Live data from Hacker News

More Than 1M Google Accounts Breached by Gooligan

blog.checkpoint.com

131–140 of 183 posts

Re: More Than 1M Google Accounts Breached by Gooligan

#131
post #121

Earlier quoted context omitted.

Right now, Google has no credible open competitor to Android, and not for lack of trying. If Android wants to be the Windows to iPhone's Mac, it will have to get serious about security, or be swept away by the competitors which will inevitably emerge. I also want to say that voting machines run unsupported Android builds. If Google is derelict in that duty... well, that's a much bigger deal than some compromised Goog…

I never heard that about voting machines. Do you have a source for that? I'm not sure why that's more surprising than hearing that they run Windows XP...

These are the certified electronic voting machines (DREs) for Pennsylvania:

http://www.dos.pa.gov/VotingElections/OtherServicesEvents/Pa...

The Android device in use is the EA Tablet. The certification tests are listed in "EA TABLET FOR ANDROID WITH JELLYBEAN 4.2.1 ELECTRONIC Test Report," dating from 2013.

To be fair, it's probably the best of the horrible lot in security, but that ain't saying much.

For example, the iVotronic systems contain a readily accessible compact flash card right on the top, which stores the election returns. Demonstration machines are set up in each county, so I went to see one in person. Unsurprisingly, the demo machine's card wasn't even covered with a tamper-evident seal.

The devices, including the compact flash cards and the PEBs, are reused from year to year because the legally required certification for the device is very narrow. As the demo machine compact flash cards and PEBs are re-used in each election, at any time prior to the election, infecting the demo machine can be used as a vector to attack the entire county voting total.

Since the demo machine is not sealed, its compact flash can be accessed. If the compact flash card is compromised, the system can be quickly owned. From there, the malware can spread rather trivially to the PEB unit used as a secure token by the election workers, and from there to the county's Unity system at Election Central, allowing the entire county's vote to be altered. So instead of the 4,500 machine compromises PA is claiming would be necessary to influence a state election, it would probably only take 6-7 people any time in the past ten years planting their malware in a few key counties.

All one would need to do to untraceably change the vote totals would be walk in to the county election commission, swap the compact flash out for your malware, and leave. If you do this at any point prior to the election, the malware can spread from the demo machine, to a live voting machine, and finally, when the compact flash cards are entered into the Unity system for final tally, the malware can compromise the whole lot. Then the malware would self-delete, leaving no reliable paper audit record.

Interestingly, from a legal perspective, the Secretary of the Commonwealth's certification for these machines is contingent upon the locking mechanism preventing access to the compact flash card. The machine that I saw, the most common model in use in the state, physically could not be secured that way. The plastic cover mechanism to which the lock is affixed simply doesn't cover the flash card slot well enough.

Under the PA election code, if a specific requirement of the Secretary's certification is not met, the law would invalidate the votes cast through all the iVotronics as a matter of law. As the machines were not configured as approved, they aren't approved for casting ballots, which would throw the PA recount into chaos. It's probably the only judicial avenue left to sue for a state-wide recount that might actually have a chance of being considered.

Nobody tell Jill Stein. In all liklihood, the PA legislature would just send the current electors anyway, as is their prerogative.

Re: More Than 1M Google Accounts Breached by Gooligan

#132
post #16

Earlier quoted context omitted.

Yes. It never occurred to me to connect my portable devices to any accounts that mattered. Who does that?

People who don't think with a security-first mindset or who prefer to gain the benefits of cloud-integration with their devices.

Is that what I have? A security-first mindset? Honestly it never even crossed my mind back in 2010 when I bought a Nexus S that the thing to do was put the keys to the kingdom on something that might fall out of a pocket somewhere... silly me; I just made a separate account and I don't use that account for signing up other accounts or whatnot; when that account gets compromised they'll find precious little of value.

Re: More Than 1M Google Accounts Breached by Gooligan

#133
post #99
post #84

Earlier quoted context omitted.

That's not to say Google has no responsibility in this. Google's OS has a terrible security-update policy. Being able to buy a new computing device from a store that will receive no security updates is terrible, and is fairly common in Android devices. Now, there are valid technical reasons that Google can't be as good as Microsoft at pushing out updates to every device running their OS, but still, it's hard to say t…

Google in most cases is not the device's manufacturer, and in a mobile device OS and application SW are tightly coupled, so you cannot really have OS updates separate from firmware updates, bypassing the actual manufacturer's own updates. Google (and Apple and Microsoft) can totally do it for devices that manufactures and maintains on its own, and actually it is one of the selling points of their new phone. In additi…

That is specifically a design flaw in the AOSP. Right now manufacturers have to integrate their custom device drivers into every new OS build, leading to long delays and fragmentation. The device drivers should be separate, and the OS should expose a stable API and integration points. That way OS upgrades could be pushed out without breaking everything, just like with desktop OSs.

Re: More Than 1M Google Accounts Breached by Gooligan

#134
post #20
post #16

Earlier quoted context omitted.

Yes. It never occurred to me to connect my portable devices to any accounts that mattered. Who does that?

It never occured to me that anything sent or received from a gmail account was private.

I take that as validation; the stuff that matters to me isn't on Google's systems and never has been.

I got down-modded pretty badly for my first comment; apparently that was terribly offensive. I don't really care much but it is very telling; the same folks that wail and moan endlessly about having their privacy compromised by Google et al. apparently don't hesitate to make it trivially simple to do so.

