Live data from Hacker News

More Than 1M Google Accounts Breached by Gooligan

blog.checkpoint.com

91–100 of 183 posts

Re: More Than 1M Google Accounts Breached by Gooligan

#91
post #60

Earlier quoted context omitted.

"Windows is a mess because you can install a virus executable on it." "You can't install Windows software outside App Store anymore, MS is taking muh freedoms." You can't win.

You definitely can't win, but those two complaints are not mutually exclusive. Instead of locking down apps to solve the first problem, in theory Microsoft could have redesigned Windows to make third party executables less of a risk. Obviously that's harder, but it's not hypocritical to make both those statements.

I'm not exactly a fan of those, but I think MS is already doing that with UWP, which apps weren't exactly greeted with rejoice.

Re: More Than 1M Google Accounts Breached by Gooligan

#92
post #87
post #82

Earlier quoted context omitted.

You can win. Sane defaults. Allowing the potentially unsafe method "expert mode" is OptIn. I wouldn't buy a car if the dealer held the only key to the hood, still I don't expect everyone to be a grease monkey nor do I think it remarkably safe.

What's "insane" about explicitly having to opt-in to 3rd party application installs in Android ? That switch existed for years and was praised upon. The media opinion only shifted after Android becoming most widely distributed phone OS. It's just easy clicks. Android is fine.

I'm in agreement with you and that's what I was saying or tried to say. Opting into 3rd party installs is fine with me, having the option disabled is a "sane default".

Re: More Than 1M Google Accounts Breached by Gooligan

#93
post #28

Just to be clear, they didn't obtain any passwords, but auth tokens. This would potentially allow them to log into accounts, but only as long as the tokens are valid. Also, they don't reveal which "third party app stores" served infected apps, but they do provide a list of infected apps, and searching for these yields some real shady download sites: http://imgur.com/a/0luW3

Couldn't Google just revoke all of those access tokens? It'd be a minor inconvenience for some, but it would hardly be a big deal, right? You'd just have to grant access again.

    > Google also stated that they are ..., revoking affected tokens
That alone obviously isn't a fix though, just plasters over the hole such that you can still punch through just as before.

Re: More Than 1M Google Accounts Breached by Gooligan

#94
post #60
post #40

We were just reading "Android security in 2016 is a mess"[1] 2 days ago and now we have another great example for it. https://news.ycombinator.com/item?id=13056288

"Windows is a mess because you can install a virus executable on it." "You can't install Windows software outside App Store anymore, MS is taking muh freedoms." You can't win.

Android could let me add a specific source so I don't have all-or-nothing security.

For example, I only wish to install apps from HumbleBundle and F-Droid (in addition to the default play store). Any other APK that lands on my system is still untrustworthy.

Of course, this would probably require additional signature on the APK, since I think all 3rd party sources are just providing raw APKs.

Re: More Than 1M Google Accounts Breached by Gooligan

#96
post #6

Does anyone else use a special account for their Android phone that they don't use for anything else?

Yes, a gmail address that I use for nothing other than to access the Play Store.

I don't use it to send or receive emails and I don't use any other google products or services.

Anything I actually sign up for uses one of my other three paid services.

At this point I'm tempted to start using Raccoon;

http://www.onyxbits.de/raccoon

Re: More Than 1M Google Accounts Breached by Gooligan

#97
post #8

Earlier quoted context omitted.

I don't use a Google account on my android phone. Cyanogenmod sans google anything.

No gmail, gmaps, gphotos ? do you have replacements ? pse: thanks all AP a lot for suggestions :)

There are alternative services for pretty much everything Google offers.

Re: More Than 1M Google Accounts Breached by Gooligan

#98
post #87
post #82

Earlier quoted context omitted.

You can win. Sane defaults. Allowing the potentially unsafe method "expert mode" is OptIn. I wouldn't buy a car if the dealer held the only key to the hood, still I don't expect everyone to be a grease monkey nor do I think it remarkably safe.

What's "insane" about explicitly having to opt-in to 3rd party application installs in Android ? That switch existed for years and was praised upon. The media opinion only shifted after Android becoming most widely distributed phone OS. It's just easy clicks. Android is fine.

I agree with the first comment, but Android is "not fine".

The lack of a sane updating model is a real security problem.

Re: More Than 1M Google Accounts Breached by Gooligan

#99
post #84
post #29

Earlier quoted context omitted.

Thanks for making this comment. This post is a wonderful example of the rampant marketing that has given the security industry a bad name. - The title is technically accurate, which is the best kind of accurate for clickbait. This is not a novel vulnerability representative of an application security flaw within Google - the malware campaign specifically targets older devices using previously known vulnerabilities.[1…

That's not to say Google has no responsibility in this. Google's OS has a terrible security-update policy. Being able to buy a new computing device from a store that will receive no security updates is terrible, and is fairly common in Android devices. Now, there are valid technical reasons that Google can't be as good as Microsoft at pushing out updates to every device running their OS, but still, it's hard to say t…

Google in most cases is not the device's manufacturer, and in a mobile device OS and application SW are tightly coupled, so you cannot really have OS updates separate from firmware updates, bypassing the actual manufacturer's own updates.

Google (and Apple and Microsoft) can totally do it for devices that manufactures and maintains on its own, and actually it is one of the selling points of their new phone.

In addition, at least in the US, devices connecting to a cellular network have to go through a certification process, enforced by the carriers, and every firmware update requires additional regression testing (time and money) for the device to be admitted on the network again.

(That's my guess of why Lenovo dropped the policy of fast updates for Moto phones when they bought Motorola)

Re: More Than 1M Google Accounts Breached by Gooligan

#100
post #85

Malware on your Android device picked up from third party app stores (FDroid? Amazon?) that steals email accounts and auth tokens. Looks like it only works on the older Android 4 Jellybean software (and some Android 5 Lollipop) and below, so mostly concentrated in Asia where there are lower-end phones. You can see if your account has been affected here: https://gooligan.checkpoint.com/

>Looks like it only works on the older Android 4 Jellybean software (and some Android 5 Lollipop) and below, so mostly concentrated in Asia where there are lower-end phones. But devices running Android 5 and below "only" comprise the vast majority of devices out there https://developer.android.com/about/dashboards/index.html

Yep, I'm stuck on 4.4.2 because verizon doesn't provide OTA updates any more and the 4.4 update ensures that the phone bricks if you go through the process of installing cyanogenmod.
Post reply on HN