Live data from Hacker News

Samsung’s Android app-signing key has leaked, is being used to sign malware

arstechnica.com

101–110 of 134 posts

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#101
post #2

For once the headline is underselling the scope of the issue. "some of the compromised keys: Samsung, LG, and Mediatek are the heavy hitters on the list of leaked keys, along with some smaller OEMs like Revoview and Szroco, which makes Walmart's Onn tablets."

"Mediatek" is functionally equivalent to "every cheap Android device".

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#102
post #96
post #59

Earlier quoted context omitted.

No.

Why not? Do the Android packages Samsung sends to its own TVs use a different key or security mechanism? (Do we expect Samsung better protects its TV keys, than its smartphone keys?)

I think you'd also need their SSL cert for the HTTPS request.

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#103
post #4

> “Samsung takes the security of Galaxy devices seriously. We have issued security patches since 2016 upon being made aware of the issue“ They’ve known about it since 2016!?!

I think the more generous take is that they resigned all their security patches back to 2016 with a new key?

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#104
While it's obviously bad that people are making malware with this key, I do wonder if there could be a silver lining. Samsung and Google lock a lot of cool permissions behind system apps. I wonder if you could use this key to sign you own apps (or make modified versions of existing system apps) and get the benefits of rooting without actually rooting (especially on devises that don't allow unlocking the bootloader)?

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#105

Earlier quoted context omitted.

I don't know how to feel about those "security updates". That iPhone 5s is still running an outdated Safari browser, for example. The device isn't secure. When I think about long term support, I'm thinking about the kind of support Windows, Linux LTS, etc, provide. When Apple, Samsung, etc, release the type of updates you mention, they're just fixing one of the many security problems the device has. It's like fixing…

You’re saying that Webkit hasn’t been updated on the 5s? How do you know?

The changelog for iOS 12.5.6 mentions a fix for a Webkit exploit, so I guess Webkit was updated? The current version of Webkit/Safari doesn't run on iOS 12 (released in 2018) though (as far as I'm aware).

On a side note, if we want to use this a proof of good long term support, then Android is even better. Phones running Android 7 (2016) are using the latest Chrome/Webview version (108). The difference is that updates are delivered via the Play Store and not as system updates.

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#106
post #46
post #32

Earlier quoted context omitted.

> The main issue to me seems to be sideloading apps I think you could phrase that better. Sideloading apps is not an "issue", it's an incredibly important tool that developers can use to audit the behavior of apps.

Google could do what Apple does, and allow sideloading for a limited time only to those with a paid developer account. With the continuing security problems, it is increasingly being proven out that Apple got the app ecosystem right, from the get-go, with their walled garden approach. The benefits of such vastly outweigh the costs to a few tinkerers (and malicious actors) when you're building a product for the averag…

Apple doing what they do is the main reason I will never buy an iPhone. It's my phone and I should be able to install whatever I want on it.

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#107
post #2

For once the headline is underselling the scope of the issue. "some of the compromised keys: Samsung, LG, and Mediatek are the heavy hitters on the list of leaked keys, along with some smaller OEMs like Revoview and Szroco, which makes Walmart's Onn tablets."

"Mediatek" is functionally equivalent to "every cheap Android device".

No post body was provided.

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#108

While it's obviously bad that people are making malware with this key, I do wonder if there could be a silver lining. Samsung and Google lock a lot of cool permissions behind system apps. I wonder if you could use this key to sign you own apps (or make modified versions of existing system apps) and get the benefits of rooting without actually rooting (especially on devises that don't allow unlocking the bootloader)?

No post body was provided.

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#109

Earlier quoted context omitted.

I used to feel that way, but since the S10 series, there are very few things built into the Galaxy line that fall in the description of shitware anymore. McAfee's device protection shit definitely, but other than that, I can't think of any forced crapware on my last 3 unlocked Galaxy devices.

Do you specifically mean Galaxy S? I bought a Galaxy A33 the other day for my mother. It came full of crapware. All kinds of Samsung this-or-the-other. Some of the apps can be disabled, but not all. Like parts of Bixby (= Samsung's assistant? no idea) can be disabled if you click through a warning, but others cannot. There is also a bunch of 3rd party crap pre-installed, like MS Onedrive, Facebook, Tiktok. And it pus…

No post body was provided.

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#110
post #64

Earlier quoted context omitted.

>I’ve avoided Samsung anything for years because of their total disregard for security and total contempt towards their users. The thing is, if you live in the west then all the other major Android brands aren't better at all. There just are no good options anymore. HTC went bust, OnePlus turned to shit, LG threw in the towel, Sony's SW updates cycle is unimpressive for how expensive they are, Google Pixels are buggy…

> Google Pixels are buggy as hell, That hasn't been my experience.

Hm...

1. GPS didn't work in the background for me. A few OS updates and some Waze updates later it seems I do get turn-by-turn directions.

2. GPU artefacts in Minecraft and Firefox. A few OS, Minecraft and Firefox updates later and it all "just works".

3. Fingerprint sensor works well except when you need it. Murphy's law for sure.

4. I'm in a low signal area and it seems to be unable to receive calls sometimes. I've had people tell me they called and my phone just didn't ring (it's not do not disturb).

Overall is a decent phone but it was a struggle for the high price it had.

Post reply on HN