Re: More Than 1M Google Accounts Breached by Gooligan

#135

Earlier quoted context omitted.

If it is just auth tokens instead of email password, should google be able to invalidate all these auth tokens in their backend immediately? Force those uses to re-login and get new auth tokens?

The malware is still installed and would just capture the new auth tokens. And forcing the user to login would also give the malware an opportunity to capture the actual password.

I see.

Google should log other signatures such as device id, ip, network, region where the request coming from and use those data as additional layer of security in the backend to help id the folks/org behind hack.

Re: More Than 1M Google Accounts Breached by Gooligan

#136
post #115

Earlier quoted context omitted.

Hey Eren, It's not like that email addresses are that hard to find when they are listed on websites publically... ereny*gdir*n[@AT]gm*il

It requires manual interaction and obviously not scalable.

It's pretty easy to automate an email harvester.

Then again just @(gmail|yahoo|hotmail).com works for a lot of people.

Re: More Than 1M Google Accounts Breached by Gooligan

#137
post #114

Earlier quoted context omitted.

> Being able to buy a new computing device from a store that will receive no security updates is terrible, and is fairly common in Android devices. This seems like the kind of problem the free market could solve. Just get one phone vendor to guarantee secruity updates for a few years and then some customers will start buying those phones. After a while other vendors will start promising it or losing sales.

The underlying assumption is that a multitude of users would switch to devices produced by such a manufacturer. This, I think, overestimates how much most users currently care about security. As it turns out, there are more secure devices in the marketplace than the affected phones, but they cost more. All other things equal, a contractual obligation for security policies would increase the cost (and thus price) of d…

>This, I think, overestimates how much most users currently care about security.

The media has failed to inform the lay public about this issue. Users could be made to care about security with the right messaging. Your average user may not understand OS updates but the issue can be phrased simply in terms of product defects which the manufacturer refuses to fix and that put their personal info at risk.

Re: More Than 1M Google Accounts Breached by Gooligan

#138
post #99

Earlier quoted context omitted.

Google in most cases is not the device's manufacturer, and in a mobile device OS and application SW are tightly coupled, so you cannot really have OS updates separate from firmware updates, bypassing the actual manufacturer's own updates. Google (and Apple and Microsoft) can totally do it for devices that manufactures and maintains on its own, and actually it is one of the selling points of their new phone. In additi…

Google have an approval system before they allow a manufacturer to bundle Google services. Update mechanisms could easily be built into that approval process. I suspect that they haven't turned the screws too hard on manufacturers for fear of Samsung or LG making an Amazon-style fork. Google have already drawn their own roadmap with the Android One project - a number of low-end manufacturers have devices that get upd…

[deleted]

Re: More Than 1M Google Accounts Breached by Gooligan

#139
post #90
post #29

Earlier quoted context omitted.

Thanks for making this comment. This post is a wonderful example of the rampant marketing that has given the security industry a bad name. - The title is technically accurate, which is the best kind of accurate for clickbait. This is not a novel vulnerability representative of an application security flaw within Google - the malware campaign specifically targets older devices using previously known vulnerabilities.[1…

Checkpoint has been notorious for this kind of exaggerated marketing, especially within the past few years. My theory is that their security appliance line has been suffering due to superior competitors (source: personal experience; could be wrong without global sales numbers), so I think they're trying to get their name back in people's minds. This research is definitely good and beneficial, but yes, it's threat int…

Years and years ago I went out searching for UMD devices vulnerable to CSRF.

They universally were, but the only vendor that responded to my email was CheckPoint, who admitted it and said they were working on a fix. (They had the fix released soon, too.) Everyone else was 100% silent treatment.

Re: More Than 1M Google Accounts Breached by Gooligan

#140
post #99

Earlier quoted context omitted.

Google in most cases is not the device's manufacturer, and in a mobile device OS and application SW are tightly coupled, so you cannot really have OS updates separate from firmware updates, bypassing the actual manufacturer's own updates. Google (and Apple and Microsoft) can totally do it for devices that manufactures and maintains on its own, and actually it is one of the selling points of their new phone. In additi…

Google have an approval system before they allow a manufacturer to bundle Google services. Update mechanisms could easily be built into that approval process. I suspect that they haven't turned the screws too hard on manufacturers for fear of Samsung or LG making an Amazon-style fork. Google have already drawn their own roadmap with the Android One project - a number of low-end manufacturers have devices that get upd…

Exactly. Apple only has one set of hardware to support. Microsoft support the PC platform and you can usually do a fresh install on any machine and it will boot (driver support is a little different).

Android is garbage in this regard. Google binds everyones' feet with the OHA so they are required to use the Google Play Store and services (and they can also never manufacture Amazon devices) yet they don't standardize the system to ensure that AOSP can install anywhere. Part of this is the difficulty of ARM not really being an architecture, but even Microsoft was able to deal with this by requiring UEFI and some standardization on Windows devices (although they're more like Apple where there's limited hardware to support).

Google makes a ton of money from their licensing. It's in their advantage that people buy new phones all the time. If the hardware wasn't all over the place, we'd see more uptake for thinks like Plasma.

What are the alternatives right now for software devs that are willing to do their own roll-your-own work? Ubuntu Touch doesn't seem to have been updated for most of their ports in forever. Plasma supports two devices, neither of which have sdcard slots.

Post reply on HN