Live data from Hacker News

Samsung’s Android app-signing key has leaked, is being used to sign malware

arstechnica.com

71–80 of 134 posts

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#71

Earlier quoted context omitted.

>I’ve avoided Samsung anything for years because of their total disregard for security and total contempt towards their users. The thing is, if you live in the west then all the other major Android brands aren't better at all. There just are no good options anymore. HTC went bust, OnePlus turned to shit, LG threw in the towel, Sony's SW updates cycle is unimpressive for how expensive they are, Google Pixels are buggy…

For about 300 eur you can get 1.5 used iPhone SE 2020 in perfect condition. I know, I’ve bought several recently. Not saying Apple is the greatest in general but that’s an alternative. I personally don’t regret switching over to iPhones years ago. And I only ever buy iPhones from Apple. And I buy them used because they’re insanely expensive otherwise. That aside, Samsung’s shittiness extends far beyond smartphones. T…

You're moving the goal-posts. I was talking about new phones, not second hand one, as many people prefer buying new for the full 2 year warranty and that added peace of mind. A basic new SE is 550 Euros, far away from the ~300 Euros price bracket. Also, I haven't found used iPhones to buy directly from Apple in EU. Maybe you can point me in the right direction.

I tried to get my mom a 2020 SE since that's the phone my employer gave me and she hated the tiny, dim, low resolution display but she loves her Samsung A52 though, with its big and bright OLED display while being cheaper than the SE. Also battery life is longer on her A52 than on my work SE.

Different people have different requirements for a smartphone that go beyond the brand and reputation (display size, brightness, USB-C, etc). iPhone SE is not a one-size fits all solution for everyone.

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#72
post #21

Earlier quoted context omitted.

What's the latest security update? I just checked S9 I have in a drawer and it's from March 2022.

My ultra cheap, as in free, Samsung is running Android 12 with security updates from October 1 2022.

“Free” means paid through your contract though, so that doesn’t really add anything to your point.

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#73
post #7

Earlier quoted context omitted.

It’s my understanding that most Android devices don’t get OEM updates for very long

My S9 was getting updates as late as a few weeks ago.

When did that come out?

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#74

Earlier quoted context omitted.

It got better in the past 2 years. The latest Pixel or Samsung gives you 5 years of support. 3 major updates + 2 years of security updates on the Pixel and 4 major updates + 1 year of security updates on a Samsung. An iPhone gets you 6 major iOS updates, I think.

It's taken them up to the past 2 years to still be this much less than a competitor? We've had smart devices like this since 2007. It took 13 years to get to a point of still being inferior. You're not impressing me at all here.

It's probably not a huge priority, given the replacement cadence of most phone users.

https://www.statista.com/statistics/619788/average-smartphon....

If, on average, people are replacing their phone within three years, 5 years or more of support is largely marketing.

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#75

Earlier quoted context omitted.

It got better in the past 2 years. The latest Pixel or Samsung gives you 5 years of support. 3 major updates + 2 years of security updates on the Pixel and 4 major updates + 1 year of security updates on a Samsung. An iPhone gets you 6 major iOS updates, I think.

It's taken them up to the past 2 years to still be this much less than a competitor? We've had smart devices like this since 2007. It took 13 years to get to a point of still being inferior. You're not impressing me at all here.

Apple didn't start with 6 years of support. Everyone keeps improving.

Android has to play catch up because of the way it works and because OEMs don't control everything. Apple develops their own SoC, while most Android OEMs have to use a SoC from Qualcomm or Mediatek... which also need to support new Android versions. All this is improving... slowly. In other areas it has been better than iOS for years (eg: apps like the browser receive updates via the app store even after end-of-life, same with some Android features).

Everything has trade-offs. A $500 Windows laptop gets better support than my $3500 Macbook Pro, and we've had laptops for a long, long time. Still, I own a Mac. I also use Android because it lets me do more than iOS.

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#76

Earlier quoted context omitted.

For about 300 eur you can get 1.5 used iPhone SE 2020 in perfect condition. I know, I’ve bought several recently. Not saying Apple is the greatest in general but that’s an alternative. I personally don’t regret switching over to iPhones years ago. And I only ever buy iPhones from Apple. And I buy them used because they’re insanely expensive otherwise. That aside, Samsung’s shittiness extends far beyond smartphones. T…

You're moving the goal-posts. I was talking about new phones, not second hand one, as many people prefer buying new for the full 2 year warranty and that added peace of mind. A basic new SE is 550 Euros, far away from the ~300 Euros price bracket. Also, I haven't found used iPhones to buy directly from Apple in EU. Maybe you can point me in the right direction. I tried to get my mom a 2020 SE since that's the phone m…

Used iPhones from Apple in the EU:

https://www.apple.com/de/shop/refurbished/iphone

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#77
post #64

Earlier quoted context omitted.

> Google Pixels are buggy as hell, That hasn't been my experience.

That's funny since the Pixel 6 has had so many people complaining about various bugs. Google has no quality consistency both with SW and HW, it's all hit and miss with their Pixel range. Some turned out great, some were abasically e-waste. IMHO they peaked with the Nexus 5 and then went downhill after that. Then current Pixel 7 seems to be an exception.

> That's funny since the Pixel 6 has had so many people complaining about various bugs.

Like what?

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#78
post #4

> “Samsung takes the security of Galaxy devices seriously. We have issued security patches since 2016 upon being made aware of the issue“ They’ve known about it since 2016!?!

Who's in charge of certificate stuff in these situations?

I don't know if this has changed since I last looked a few years ago (around 2018-2019), but:

The app-signing key can't be changed without just creating a new app, and creating a new app means you users won't be able to upgrade - they have to manually uninstall, go to the app store, and install the new one.

It's not just an app store thing, I think I remember Android itself verifies that the upgrades have the same key as the old version.

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#79
post #43
post #33

Earlier quoted context omitted.

In the world of Android, apps are signed (including system/platform apps) through a trust-on-first-use system. There's no PKI with roots and intermediates which could support easily enabling a quick fix. On Android, an updated app is validated by the system to be signed by the same signing key hash as was used previously. The most recent (v3, IIRC) apk signing scheme allows you to update an APK and sign it with the o…

So why exactly can't they do an OS update with the new signing keys? OEMs put out OS updates all the time. Plus if they don't want to do that, they could update their individual apps to use the v3 signing schema. They've had 6 years to figure this out.

They can but don't want to. There is no multi-billion profit in that.

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#80
post #55

Earlier quoted context omitted.

This is true in the sense that most android devices are small/cheap off brand or Chinese devices sold across low-income markets, like Africa and the Middle East. Any mid- or top-tier Android devices, such as Pixels and Galaxy devices which compete directly with Apple, are usually on a monthly security update cadence for at least 3 years.

Samsung generally takes several months to fix 0days. source: have owned a samsung and took notice of when the update came

Samsung improved it's update process (and probably pipeline?) dramatically in the past years[1] and the software became much better and more polished.

I received the Android 13 update in November and less than two weeks later another security update. This indicates to me that they roll out updates as fast as possible. Normally I get the monthly security update in the first half of the month.

EDIT: I should probably mention that I usually only buy Samsung's flagships but the midrange device are getting the same treatment AFAIK.

[1] https://www.androidpolice.com/2021/02/22/samsung-solidifies-...

Post reply on HN