. “HTC didn’t test the software on its mobile devices for potential security vulnerabilities, didn’t follow commonly accepted secure coding practices and didn’t even respond when warned about the flaws in its devices.” An HTC official said Friday that the company had already started to update its software and distribute it to users of some, but not all, of the affected phones. “Working with our carrier partners, we have addressed the identified security vulnerabilities on the majority of devices in the U.S. released after December 2010,” Sally Julien, an HTC spokeswoman, said in a statement. “We’re working to roll out the remaining software updates now and recommend customers download them once available.” “Privacy and security are important,” the statement added, “and we are committed to improving practices that help safeguard our customers’ devices and data.” The trade commission charged that the security flaws resulted from HTC’s modifying the operating system software used on most of the affected phones. In the case of Android, created by Google, the system is designed to protect sensitive information and phone functions through what is known as a permission-based security model. That requires a user, when installing an application that is not a standard part of the operating system, to be notified and to agree that the application could gain access to certain information or functions. HTC, however, preinstalled certain apps on its phones in a way that, in addition to preventing consumers from removing them, disabled the permission-based model and allowed newly installed apps to have immediate access to personal data. “The analogy isn’t exact,” wrote Ms. Fair of the F.T.C., “but it’s like giving a friend the combination to a safe only to find out he’s handing it over to anyone who asks.” That security hole could, for example, let the rogue software secretly record users’ phone conversations or track their location. Flaws in the security system could also give third-party apps access to phone numbers, contents of text messages, browsing history and information like credit card numbers and banking transactions. Those flaws also affected HTC phones that used Windows-based operating systems. While HTC’s actions introduced numerous security vulnerabilities to its phones, a commission official said it was not clear how many users experienced illegal incursions into their phones and personal information. The flaw in the company’s phones has been known since at least 2011. HTC acknowledged the problems at that time and developed software patches for at least some of the deficiencies that year. But the problems were far from minor. The F.T.C. said that text-message toll fraud, in which a hacker causes a phone to send text messages to a number that charges the user for delivery of the message, “is one of the most common types of Android malware,” or malicious software. 大大你要不要把這邊原文 先翻譯看看?
2013/02/25 11:26:19
2013/02/25 11:26:19
2013/02/25 11:28:33
買國貨(華碩)就對了 ~ 😆
2013/02/26 09:02:56
2013/02/26 09:02:56
扯翻譯.. 扯舊新聞.. 除了這些還會啥 ?
麻說個新鮮及能輔證的說法來聽聽.. [很悶]
大概大家都沒看出重點在哪.. [昏倒]
[url="https://www.google.com.tw/#hl=zh-TW&site=&source=hp&q=HTC+%E7%BE%8E%E5%9C%8B+%E6%BC%8F%E6%B4%9E&oq=HTC+&gs_l=hp.1.1.35i39l2j0l8.4785.8668.0.13130.,or.r_gc.r_pw.r_cp.&bvm=bv.42768644,d.dGI&fp=55324cfbfb3904d1&biw=1068&bih=704"]Google 搜尋 "HTC 美國 漏洞 FTC" [/url]
HTC 不同 蘋果. 三星. Sony.. 這些大廠都是發行單一型號的國際版手機..
無論你拿到何處. 或在哪買.. 終究大都是同樣的規格配備..
HTC 則不同.. 在他的銷售策略.. 主打的大都是當地電信的客製機.. 少有單一國際版手機..
舉例.. 蝴蝶機.. 就有分台版.中版.日版..
而在這些新聞當中.. [color="#7F0000"]FTC 已公告 HTC 要配合美國當地的電信商來發布更新.. 長達 20 年..[/color]
這意味這套規範.. 台灣的使用者是沒有包括在內.. 畢竟客製機有限定地區..
所以.. 在台的 HTC 使用者.. 可能還要了解一下.. 啥時候也會有新的更新..[嘆氣]
樓上有幾個可以組一個 唱衰台灣聯盟... | |||
