Earlier quoted context omitted.
Google could do what Apple does, and allow sideloading for a limited time only to those with a paid developer account. With the continuing security problems, it is increasingly being proven out that Apple got the app ecosystem right, from the get-go, with their walled garden approach. The benefits of such vastly outweigh the costs to a few tinkerers (and malicious actors) when you're building a product for the averag…
Anybody can sideload without a developer account, but your phone will have to connect to your home WiFi network at least once a week for your PC or Mac to keep the app on your phone authorized. If you do have a developer account, your device only has to connect to your home WiFi network once a year for your computer to keep the app authorized.
Samsung’s Android app-signing key has leaked, is being used to sign malware
81–90 of 134 posts
Re: Samsung’s Android app-signing key has leaked, is being used to sign malware
#82Earlier quoted context omitted.
Some intern at the corporate HQ
Which corporation though? Samsung or GOOG?
Re: Samsung’s Android app-signing key has leaked, is being used to sign malware
#83Re: Samsung’s Android app-signing key has leaked, is being used to sign malware
#84Earlier quoted context omitted.
A new Samsung Galaxy S22 (and above) has 5 years of support. 4 major Android updates and 1 year of security updates. For the Pixel 6/7/Pro (including the cheaper 6a), it's also 5 years, but only 3 major Android upgrades and 2 of security updates. Not as good as an iPhone (5-6 years), but it's improving.
If you include years where you only get a security update, but not an OS update, then the 2014 iPhone 5s is still supported today, since it's last update was in August.
Re: Samsung’s Android app-signing key has leaked, is being used to sign malware
#85Earlier quoted context omitted.
A new Samsung Galaxy S22 (and above) has 5 years of support. 4 major Android updates and 1 year of security updates. For the Pixel 6/7/Pro (including the cheaper 6a), it's also 5 years, but only 3 major Android upgrades and 2 of security updates. Not as good as an iPhone (5-6 years), but it's improving.
If you include years where you only get a security update, but not an OS update, then the 2014 iPhone 5s is still supported today, since it's last update was in August.
When I think about long term support, I'm thinking about the kind of support Windows, Linux LTS, etc, provide. When Apple, Samsung, etc, release the type of updates you mention, they're just fixing one of the many security problems the device has.
It's like fixing the lock on a door of a building full of broken windows and call it secure. I guess it's better than nothing, but it's not proper maintenance.
Re: Samsung’s Android app-signing key has leaked, is being used to sign malware
#86Let me play devil's advocate here: Could it be that these keys were forced out of these companies by governments and used for their spying business ... and then got lost somewhere there (where the incentives of protecting them is not that high)
Re: Samsung’s Android app-signing key has leaked, is being used to sign malware
#87Earlier quoted context omitted.
That's funny since the Pixel 6 has had so many people complaining about various bugs. Google has no quality consistency both with SW and HW, it's all hit and miss with their Pixel range. Some turned out great, some were abasically e-waste. IMHO they peaked with the Nexus 5 and then went downhill after that. Then current Pixel 7 seems to be an exception.
> That's funny since the Pixel 6 has had so many people complaining about various bugs. Like what?
Re: Samsung’s Android app-signing key has leaked, is being used to sign malware
#88> These companies somehow had their signing keys leaked to outsiders I can dream, but I would love to know what this "somehow" is. Such a leak is a major security threat to a sizeable portion of phone users. Disclaiming what happened and what you are doing about it would be good. Generally speaking I don't have much trust in anything a large company is building. In this case, this is very likely they haven't used an…
Re: Samsung’s Android app-signing key has leaked, is being used to sign malware
#89Earlier quoted context omitted.
Who's in charge of certificate stuff in these situations?
I don't know if this has changed since I last looked a few years ago (around 2018-2019), but: The app-signing key can't be changed without just creating a new app, and creating a new app means you users won't be able to upgrade - they have to manually uninstall, go to the app store, and install the new one. It's not just an app store thing, I think I remember Android itself verifies that the upgrades have the same ke…
https://source.android.com/docs/security/features/apksigning...
Re: Samsung’s Android app-signing key has leaked, is being used to sign malware
#90> These companies somehow had their signing keys leaked to outsiders I can dream, but I would love to know what this "somehow" is. Such a leak is a major security threat to a sizeable portion of phone users. Disclaiming what happened and what you are doing about it would be good. Generally speaking I don't have much trust in anything a large company is building. In this case, this is very likely they haven't used an…
> I would love to know what this "somehow" is. Multiple independent business units developing apps and needing to share the same signing key. Probably contracting out development to other firms. Neither Google or Apple offer robust ways to effectively delegate App develop while retaining secrets needed to publish an App. So you effectively need a FTE managing and supporting all of these groups.