I-Android ivezwa izinsongo ezimbili ezintsha zokuphepha

ukuhlolwa komcibisholo we-microsoft

Ngezinguqulo zakamuva ze-Android, sibone ukuthuthuka okubalulekile kwezokuvikela ezihumusha, isibonelo, ekusungulweni komaka be-biometric njengezigxivizo zeminwe ukuze kuvikelwe amatheminali ekwebiweni. Kodwa-ke, ukuvikelwa komsebenzisi akuqinisekisiwe ngokuphelele, njengoba abathuthukisi be-software behlanganisa izinyathelo ezintsha zokuvikela abathengi ngangokunokwenzeka, izigebengu ze-inthanethi nazo ziyaqhubeka nokudala izinto ezinonya ezingase zilimaze izigidi zabantu lapho besebenzisa amathebulethi abo nama-smartphone. Isibonelo salokhu idatha esiyinikeze ezinsukwini ezimbalwa ezedlule elinganisela izinsongo ezikhona ngokumelene nesistimu yokusebenza esetshenziswa kakhulu emhlabeni ngaphezu kwezigidi ezingu-2. Ngaphambili sike sakhuluma ngayo ukuba sengozini okubalulekile obekungalimaza amatheminali amakhulu ezigidi zabasebenzisi ekugcineni angazange abe nomthelela omkhulu. Ukuphulwa kwezokuphepha okuvulwe ehlobo okungase kuthinte amatheminali angaphezu kwezigidi ezingu-900 kuyisibonelo. Kodwa-ke, naphezu kweqiniso lokuthi ezimweni eziningi, izingozi zigcina zincane futhi lokhu kuhlaselwa kwehluleka, izigebengu ziyaqhubeka nokuthola isofthiwe kwalabo be Mountain View ithagethi ekhangayo kakhulu ongaqondisa kuyo izenzo zakho. Okulandelayo sizokhuluma ngakho Golem futhi Clickjacking, uhlelo olungayilungele ikhompuyutha olusha olusongela irobhothi eliluhlaza, futhi siyakutshela ukuthi zingalimaza kanjani amadivayisi ethu nokuthi ungabhekana kanjani nazo. I-malware ye-Android

Yini iGolem?

Okokuqala sikhuluma ngaleli gciwane, elivele ezinsukwini ezimbalwa ezedlule futhi lisuselwa kwedlule elibizwa Ghost push futhi lokho kwabona ukukhanya ehlobo lika-2015. Naphezu kweqiniso lokuthi inani lemishini eveziwe alifikanga esigidini futhi nakuba litholiwe futhi lacindezelwa ngokushesha, likwazile ukuthelela amatheminali athile ngokusebenzisa. izinhlelo zokusebenza ezingamanga ezazinentengo futhi zaziqukethe ifayela eliyingozi. Uma kwenzeka kuba golem, ukusebenza kuyafana nomehluko wokuthi kusekelwe ekuqalisweni kwabambalwa amakhodi kumafu emva kwalokho, izinhlelo zokusebenza ziyalandwa ngokuzenzakalelayo ngaphandle kokuthi umsebenzisi azi futhi avumele control wakho amaphilisi kanye Smartphones. Njenge-Ghost Push, uma la mathuluzi esegciniwe futhi umnikazi wedivayisi esewafinyelele, aqala ukusebenzisa imali kuwo. Ngakho-ke, kungu-a igciwane inhloso yakhe robar kubanikazi bemithombo yezindaba elithelelayo. Indlela engcono kakhulu yokunciphisa izingozi zokuchayeka ku-Golem ngakolunye uhlangothi, ngokusebenzisa i-antivirus enamandla futhi ngakolunye, ngokulanda izinhlelo zokusebenza ezivela kubathuthukisi abahamba phambili. i-malware ye-android

