Live data from Hacker News

Samsung’s Android app-signing key has leaked, is being used to sign malware

arstechnica.com

51–60 of 134 posts

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#51
post #46
post #32

Earlier quoted context omitted.

> The main issue to me seems to be sideloading apps I think you could phrase that better. Sideloading apps is not an "issue", it's an incredibly important tool that developers can use to audit the behavior of apps.

Google could do what Apple does, and allow sideloading for a limited time only to those with a paid developer account. With the continuing security problems, it is increasingly being proven out that Apple got the app ecosystem right, from the get-go, with their walled garden approach. The benefits of such vastly outweigh the costs to a few tinkerers (and malicious actors) when you're building a product for the averag…

No need to be so draconian. Security should be built to protect users, not Apple's profits. Play Protect could easily flag the APK downloaded outside the Play Store with Samsung's keys and prevent install.

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#52
post #46
post #32

Earlier quoted context omitted.

> The main issue to me seems to be sideloading apps I think you could phrase that better. Sideloading apps is not an "issue", it's an incredibly important tool that developers can use to audit the behavior of apps.

Google could do what Apple does, and allow sideloading for a limited time only to those with a paid developer account. With the continuing security problems, it is increasingly being proven out that Apple got the app ecosystem right, from the get-go, with their walled garden approach. The benefits of such vastly outweigh the costs to a few tinkerers (and malicious actors) when you're building a product for the averag…

> Google could do what Apple does, and allow sideloading for a limited time only to those with a paid developer account.

that is the worst idea I have heard in a long time. what happens to developers, like me, that cannot afford a "paid developer account"? and whats to stop Google (or Apple) from raising the fee so high that it prices out important people from the process?

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#53
post #46
post #32

Earlier quoted context omitted.

> The main issue to me seems to be sideloading apps I think you could phrase that better. Sideloading apps is not an "issue", it's an incredibly important tool that developers can use to audit the behavior of apps.

Google could do what Apple does, and allow sideloading for a limited time only to those with a paid developer account. With the continuing security problems, it is increasingly being proven out that Apple got the app ecosystem right, from the get-go, with their walled garden approach. The benefits of such vastly outweigh the costs to a few tinkerers (and malicious actors) when you're building a product for the averag…

I continue to be astounded when seeing takes like this on a site called Hacker News. If this had been the attitude in the 80s and 90s, we'd be in a Microsoft (or IBM) monoculture today and the web wouldn't exist.

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#54
> These companies somehow had their signing keys leaked to outsiders

I can dream, but I would love to know what this "somehow" is. Such a leak is a major security threat to a sizeable portion of phone users. Disclaiming what happened and what you are doing about it would be good.

Generally speaking I don't have much trust in anything a large company is building. In this case, this is very likely they haven't used an HSM for something at the root of the security for stuff like Samsung Pay... This is a major smell to me.

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#55
post #7

Earlier quoted context omitted.

It’s my understanding that most Android devices don’t get OEM updates for very long

This is true in the sense that most android devices are small/cheap off brand or Chinese devices sold across low-income markets, like Africa and the Middle East. Any mid- or top-tier Android devices, such as Pixels and Galaxy devices which compete directly with Apple, are usually on a monthly security update cadence for at least 3 years.

Samsung generally takes several months to fix 0days.

source: have owned a samsung and took notice of when the update came

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#56
Just when it seems like we’ve reached the bottom on the level of Samsung’s incompetence, it just drops deeper.

I’ve avoided Samsung anything for years because of their total disregard for security and total contempt towards their users.

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#58
post #46
post #32

Earlier quoted context omitted.

> The main issue to me seems to be sideloading apps I think you could phrase that better. Sideloading apps is not an "issue", it's an incredibly important tool that developers can use to audit the behavior of apps.

Google could do what Apple does, and allow sideloading for a limited time only to those with a paid developer account. With the continuing security problems, it is increasingly being proven out that Apple got the app ecosystem right, from the get-go, with their walled garden approach. The benefits of such vastly outweigh the costs to a few tinkerers (and malicious actors) when you're building a product for the averag…

> allow sideloading for a limited time only to those with a paid developer account.

I think this is confusingly phrased and the replies relate to that confusion.

A free Apple developer account allows 'sideloading' for a limited time, currently a week IIRC, and a paid account extends this to a year, which is technically limited but probably not what most people would understand by the phrase.

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#60

Just when it seems like we’ve reached the bottom on the level of Samsung’s incompetence, it just drops deeper. I’ve avoided Samsung anything for years because of their total disregard for security and total contempt towards their users.

>I’ve avoided Samsung anything for years because of their total disregard for security and total contempt towards their users.

The thing is, if you live in the west then all the other major Android brands aren't better at all. There just are no good options anymore. HTC went bust, OnePlus turned to shit, LG threw in the towel, Sony's SW updates cycle is unimpressive for how expensive they are, Google Pixels are buggy as hell and not available in every country, and Motorola, Nokia and Blackberry are basically rebadged Chinese OEM designs. This lack of good options explains why Android lost so much market share to iOS in the last years.

Excluding Chinese phone makers, Samsung is pretty much the only big player in town from a western aligned nation, that has its shit mostly together as of present, promising 5 years of updates, having service and distribution centers in most countries around the world and a wide portfolio covering all price brackets.

For example, if you're in the market for a new relatively affordable mid-range ~300 Euro phone, then Samsung is pretty much your safest bet in the Android space.

Sure, there are better option like Fairphone but those are far away from being globally mainstream.

Post reply on HN