Samsung’s Android app-signing key has leaked, is being used to sign malware
1–10 of 134 posts
Re: Samsung’s Android app-signing key has leaked, is being used to sign malware
#2"some of the compromised keys: Samsung, LG, and Mediatek are the heavy hitters on the list of leaked keys, along with some smaller OEMs like Revoview and Szroco, which makes Walmart's Onn tablets."
Re: Samsung’s Android app-signing key has leaked, is being used to sign malware
#3Re: Samsung’s Android app-signing key has leaked, is being used to sign malware
#4They’ve known about it since 2016!?!
Re: Samsung’s Android app-signing key has leaked, is being used to sign malware
#5Re: Samsung’s Android app-signing key has leaked, is being used to sign malware
#6https://news.ycombinator.com/item?id=33823946
An important comment from the original story:
> OEMs have mitigated the issues above in previous updates. A new security update from Android is not required to mitigate these issues. Ensuring your device is running the latest version of Android is a general best security practice for users.
Though the ars story says Samsung is signing their first party apps with it still. So who knows.
Re: Samsung’s Android app-signing key has leaked, is being used to sign malware
#7Fyi, this is related to the story from 2 days ago: https://news.ycombinator.com/item?id=33823946 An important comment from the original story: > OEMs have mitigated the issues above in previous updates. A new security update from Android is not required to mitigate these issues. Ensuring your device is running the latest version of Android is a general best security practice for users. Though the ars story says Samsu…
Re: Samsung’s Android app-signing key has leaked, is being used to sign malware
#8Fyi, this is related to the story from 2 days ago: https://news.ycombinator.com/item?id=33823946 An important comment from the original story: > OEMs have mitigated the issues above in previous updates. A new security update from Android is not required to mitigate these issues. Ensuring your device is running the latest version of Android is a general best security practice for users. Though the ars story says Samsu…
It’s my understanding that most Android devices don’t get OEM updates for very long
Re: Samsung’s Android app-signing key has leaked, is being used to sign malware
#9I mean considering the level of shitware samsung install on their phones (and make difficult to remove or disable) it will be hard to tell the difference between the official stuff and straight up honest malware.
Re: Samsung’s Android app-signing key has leaked, is being used to sign malware
#10It could also mean people signing their own firmware and freeing those devices.