Samsung’s Android app-signing key has leaked, is being used to sign malware
111–120 of 134 posts
Re: Samsung’s Android app-signing key has leaked, is being used to sign malware
#112Earlier quoted context omitted.
Why not? Do the Android packages Samsung sends to its own TVs use a different key or security mechanism? (Do we expect Samsung better protects its TV keys, than its smartphone keys?)
I think you'd also need their SSL cert for the HTTPS request.
These sorts of consumer-device companies often take other unwise security-through-obscurity, or only "folk-secure", shortcuts elsewhere – rather than defense in depth.
For example, thinking their app-signing keys secure, maybe they used something other than SSL, or SSL in some no-certificate-validation-mode.
It happens more than it should, with giant consumer-electronics conglomerates, even!
Re: Samsung’s Android app-signing key has leaked, is being used to sign malware
#113Earlier quoted context omitted.
It got better in the past 2 years. The latest Pixel or Samsung gives you 5 years of support. 3 major updates + 2 years of security updates on the Pixel and 4 major updates + 1 year of security updates on a Samsung. An iPhone gets you 6 major iOS updates, I think.
It's taken them up to the past 2 years to still be this much less than a competitor? We've had smart devices like this since 2007. It took 13 years to get to a point of still being inferior. You're not impressing me at all here.
Google has recently managed to strike some better deals with Qualcomm to get updates for 5 years for the latest crop of Pixel devices. I agree it's still not as good as Apple, but that's just how market forces work, and shows you who has the most leverage.
I don't think anyone is trying to "impress" anyone; merely stating the facts as they are.
Re: Samsung’s Android app-signing key has leaked, is being used to sign malware
#114Earlier quoted context omitted.
> The main issue to me seems to be sideloading apps I think you could phrase that better. Sideloading apps is not an "issue", it's an incredibly important tool that developers can use to audit the behavior of apps.
Google could do what Apple does, and allow sideloading for a limited time only to those with a paid developer account. With the continuing security problems, it is increasingly being proven out that Apple got the app ecosystem right, from the get-go, with their walled garden approach. The benefits of such vastly outweigh the costs to a few tinkerers (and malicious actors) when you're building a product for the averag…
Re: Samsung’s Android app-signing key has leaked, is being used to sign malware
#115Re: Samsung’s Android app-signing key has leaked, is being used to sign malware
#116For once the headline is underselling the scope of the issue. "some of the compromised keys: Samsung, LG, and Mediatek are the heavy hitters on the list of leaked keys, along with some smaller OEMs like Revoview and Szroco, which makes Walmart's Onn tablets."
"Mediatek" is functionally equivalent to "every cheap Android device".
That Sony Google TV? MediaTek.
Google Chromecast? MediaTek.
Blu-ray Player? MediaTek.
Random IoT device? Likely MediaTek.
Re: Samsung’s Android app-signing key has leaked, is being used to sign malware
#117Earlier quoted context omitted.
It's taken them up to the past 2 years to still be this much less than a competitor? We've had smart devices like this since 2007. It took 13 years to get to a point of still being inferior. You're not impressing me at all here.
It's probably not a huge priority, given the replacement cadence of most phone users. https://www.statista.com/statistics/619788/average-smartphon... . If, on average, people are replacing their phone within three years, 5 years or more of support is largely marketing.
And ironically, I highly doubt the majority of the users here on HN use their devices through their EOL. They just like the idea, philosophically.
Re: Samsung’s Android app-signing key has leaked, is being used to sign malware
#118Earlier quoted context omitted.
"Mediatek" is functionally equivalent to "every cheap Android device".
They also show up in a million other places. That Sony Google TV? MediaTek. Google Chromecast? MediaTek. Blu-ray Player? MediaTek. Random IoT device? Likely MediaTek.
Re: Samsung’s Android app-signing key has leaked, is being used to sign malware
#119Earlier quoted context omitted.
It's taken them up to the past 2 years to still be this much less than a competitor? We've had smart devices like this since 2007. It took 13 years to get to a point of still being inferior. You're not impressing me at all here.
If Qualcomm stops supporting a particular chipset version after N years, all the Android OEMs that use Qualcomm chips can't do anything about it. Apple, however, builds their own SoCs, so they can support them as long as they want. Google has recently managed to strike some better deals with Qualcomm to get updates for 5 years for the latest crop of Pixel devices. I agree it's still not as good as Apple, but that's j…
The last 2 generations of Pixels use Google's own SoC (developed with Samsung?) called Tensor[0].
Google deserves some criticism here. The main force behind Android is now behind Apple and other Android brands. Samsung uses a mix of Qualcomm and Exynos, and their flagships get 4 major Android updates. OnePlus, which relies on Qualcomm and Mediatek, will do the same for "selected devices"[1]. A Pixel 7 only gets 3 major updates... at least the phone receives security updates for 5 years, but they need to improve.
[0] https://en.wikipedia.org/wiki/Google_Tensor [1] https://www.xda-developers.com/oneplus-four-platform-updates...
Re: Samsung’s Android app-signing key has leaked, is being used to sign malware
#120Earlier quoted context omitted.
Samsung generally takes several months to fix 0days. source: have owned a samsung and took notice of when the update came
Samsung improved it's update process (and probably pipeline?) dramatically in the past years[1] and the software became much better and more polished. I received the Android 13 update in November and less than two weeks later another security update. This indicates to me that they roll out updates as fast as possible. Normally I get the monthly security update in the first half of the month. EDIT: I should probably m…
I really don't have that kind of money to just drop on a phone that will inevitably fall from my pocket and break because it's too damn big. My phones cost less than 200€, and since they aren't samsung they get timely updates.