Live data from Hacker News

Samsung’s Android app-signing key has leaked, is being used to sign malware

arstechnica.com

91–100 of 134 posts

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#91
post #4

> “Samsung takes the security of Galaxy devices seriously. We have issued security patches since 2016 upon being made aware of the issue“ They’ve known about it since 2016!?!

Maybe for all devices published since 2016?

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#92
post #86
post #83

Let me play devil's advocate here: Could it be that these keys were forced out of these companies by governments and used for their spying business ... and then got lost somewhere there (where the incentives of protecting them is not that high)

That’s not “devil’s advocate”, that’s just baseless conspiracy theory.

Fair on baseless and theory but conspiracy?

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#93
post #77

Earlier quoted context omitted.

> That's funny since the Pixel 6 has had so many people complaining about various bugs. Like what?

* Buggy pull down brightness switcher. * Buggy do not disturb mode * Camera app bugs out when taking photos, random frame drops in video recordings. * Sharing menus - slow, suggestions are poor. * broken launcher + third-party launcher support. * buggy compass calibration * buggy 911 support

I haven't needed to call 911 or use a 3rd party launcher but I haven't noticed any of those other issues.

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#94

Earlier quoted context omitted.

If you include years where you only get a security update, but not an OS update, then the 2014 iPhone 5s is still supported today, since it's last update was in August.

I don't know how to feel about those "security updates". That iPhone 5s is still running an outdated Safari browser, for example. The device isn't secure. When I think about long term support, I'm thinking about the kind of support Windows, Linux LTS, etc, provide. When Apple, Samsung, etc, release the type of updates you mention, they're just fixing one of the many security problems the device has. It's like fixing…

You’re saying that Webkit hasn’t been updated on the 5s?

How do you know?

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#95

Earlier quoted context omitted.

If you include years where you only get a security update, but not an OS update, then the 2014 iPhone 5s is still supported today, since it's last update was in August.

that's an important distinction. i don't have an android, but i get the sense that by "supported" we are talking about continuing to receive security updates. i am not sure my assumption is correct, though. do new samsung phones stop receiving security updates in 5 years?

You get at least 5 years of security updates with a new Samsung flagship[0]. During those 5 years, you'll use 4 major Android versions (there's a new one each year, like iOS). The last year of support is essentially security patches for the Android version released in the previous year.

On top of this, since Android 10 (2019), some security and feature updates come directly from Google (delivered via the app store) and continue after the brand stops supporting the device.

These security updates Apple, Samsung, etc, release years after the phone reaches end-of-life are a bit misleading. The update for the iPhone 5S fixed an exploit on Webkit, but everything else remains unpatched. Same with the update Samsung released for the Galaxy S7 (released before they had a 5 year support policy)... it fixed a GPS bug. That's it.

So while these updates are better than nothing, it's important to understand that the device is not up-to-date or secure.

---

[0] The 50-100 dollars device sold in low income markets won't have the same level of long term support as $500+ devices. We can't compare them to Apple here as Apple doesn't compete in that market.

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#96
post #59
post #57

So, does it look like (auto-)updates of Samsung 'Smart' TVs could be tricked into acepting malware?

No.

Why not? Do the Android packages Samsung sends to its own TVs use a different key or security mechanism?

(Do we expect Samsung better protects its TV keys, than its smartphone keys?)

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#98
post #4

> “Samsung takes the security of Galaxy devices seriously. We have issued security patches since 2016 upon being made aware of the issue“ They’ve known about it since 2016!?!

The article is rather misleading. It is almost certain that Samsung used HSMs to sign their APKs, so the key itself could never actually leak unless someone had physical access to the HSMs themselves and managed to somehow delid it and then put it back together without anyone noticing. I'm not too familiar with the documented attacks on delidding HSMs, but I believe that delidding chips causes permanent damage to them in such a way that they will never function properly again.

It's much more likely that an employee's account was compromised and then used to sign malicious APKs, or something similar. Once Samsung realized, they could get the logs of every APK signed with the HSM and then revoke those certificates individually through a software update. Not really sure if they actually did that or not, but either way the key doesn't necessarily need to be replaced.

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#99
post #4

> “Samsung takes the security of Galaxy devices seriously. We have issued security patches since 2016 upon being made aware of the issue“ They’ve known about it since 2016!?!

The article is rather misleading. It is almost certain that Samsung used HSMs to sign their APKs, so the key itself could never actually leak unless someone had physical access to the HSMs themselves and managed to somehow delid it and then put it back together without anyone noticing. I'm not too familiar with the documented attacks on delidding HSMs, but I believe that delidding chips causes permanent damage to the…

> revoke those certificates individually through a software update

Android doesn't really do revoking certificates in this way. The only way to fix a leak of a system key is to generate a new key and use replace the entire system image.

I hope you're right that this is merely a remote signing account being compromised, because I don't see Samsung building six years of new system images.

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#100
post #7
post #6

Fyi, this is related to the story from 2 days ago: https://news.ycombinator.com/item?id=33823946 An important comment from the original story: > OEMs have mitigated the issues above in previous updates. A new security update from Android is not required to mitigate these issues. Ensuring your device is running the latest version of Android is a general best security practice for users. Though the ars story says Samsu…

It’s my understanding that most Android devices don’t get OEM updates for very long

Manufacturers have been extending the support life cycle for the past few years. Samsung provides five years of updates for most phones, for example, with four years of Android updates. Still not great, but a lot better than the single year of updates you used to get.

Extremely cheap brands don't tend to do updates much, especially Android version updates.

Mid-range phones land somewhere in the middle; some have budget hardware with decent support, but other brands get good hardware for dirt cheap in exchange of basically no software support after buying the phone. The latter is great if you're planning on using custom ROMs to extend the life time of your dirt cheap hardware, but quite terrible for people who are used to buying phones four times the price and expecting the same level of support, thinking they just scored a good deal.

Post reply on HN