Live data from Hacker News

Samsung’s Android app-signing key has leaked, is being used to sign malware

arstechnica.com

61–70 of 134 posts

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#61
post #22

Earlier quoted context omitted.

3 years of updates is no competition for Apple.

It got better in the past 2 years. The latest Pixel or Samsung gives you 5 years of support. 3 major updates + 2 years of security updates on the Pixel and 4 major updates + 1 year of security updates on a Samsung. An iPhone gets you 6 major iOS updates, I think.

It's taken them up to the past 2 years to still be this much less than a competitor? We've had smart devices like this since 2007. It took 13 years to get to a point of still being inferior.

You're not impressing me at all here.

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#62
post #6

Fyi, this is related to the story from 2 days ago: https://news.ycombinator.com/item?id=33823946 An important comment from the original story: > OEMs have mitigated the issues above in previous updates. A new security update from Android is not required to mitigate these issues. Ensuring your device is running the latest version of Android is a general best security practice for users. Though the ars story says Samsu…

Can they revoke the key?

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#63

> These companies somehow had their signing keys leaked to outsiders I can dream, but I would love to know what this "somehow" is. Such a leak is a major security threat to a sizeable portion of phone users. Disclaiming what happened and what you are doing about it would be good. Generally speaking I don't have much trust in anything a large company is building. In this case, this is very likely they haven't used an…

> I would love to know what this "somehow" is.

Multiple independent business units developing apps and needing to share the same signing key. Probably contracting out development to other firms.

Neither Google or Apple offer robust ways to effectively delegate App develop while retaining secrets needed to publish an App. So you effectively need a FTE managing and supporting all of these groups.

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#64

Just when it seems like we’ve reached the bottom on the level of Samsung’s incompetence, it just drops deeper. I’ve avoided Samsung anything for years because of their total disregard for security and total contempt towards their users.

>I’ve avoided Samsung anything for years because of their total disregard for security and total contempt towards their users. The thing is, if you live in the west then all the other major Android brands aren't better at all. There just are no good options anymore. HTC went bust, OnePlus turned to shit, LG threw in the towel, Sony's SW updates cycle is unimpressive for how expensive they are, Google Pixels are buggy…

> Google Pixels are buggy as hell,

That hasn't been my experience.

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#65
post #20

Earlier quoted context omitted.

3 years of support sounds like the bare minimum you can expect, and that is what the most expensive brand offer?

A new Samsung Galaxy S22 (and above) has 5 years of support. 4 major Android updates and 1 year of security updates. For the Pixel 6/7/Pro (including the cheaper 6a), it's also 5 years, but only 3 major Android upgrades and 2 of security updates. Not as good as an iPhone (5-6 years), but it's improving.

If you include years where you only get a security update, but not an OS update, then the 2014 iPhone 5s is still supported today, since it's last update was in August.

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#66
post #46
post #32

Earlier quoted context omitted.

> The main issue to me seems to be sideloading apps I think you could phrase that better. Sideloading apps is not an "issue", it's an incredibly important tool that developers can use to audit the behavior of apps.

Google could do what Apple does, and allow sideloading for a limited time only to those with a paid developer account. With the continuing security problems, it is increasingly being proven out that Apple got the app ecosystem right, from the get-go, with their walled garden approach. The benefits of such vastly outweigh the costs to a few tinkerers (and malicious actors) when you're building a product for the averag…

Anybody can sideload without a developer account, but your phone will have to connect to your home WiFi network at least once a week for your PC or Mac to keep the app on your phone authorized.

If you do have a developer account, your device only has to connect to your home WiFi network once a year for your computer to keep the app authorized.

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#68
post #64

Earlier quoted context omitted.

>I’ve avoided Samsung anything for years because of their total disregard for security and total contempt towards their users. The thing is, if you live in the west then all the other major Android brands aren't better at all. There just are no good options anymore. HTC went bust, OnePlus turned to shit, LG threw in the towel, Sony's SW updates cycle is unimpressive for how expensive they are, Google Pixels are buggy…

> Google Pixels are buggy as hell, That hasn't been my experience.

That's funny since the Pixel 6 has had so many people complaining about various bugs.

Google has no quality consistency both with SW and HW, it's all hit and miss with their Pixel range. Some turned out great, some were abasically e-waste.

IMHO they peaked with the Nexus 5 and then went downhill after that. Then current Pixel 7 seems to be an exception.

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#69

Just when it seems like we’ve reached the bottom on the level of Samsung’s incompetence, it just drops deeper. I’ve avoided Samsung anything for years because of their total disregard for security and total contempt towards their users.

>I’ve avoided Samsung anything for years because of their total disregard for security and total contempt towards their users. The thing is, if you live in the west then all the other major Android brands aren't better at all. There just are no good options anymore. HTC went bust, OnePlus turned to shit, LG threw in the towel, Sony's SW updates cycle is unimpressive for how expensive they are, Google Pixels are buggy…

For about 300 eur you can get 1.5 used iPhone SE 2020 in perfect condition. I know, I’ve bought several recently. Not saying Apple is the greatest in general but that’s an alternative. I personally don’t regret switching over to iPhones years ago. And I only ever buy iPhones from Apple. And I buy them used because they’re insanely expensive otherwise.

That aside, Samsung’s shittiness extends far beyond smartphones. Their TVs are a disaster, their appliances fail just outside warranty, their wearable and speakers are spyware just like the rest of their products… the only thing from them not on my shitlist are semis or components like ram because there isn’t much that can go wrong on this kind of commodity product.

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#70

Earlier quoted context omitted.

So the signing key for Samsung Android phones were leaked so that any software that is loaded is signed such that it comes from the App Store is trusted. The problem for OEMs is that developing and distributing a new key requires a Firmware update and it isn't trivial to develop for QA/QC because if they make a mistake with the keys then devices could be unable to load apps from the App Store.

>> and it isn't trivial to develop for QA/QC because if they make a mistake with the keys then devices could be unable to load apps from the App Store. Well then they better do some f..ing testing. They're only one of the biggest tech companies in existence. Making phones isn't trivial either!

Making a phone is dead easy: contract one of the ton of third party manufacturers in China to supply you with one of their white-label designs, pay for them and ship them.

The stuff around it is where the complexity lies: making sure you get updates and have infrastructure to distribute these to customers, that you apply for and get certifications from regulatory agencies and, in the US, carriers, deal with e-waste and warranty regulatory requirements (which is a pain in the EU), establish a supply chain for spare parts...

Post reply on HN