Ukuchofoza, i-malware entsha enezindlela ezindala

Okokugcina, sigqamisa le nto ubungozi bayo obukhulu kunani lamatheminali engawathelela: Amanye Izigidi ezingu-500 equkethe izinguqulo ze Android phakathi kwe 2.2 kanye no-4.4. Nokho, akuthinti amadivayisi afakwe izibuyekezo ezifana ne-Marshmallow noma i-Lollipop. Ukusebenza kwayo kulula futhi kusetshenziswa kabanzi ngabaduni. I-Clickjacking camouflages kumafayela nezinhlelo zokusebenza ezibonakala zithembekile futhi ziphephile ukufaka amadivaysi, kanye nokufinyelela ulwazi lomuntu siqu njengabathintwayo esibashayela izingcingo, imilayezo esiyithumelayo kodwa esiyitholayo nangezinhlelo zokusebenza futhi, futhi sigxile kakhulu kubasebenzisi abangochwepheshe, ukwebiwa kwama-akhawunti e-imeyili nama-imeyili agciniwe. Kodwa-ke, isenzo seClickjacking asigcini lapha njengoba, lapho umgebengu efinyelele konke lokhu okuqukethwe, unamandla okuzibeka njenge umlawuli wesoftware futhi uthole izimvume ezikhethekile zesistimu yokusebenza futhi ingase yenze isiphetho singasebenziseki unomphela. Izindlela ezingcono kakhulu zokuvimbela isenzo salolu hlelo olungayilungele ikhompuyutha ukulanda izinhlelo zokusebenza nokumisa iziphequluli kuzo gwema ukubukeka kwe amawindi ezigaxekile futhi unciphise umthelela wayo, njengaseGolem, sebenzisa kuphela Izinhlelo zokusebenza lokho kuvela onjiniyela abafakiwe futhi uthembekile futhi okokugcina, uma kungenzeka, buyekeza i-android kuzinguqulo kamuva kuno-4.4. Izindlela 5 no-6 ziyizindlela ezingcono kakhulu zokugwema ukuhlaselwa yi-Clickjacking. impande ye-android

Izinsongo ezingathi sína?

Ngaphandle komthelela lobu bungozi obusha obusha ku-Android obungaba nabo, uma uthi nhlá, babo umphumela kwanele kunqunyelwe kusukela ngokujwayelekile, unjalo ziyabanjwa ngaphambi kokuthi bahlasele kakhulu futhi ngakolunye uhlangothi, abathuthukisi be-software basheshe bakhiphe izibuyekezo zokuphepha ukuze babavimbele ekudaleni umonakalo. Okokugcina, njengoba sishilo kwezinye izikhathi, ukusebenzisa ingqondo kuyisihluthulelo sokugwema, ngakolunye uhlangothi, ukuba yizisulu ezilula zabaduni futhi, ngakolunye, ukunciphisa ubungozi esidalula kuzo zombili izisetshenziswa zethu kanye nolwazi lwethu olubucayi kakhulu. ngesikhathi sokuhlaselwa. Unodoli we-Xposed Framework

Ngemva kokufunda ngezinsongo ezimbili ezinkulu ezivele ngoMashi ngokumelene ne-Android kodwa ukuthi nokho, ngokuvikelwa okwanele, azibandakanyi izingozi eziningi kakhulu, ucabanga ukuthi abathuthukisi bohlelo olusetshenziswa kakhulu emhlabeni kufanele bathuthukise izindlela zokuphepha noma noma kunjalo, Ngabe ucabanga ukuthi ingxenye yesibopho kulolu daba kufanele iwele kubasebenzisi futhi kufanele kube yibo abagcina beqinisa amaphilisi abo kanye nama-smartphone? Unolwazi oluningi oluhlobene olutholakalayo, olufana nomhlahlandlela wamaqhinga okuphepha. lokho kuzokusiza ukuthi uvikele amatheminali akho ngangokunokwenzeka ngenkathi uthola okuningi kuwo.