Live data from Hacker News

Samsung’s Android app-signing key has leaked, is being used to sign malware

arstechnica.com

81–90 of 134 posts

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#81
post #46

Earlier quoted context omitted.

Google could do what Apple does, and allow sideloading for a limited time only to those with a paid developer account. With the continuing security problems, it is increasingly being proven out that Apple got the app ecosystem right, from the get-go, with their walled garden approach. The benefits of such vastly outweigh the costs to a few tinkerers (and malicious actors) when you're building a product for the averag…

Anybody can sideload without a developer account, but your phone will have to connect to your home WiFi network at least once a week for your PC or Mac to keep the app on your phone authorized. If you do have a developer account, your device only has to connect to your home WiFi network once a year for your computer to keep the app authorized.

[deleted]

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#82

Earlier quoted context omitted.

Some intern at the corporate HQ

Which corporation though? Samsung or GOOG?

Google can add certificates to the CRLs (certification revocation lists) for things they control, but generally, Samsung owns and keeps their private keys, including this one.

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#83
Let me play devil's advocate here: Could it be that these keys were forced out of these companies by governments and used for their spying business ... and then got lost somewhere there (where the incentives of protecting them is not that high)

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#84

Earlier quoted context omitted.

A new Samsung Galaxy S22 (and above) has 5 years of support. 4 major Android updates and 1 year of security updates. For the Pixel 6/7/Pro (including the cheaper 6a), it's also 5 years, but only 3 major Android upgrades and 2 of security updates. Not as good as an iPhone (5-6 years), but it's improving.

If you include years where you only get a security update, but not an OS update, then the 2014 iPhone 5s is still supported today, since it's last update was in August.

that's an important distinction. i don't have an android, but i get the sense that by "supported" we are talking about continuing to receive security updates. i am not sure my assumption is correct, though. do new samsung phones stop receiving security updates in 5 years?

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#85

Earlier quoted context omitted.

A new Samsung Galaxy S22 (and above) has 5 years of support. 4 major Android updates and 1 year of security updates. For the Pixel 6/7/Pro (including the cheaper 6a), it's also 5 years, but only 3 major Android upgrades and 2 of security updates. Not as good as an iPhone (5-6 years), but it's improving.

If you include years where you only get a security update, but not an OS update, then the 2014 iPhone 5s is still supported today, since it's last update was in August.

I don't know how to feel about those "security updates". That iPhone 5s is still running an outdated Safari browser, for example. The device isn't secure.

When I think about long term support, I'm thinking about the kind of support Windows, Linux LTS, etc, provide. When Apple, Samsung, etc, release the type of updates you mention, they're just fixing one of the many security problems the device has.

It's like fixing the lock on a door of a building full of broken windows and call it secure. I guess it's better than nothing, but it's not proper maintenance.

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#86
post #83

Let me play devil's advocate here: Could it be that these keys were forced out of these companies by governments and used for their spying business ... and then got lost somewhere there (where the incentives of protecting them is not that high)

That’s not “devil’s advocate”, that’s just baseless conspiracy theory.

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#87
post #77

Earlier quoted context omitted.

That's funny since the Pixel 6 has had so many people complaining about various bugs. Google has no quality consistency both with SW and HW, it's all hit and miss with their Pixel range. Some turned out great, some were abasically e-waste. IMHO they peaked with the Nexus 5 and then went downhill after that. Then current Pixel 7 seems to be an exception.

> That's funny since the Pixel 6 has had so many people complaining about various bugs. Like what?

* Buggy pull down brightness switcher. * Buggy do not disturb mode * Camera app bugs out when taking photos, random frame drops in video recordings. * Sharing menus - slow, suggestions are poor. * broken launcher + third-party launcher support. * buggy compass calibration * buggy 911 support

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#88

> These companies somehow had their signing keys leaked to outsiders I can dream, but I would love to know what this "somehow" is. Such a leak is a major security threat to a sizeable portion of phone users. Disclaiming what happened and what you are doing about it would be good. Generally speaking I don't have much trust in anything a large company is building. In this case, this is very likely they haven't used an…

not too long ago i belive there was a dump of samsung IP materials, and proprietary tech resources, if it wasnt there somehow, the method could have been in there.

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#89
post #78

Earlier quoted context omitted.

Who's in charge of certificate stuff in these situations?

I don't know if this has changed since I last looked a few years ago (around 2018-2019), but: The app-signing key can't be changed without just creating a new app, and creating a new app means you users won't be able to upgrade - they have to manually uninstall, go to the app store, and install the new one. It's not just an app store thing, I think I remember Android itself verifies that the upgrades have the same ke…

You can do certificate rotation in signing scheme V3 and Android 9+.

https://source.android.com/docs/security/features/apksigning...

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#90

> These companies somehow had their signing keys leaked to outsiders I can dream, but I would love to know what this "somehow" is. Such a leak is a major security threat to a sizeable portion of phone users. Disclaiming what happened and what you are doing about it would be good. Generally speaking I don't have much trust in anything a large company is building. In this case, this is very likely they haven't used an…

> I would love to know what this "somehow" is. Multiple independent business units developing apps and needing to share the same signing key. Probably contracting out development to other firms. Neither Google or Apple offer robust ways to effectively delegate App develop while retaining secrets needed to publish an App. So you effectively need a FTE managing and supporting all of these groups.

Or, and it's crazy but hear me out, use an HSM to sign these apps instead of distributing keys
Post reply on HN