> “Samsung takes the security of Galaxy devices seriously. We have issued security patches since 2016 upon being made aware of the issue“ They’ve known about it since 2016!?!
Samsung’s Android app-signing key has leaked, is being used to sign malware
91–100 of 134 posts
Re: Samsung’s Android app-signing key has leaked, is being used to sign malware
#92Let me play devil's advocate here: Could it be that these keys were forced out of these companies by governments and used for their spying business ... and then got lost somewhere there (where the incentives of protecting them is not that high)
That’s not “devil’s advocate”, that’s just baseless conspiracy theory.
Re: Samsung’s Android app-signing key has leaked, is being used to sign malware
#93Earlier quoted context omitted.
> That's funny since the Pixel 6 has had so many people complaining about various bugs. Like what?
* Buggy pull down brightness switcher. * Buggy do not disturb mode * Camera app bugs out when taking photos, random frame drops in video recordings. * Sharing menus - slow, suggestions are poor. * broken launcher + third-party launcher support. * buggy compass calibration * buggy 911 support
Re: Samsung’s Android app-signing key has leaked, is being used to sign malware
#94Earlier quoted context omitted.
If you include years where you only get a security update, but not an OS update, then the 2014 iPhone 5s is still supported today, since it's last update was in August.
I don't know how to feel about those "security updates". That iPhone 5s is still running an outdated Safari browser, for example. The device isn't secure. When I think about long term support, I'm thinking about the kind of support Windows, Linux LTS, etc, provide. When Apple, Samsung, etc, release the type of updates you mention, they're just fixing one of the many security problems the device has. It's like fixing…
How do you know?
Re: Samsung’s Android app-signing key has leaked, is being used to sign malware
#95Earlier quoted context omitted.
If you include years where you only get a security update, but not an OS update, then the 2014 iPhone 5s is still supported today, since it's last update was in August.
that's an important distinction. i don't have an android, but i get the sense that by "supported" we are talking about continuing to receive security updates. i am not sure my assumption is correct, though. do new samsung phones stop receiving security updates in 5 years?
On top of this, since Android 10 (2019), some security and feature updates come directly from Google (delivered via the app store) and continue after the brand stops supporting the device.
These security updates Apple, Samsung, etc, release years after the phone reaches end-of-life are a bit misleading. The update for the iPhone 5S fixed an exploit on Webkit, but everything else remains unpatched. Same with the update Samsung released for the Galaxy S7 (released before they had a 5 year support policy)... it fixed a GPS bug. That's it.
So while these updates are better than nothing, it's important to understand that the device is not up-to-date or secure.
---
[0] The 50-100 dollars device sold in low income markets won't have the same level of long term support as $500+ devices. We can't compare them to Apple here as Apple doesn't compete in that market.
Re: Samsung’s Android app-signing key has leaked, is being used to sign malware
#96So, does it look like (auto-)updates of Samsung 'Smart' TVs could be tricked into acepting malware?
No.
(Do we expect Samsung better protects its TV keys, than its smartphone keys?)
Re: Samsung’s Android app-signing key has leaked, is being used to sign malware
#97Re: Samsung’s Android app-signing key has leaked, is being used to sign malware
#98> “Samsung takes the security of Galaxy devices seriously. We have issued security patches since 2016 upon being made aware of the issue“ They’ve known about it since 2016!?!
It's much more likely that an employee's account was compromised and then used to sign malicious APKs, or something similar. Once Samsung realized, they could get the logs of every APK signed with the HSM and then revoke those certificates individually through a software update. Not really sure if they actually did that or not, but either way the key doesn't necessarily need to be replaced.
Re: Samsung’s Android app-signing key has leaked, is being used to sign malware
#99> “Samsung takes the security of Galaxy devices seriously. We have issued security patches since 2016 upon being made aware of the issue“ They’ve known about it since 2016!?!
The article is rather misleading. It is almost certain that Samsung used HSMs to sign their APKs, so the key itself could never actually leak unless someone had physical access to the HSMs themselves and managed to somehow delid it and then put it back together without anyone noticing. I'm not too familiar with the documented attacks on delidding HSMs, but I believe that delidding chips causes permanent damage to the…
Android doesn't really do revoking certificates in this way. The only way to fix a leak of a system key is to generate a new key and use replace the entire system image.
I hope you're right that this is merely a remote signing account being compromised, because I don't see Samsung building six years of new system images.
Re: Samsung’s Android app-signing key has leaked, is being used to sign malware
#100Fyi, this is related to the story from 2 days ago: https://news.ycombinator.com/item?id=33823946 An important comment from the original story: > OEMs have mitigated the issues above in previous updates. A new security update from Android is not required to mitigate these issues. Ensuring your device is running the latest version of Android is a general best security practice for users. Though the ars story says Samsu…
It’s my understanding that most Android devices don’t get OEM updates for very long
Extremely cheap brands don't tend to do updates much, especially Android version updates.
Mid-range phones land somewhere in the middle; some have budget hardware with decent support, but other brands get good hardware for dirt cheap in exchange of basically no software support after buying the phone. The latter is great if you're planning on using custom ROMs to extend the life time of your dirt cheap hardware, but quite terrible for people who are used to buying phones four times the price and expecting the same level of support, thinking they just scored a good deal.