Fyi, this is related to the story from 2 days ago: https://news.ycombinator.com/item?id=33823946 An important comment from the original story: > OEMs have mitigated the issues above in previous updates. A new security update from Android is not required to mitigate these issues. Ensuring your device is running the latest version of Android is a general best security practice for users. Though the ars story says Samsu…
It’s my understanding that most Android devices don’t get OEM updates for very long
Samsung’s Android app-signing key has leaked, is being used to sign malware
11–20 of 134 posts
Re: Samsung’s Android app-signing key has leaked, is being used to sign malware
#12Anyone can do a ELI5 on the app signing key replacement difficulty?
It isn't covered in the article and seems too high level for a layman like me.
Re: Samsung’s Android app-signing key has leaked, is being used to sign malware
#13Re: Samsung’s Android app-signing key has leaked, is being used to sign malware
#14Re: Samsung’s Android app-signing key has leaked, is being used to sign malware
#15It could also mean people signing their own firmware and freeing those devices.
It’s an app signing key. I don’t think it will work for firmware. But I’m not sure. Can someone more knowledgeable about Android’s chain of trust chime in?
Re: Samsung’s Android app-signing key has leaked, is being used to sign malware
#16The main issue to me seems to be sideloading apps, playstore apps seem to be protected. Sideloaded apps could be anything since its the app key that is compromised.
Re: Samsung’s Android app-signing key has leaked, is being used to sign malware
#17> “Samsung takes the security of Galaxy devices seriously. We have issued security patches since 2016 upon being made aware of the issue“ They’ve known about it since 2016!?!
Re: Samsung’s Android app-signing key has leaked, is being used to sign malware
#18I mean considering the level of shitware samsung install on their phones (and make difficult to remove or disable) it will be hard to tell the difference between the official stuff and straight up honest malware.
I used to feel that way, but since the S10 series, there are very few things built into the Galaxy line that fall in the description of shitware anymore. McAfee's device protection shit definitely, but other than that, I can't think of any forced crapware on my last 3 unlocked Galaxy devices.
Re: Samsung’s Android app-signing key has leaked, is being used to sign malware
#19Re: Samsung’s Android app-signing key has leaked, is being used to sign malware
#20Earlier quoted context omitted.
It’s my understanding that most Android devices don’t get OEM updates for very long
This is true in the sense that most android devices are small/cheap off brand or Chinese devices sold across low-income markets, like Africa and the Middle East. Any mid- or top-tier Android devices, such as Pixels and Galaxy devices which compete directly with Apple, are usually on a monthly security update cadence for at least 3 years.