Live data from Hacker News

Samsung’s Android app-signing key has leaked, is being used to sign malware

arstechnica.com

41–50 of 134 posts

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#42
post #33

Earlier quoted context omitted.

In the world of Android, apps are signed (including system/platform apps) through a trust-on-first-use system. There's no PKI with roots and intermediates which could support easily enabling a quick fix. On Android, an updated app is validated by the system to be signed by the same signing key hash as was used previously. The most recent (v3, IIRC) apk signing scheme allows you to update an APK and sign it with the o…

Quoted post unavailable.

[deleted]

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#43
post #33

I don't get it, the problem has been known for awhile so why hasn't the key been replaced? Anyone can do a ELI5 on the app signing key replacement difficulty? It isn't covered in the article and seems too high level for a layman like me.

In the world of Android, apps are signed (including system/platform apps) through a trust-on-first-use system. There's no PKI with roots and intermediates which could support easily enabling a quick fix. On Android, an updated app is validated by the system to be signed by the same signing key hash as was used previously. The most recent (v3, IIRC) apk signing scheme allows you to update an APK and sign it with the o…

So why exactly can't they do an OS update with the new signing keys? OEMs put out OS updates all the time. Plus if they don't want to do that, they could update their individual apps to use the v3 signing schema. They've had 6 years to figure this out.

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#44
post #7

Earlier quoted context omitted.

It’s my understanding that most Android devices don’t get OEM updates for very long

My S9 was getting updates as late as a few weeks ago.

That was just a GPS (?) update. I have an S9 too, if you check the security patch level (Settings > About phone > Software information), it’s still at March 1, 2022 (and there aren’t any further updates scheduled).

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#45
post #31

Earlier quoted context omitted.

Last shitware i can remember was the 3rd party IR remote control software they bundled with Note3/4, because a couple years later it was updated to have ads on lockscreen. But it was easily disableable from the app list. The latest Samsung device i have is tab s8 from this year and the software i would call bloat was all the Google stuff like Youtube, Youtube music, Duo, Chrome, Google search. And worst of all the Go…

You bought a android phone. Google forces Samsung to put their Google crap on it and activate/ configure it a certain way before they certify the device firmware for Google play store download/access. If you don't want it the only option is a non android os such as oxygen.

Oxygen is still Android, though..? Your next concern should be what the CCP might be forcing them to add in eventually.

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#46
post #32

The main issue to me seems to be sideloading apps, playstore apps seem to be protected. Sideloaded apps could be anything since its the app key that is compromised.

> The main issue to me seems to be sideloading apps I think you could phrase that better. Sideloading apps is not an "issue", it's an incredibly important tool that developers can use to audit the behavior of apps.

Google could do what Apple does, and allow sideloading for a limited time only to those with a paid developer account.

With the continuing security problems, it is increasingly being proven out that Apple got the app ecosystem right, from the get-go, with their walled garden approach. The benefits of such vastly outweigh the costs to a few tinkerers (and malicious actors) when you're building a product for the average bear.

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#47
post #5

I mean considering the level of shitware samsung install on their phones (and make difficult to remove or disable) it will be hard to tell the difference between the official stuff and straight up honest malware.

I used to feel that way, but since the S10 series, there are very few things built into the Galaxy line that fall in the description of shitware anymore. McAfee's device protection shit definitely, but other than that, I can't think of any forced crapware on my last 3 unlocked Galaxy devices.

Bixby, Samsung Pay?

To add injury Bixby hijacks a physical button and Samsung Pay a swipe direction.

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#48

I don't get it, the problem has been known for awhile so why hasn't the key been replaced? Anyone can do a ELI5 on the app signing key replacement difficulty? It isn't covered in the article and seems too high level for a layman like me.

So the signing key for Samsung Android phones were leaked so that any software that is loaded is signed such that it comes from the App Store is trusted. The problem for OEMs is that developing and distributing a new key requires a Firmware update and it isn't trivial to develop for QA/QC because if they make a mistake with the keys then devices could be unable to load apps from the App Store.

Not any app installed from the app store but any app signed using Samsung's keys. Such an app could get any permission it pleases when installed. The app store can easily block apps signed with Samsung's keys, but a few people can probably be convinced to download the app outside the app store, which could easily be flagged by Play Protect if it is a Google-flavored phone, preventing install. I don't know if these systems have actually been updated to do this, but I imagine they would be.

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#49
post #4

> “Samsung takes the security of Galaxy devices seriously. We have issued security patches since 2016 upon being made aware of the issue“ They’ve known about it since 2016!?!

Who's in charge of certificate stuff in these situations?

Some intern at the corporate HQ

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#50
post #20

Earlier quoted context omitted.

This is true in the sense that most android devices are small/cheap off brand or Chinese devices sold across low-income markets, like Africa and the Middle East. Any mid- or top-tier Android devices, such as Pixels and Galaxy devices which compete directly with Apple, are usually on a monthly security update cadence for at least 3 years.

3 years of support sounds like the bare minimum you can expect, and that is what the most expensive brand offer?

It used to be only ~18 months for top-end Android phones.
Post reply on HN