Live data from Hacker News

Samsung’s Android app-signing key has leaked, is being used to sign malware

arstechnica.com

111–120 of 134 posts

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#112
post #96

Earlier quoted context omitted.

Why not? Do the Android packages Samsung sends to its own TVs use a different key or security mechanism? (Do we expect Samsung better protects its TV keys, than its smartphone keys?)

I think you'd also need their SSL cert for the HTTPS request.

Are you assuming Samsung's updates rigorously use SSL, with proper certificate checking, or do you know that to be the fact?

These sorts of consumer-device companies often take other unwise security-through-obscurity, or only "folk-secure", shortcuts elsewhere – rather than defense in depth.

For example, thinking their app-signing keys secure, maybe they used something other than SSL, or SSL in some no-certificate-validation-mode.

It happens more than it should, with giant consumer-electronics conglomerates, even!

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#113

Earlier quoted context omitted.

It got better in the past 2 years. The latest Pixel or Samsung gives you 5 years of support. 3 major updates + 2 years of security updates on the Pixel and 4 major updates + 1 year of security updates on a Samsung. An iPhone gets you 6 major iOS updates, I think.

It's taken them up to the past 2 years to still be this much less than a competitor? We've had smart devices like this since 2007. It took 13 years to get to a point of still being inferior. You're not impressing me at all here.

If Qualcomm stops supporting a particular chipset version after N years, all the Android OEMs that use Qualcomm chips can't do anything about it. Apple, however, builds their own SoCs, so they can support them as long as they want.

Google has recently managed to strike some better deals with Qualcomm to get updates for 5 years for the latest crop of Pixel devices. I agree it's still not as good as Apple, but that's just how market forces work, and shows you who has the most leverage.

I don't think anyone is trying to "impress" anyone; merely stating the facts as they are.

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#114
post #46
post #32

Earlier quoted context omitted.

> The main issue to me seems to be sideloading apps I think you could phrase that better. Sideloading apps is not an "issue", it's an incredibly important tool that developers can use to audit the behavior of apps.

Google could do what Apple does, and allow sideloading for a limited time only to those with a paid developer account. With the continuing security problems, it is increasingly being proven out that Apple got the app ecosystem right, from the get-go, with their walled garden approach. The benefits of such vastly outweigh the costs to a few tinkerers (and malicious actors) when you're building a product for the averag…

No thanks, hard pass. A big reason I use Android rather than iOS is because I can install whatever I want on the hardware I've purchased. I put up with Android's worse security posture because I value this.

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#116
post #2

For once the headline is underselling the scope of the issue. "some of the compromised keys: Samsung, LG, and Mediatek are the heavy hitters on the list of leaked keys, along with some smaller OEMs like Revoview and Szroco, which makes Walmart's Onn tablets."

"Mediatek" is functionally equivalent to "every cheap Android device".

They also show up in a million other places.

That Sony Google TV? MediaTek.

Google Chromecast? MediaTek.

Blu-ray Player? MediaTek.

Random IoT device? Likely MediaTek.

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#117
post #74

Earlier quoted context omitted.

It's taken them up to the past 2 years to still be this much less than a competitor? We've had smart devices like this since 2007. It took 13 years to get to a point of still being inferior. You're not impressing me at all here.

It's probably not a huge priority, given the replacement cadence of most phone users. https://www.statista.com/statistics/619788/average-smartphon... . If, on average, people are replacing their phone within three years, 5 years or more of support is largely marketing.

I agree with this. 5 years seems like plenty until smartphones sufficiently plateau resulting in longer ownership. I believe this is another case of HN's biases versus the 80-90% that the major players actually build for.

And ironically, I highly doubt the majority of the users here on HN use their devices through their EOL. They just like the idea, philosophically.

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#118

Earlier quoted context omitted.

"Mediatek" is functionally equivalent to "every cheap Android device".

They also show up in a million other places. That Sony Google TV? MediaTek. Google Chromecast? MediaTek. Blu-ray Player? MediaTek. Random IoT device? Likely MediaTek.

A chromecast might have mediatek SoC but it won't be using their signing keys. Would assume Sony have their own keys and platform setup too.

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#119
post #113

Earlier quoted context omitted.

It's taken them up to the past 2 years to still be this much less than a competitor? We've had smart devices like this since 2007. It took 13 years to get to a point of still being inferior. You're not impressing me at all here.

If Qualcomm stops supporting a particular chipset version after N years, all the Android OEMs that use Qualcomm chips can't do anything about it. Apple, however, builds their own SoCs, so they can support them as long as they want. Google has recently managed to strike some better deals with Qualcomm to get updates for 5 years for the latest crop of Pixel devices. I agree it's still not as good as Apple, but that's j…

> Google has recently managed to strike some better deals with Qualcomm to get updates for 5 years for the latest crop of Pixel devices

The last 2 generations of Pixels use Google's own SoC (developed with Samsung?) called Tensor[0].

Google deserves some criticism here. The main force behind Android is now behind Apple and other Android brands. Samsung uses a mix of Qualcomm and Exynos, and their flagships get 4 major Android updates. OnePlus, which relies on Qualcomm and Mediatek, will do the same for "selected devices"[1]. A Pixel 7 only gets 3 major updates... at least the phone receives security updates for 5 years, but they need to improve.

[0] https://en.wikipedia.org/wiki/Google_Tensor [1] https://www.xda-developers.com/oneplus-four-platform-updates...

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#120
post #80
post #55

Earlier quoted context omitted.

Samsung generally takes several months to fix 0days. source: have owned a samsung and took notice of when the update came

Samsung improved it's update process (and probably pipeline?) dramatically in the past years[1] and the software became much better and more polished. I received the Android 13 update in November and less than two weeks later another security update. This indicates to me that they roll out updates as fast as possible. Normally I get the monthly security update in the first half of the month. EDIT: I should probably m…

> I should probably mention that I usually only buy Samsung's flagships but the midrange device are getting the same treatment AFAIK.

I really don't have that kind of money to just drop on a phone that will inevitably fall from my pocket and break because it's too damn big. My phones cost less than 200€, and since they aren't samsung they get timely updates.

Post reply on HN