Live data from Hacker News

Samsung’s Android app-signing key has leaked, is being used to sign malware

arstechnica.com

31–40 of 134 posts

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#31
post #5

I mean considering the level of shitware samsung install on their phones (and make difficult to remove or disable) it will be hard to tell the difference between the official stuff and straight up honest malware.

I used to feel that way, but since the S10 series, there are very few things built into the Galaxy line that fall in the description of shitware anymore. McAfee's device protection shit definitely, but other than that, I can't think of any forced crapware on my last 3 unlocked Galaxy devices.

Last shitware i can remember was the 3rd party IR remote control software they bundled with Note3/4, because a couple years later it was updated to have ads on lockscreen. But it was easily disableable from the app list.

The latest Samsung device i have is tab s8 from this year and the software i would call bloat was all the Google stuff like Youtube, Youtube music, Duo, Chrome, Google search. And worst of all the Google assistant that you have to go to multiple places to disable.

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#32

The main issue to me seems to be sideloading apps, playstore apps seem to be protected. Sideloaded apps could be anything since its the app key that is compromised.

> The main issue to me seems to be sideloading apps

I think you could phrase that better. Sideloading apps is not an "issue", it's an incredibly important tool that developers can use to audit the behavior of apps.

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#33

I don't get it, the problem has been known for awhile so why hasn't the key been replaced? Anyone can do a ELI5 on the app signing key replacement difficulty? It isn't covered in the article and seems too high level for a layman like me.

In the world of Android, apps are signed (including system/platform apps) through a trust-on-first-use system. There's no PKI with roots and intermediates which could support easily enabling a quick fix.

On Android, an updated app is validated by the system to be signed by the same signing key hash as was used previously.

The most recent (v3, IIRC) apk signing scheme allows you to update an APK and sign it with the old key, and committing a future new signing key, which permits re-keying an app.

To use this, I believe you need to ship a platform (operating system) update, as the underlying apps are signed using old APK signing schemes.

These OEMs are likely not always shipping the latest OS version, but could look to techniques used in the custom firmware world, where there are tools to allow reflashing the OS without losing app data when changing system signing key.

It requires engineering effort for already released devices though, so I suspect we will see very little action - as usual, the eyes are on the future products, not on previously released products.

I assume Google play protect will be used to carefully patrol and detect apps on devices signed by the leaked keys, but this isn't hugely helpful for anyone concerned about "zeroday" style targeted attacks against them.

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#34
post #5

I mean considering the level of shitware samsung install on their phones (and make difficult to remove or disable) it will be hard to tell the difference between the official stuff and straight up honest malware.

I used to feel that way, but since the S10 series, there are very few things built into the Galaxy line that fall in the description of shitware anymore. McAfee's device protection shit definitely, but other than that, I can't think of any forced crapware on my last 3 unlocked Galaxy devices.

I agree. In fact I have to install MORE Samsung software (their Good Lock apps) because I loathe the UX of modern Android. Good Lock's customization options make for a better experience IMO.

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#35

I don't get it, the problem has been known for awhile so why hasn't the key been replaced? Anyone can do a ELI5 on the app signing key replacement difficulty? It isn't covered in the article and seems too high level for a layman like me.

So the signing key for Samsung Android phones were leaked so that any software that is loaded is signed such that it comes from the App Store is trusted. The problem for OEMs is that developing and distributing a new key requires a Firmware update and it isn't trivial to develop for QA/QC because if they make a mistake with the keys then devices could be unable to load apps from the App Store.

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#36
post #33

I don't get it, the problem has been known for awhile so why hasn't the key been replaced? Anyone can do a ELI5 on the app signing key replacement difficulty? It isn't covered in the article and seems too high level for a layman like me.

In the world of Android, apps are signed (including system/platform apps) through a trust-on-first-use system. There's no PKI with roots and intermediates which could support easily enabling a quick fix. On Android, an updated app is validated by the system to be signed by the same signing key hash as was used previously. The most recent (v3, IIRC) apk signing scheme allows you to update an APK and sign it with the o…

No post body was provided.

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#37
post #4

> “Samsung takes the security of Galaxy devices seriously. We have issued security patches since 2016 upon being made aware of the issue“ They’ve known about it since 2016!?!

Who's in charge of certificate stuff in these situations?

No post body was provided.

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#38

I don't get it, the problem has been known for awhile so why hasn't the key been replaced? Anyone can do a ELI5 on the app signing key replacement difficulty? It isn't covered in the article and seems too high level for a layman like me.

So the signing key for Samsung Android phones were leaked so that any software that is loaded is signed such that it comes from the App Store is trusted. The problem for OEMs is that developing and distributing a new key requires a Firmware update and it isn't trivial to develop for QA/QC because if they make a mistake with the keys then devices could be unable to load apps from the App Store.

>> and it isn't trivial to develop for QA/QC because if they make a mistake with the keys then devices could be unable to load apps from the App Store.

Well then they better do some f..ing testing. They're only one of the biggest tech companies in existence. Making phones isn't trivial either!

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#39
post #10
post #3

It could also mean people signing their own firmware and freeing those devices.

It’s an app signing key. I don’t think it will work for firmware. But I’m not sure. Can someone more knowledgeable about Android’s chain of trust chime in?

This isn't the OTA signing key, although on some cheap devices I have seen the platform key also be used to sign OTAs...

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#40
post #31

Earlier quoted context omitted.

I used to feel that way, but since the S10 series, there are very few things built into the Galaxy line that fall in the description of shitware anymore. McAfee's device protection shit definitely, but other than that, I can't think of any forced crapware on my last 3 unlocked Galaxy devices.

Last shitware i can remember was the 3rd party IR remote control software they bundled with Note3/4, because a couple years later it was updated to have ads on lockscreen. But it was easily disableable from the app list. The latest Samsung device i have is tab s8 from this year and the software i would call bloat was all the Google stuff like Youtube, Youtube music, Duo, Chrome, Google search. And worst of all the Go…

You bought a android phone. Google forces Samsung to put their Google crap on it and activate/ configure it a certain way before they certify the device firmware for Google play store download/access.

If you don't want it the only option is a non android os such as oxygen.

Post reply on HN