Live data from Hacker News

Samsung’s Android app-signing key has leaked, is being used to sign malware

arstechnica.com

121–130 of 134 posts

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#121
post #64

Earlier quoted context omitted.

> Google Pixels are buggy as hell, That hasn't been my experience.

Hm... 1. GPS didn't work in the background for me. A few OS updates and some Waze updates later it seems I do get turn-by-turn directions. 2. GPU artefacts in Minecraft and Firefox. A few OS, Minecraft and Firefox updates later and it all "just works". 3. Fingerprint sensor works well except when you need it. Murphy's law for sure. 4. I'm in a low signal area and it seems to be unable to receive calls sometimes. I've…

> . I'm in a low signal area and it seems to be unable to receive calls sometimes. I've had people tell me they called and my phone just didn't ring (it's not do not disturb).

My 5G/LTE performance definitely seems much worst than the Pixel 3a XL I had previously.

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#122

Earlier quoted context omitted.

that's an important distinction. i don't have an android, but i get the sense that by "supported" we are talking about continuing to receive security updates. i am not sure my assumption is correct, though. do new samsung phones stop receiving security updates in 5 years?

You get at least 5 years of security updates with a new Samsung flagship[0]. During those 5 years, you'll use 4 major Android versions (there's a new one each year, like iOS). The last year of support is essentially security patches for the Android version released in the previous year. On top of this, since Android 10 (2019), some security and feature updates come directly from Google (delivered via the app store) a…

The OG $499 iPhone SE from 2016 got six years of OS updates and is still supported with security updates today.

You really can't compare full OS updates AND security updates to years where you just got security updates.

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#123

Earlier quoted context omitted.

You get at least 5 years of security updates with a new Samsung flagship[0]. During those 5 years, you'll use 4 major Android versions (there's a new one each year, like iOS). The last year of support is essentially security patches for the Android version released in the previous year. On top of this, since Android 10 (2019), some security and feature updates come directly from Google (delivered via the app store) a…

The OG $499 iPhone SE from 2016 got six years of OS updates and is still supported with security updates today. You really can't compare full OS updates AND security updates to years where you just got security updates.

I'll repeat myself: long term OS support is better on iPhones. With this said, we must look at what the "security updates" are fixing.

Above you mentioned that the 5S received a security update in August. According to the changelog, all they fixed was an exploit on Webkit (essentially the browser). They didn't even update Webkit/Safari to the latest version (it doesn't work on iOS 12).

Do you know how Android would handle that security update? A simple app update via the Play Store, no restart required. Someone running Android 7, which was released 2 years before iOS 12, is using the latest version of Webview/Chrome (108)... in this regard, Android is actually better than iOS.

There's a big difference between iOS and Android here. On iOS, things like Safari, Photos, Camera, Mail, etc, are part of the system and fixes/new features are presented as part of an updated OS. On Android these things are updated individually via the store and, if applying the same thinking as Apple, receive many "major updates" and many "security updates" every year.

Another point to consider when comparing updates is that since Android 10 (2019) different parts of the system get updates directly from Google ( see: https://blog.esper.io/what-is-project-mainline/ ). A security update for WiFi/Bluetooth, for example, may not need a system update from the OEM.

Android's fragmentation problem forced Google to come up with other ways to update Android. Even for features, many (eg: the alternative to airdrop, a feature to detect/warn about earthquakes, covid app support, etc) are backported to outdated devices without Samsung, etc, releasing system updates.

I don't deny that Android is messier behind the scenes than iOS or am even saying that you should buy an Android device... but it's not as bad as you seem to think.

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#124

Earlier quoted context omitted.

A new Samsung Galaxy S22 (and above) has 5 years of support. 4 major Android updates and 1 year of security updates. For the Pixel 6/7/Pro (including the cheaper 6a), it's also 5 years, but only 3 major Android upgrades and 2 of security updates. Not as good as an iPhone (5-6 years), but it's improving.

If you include years where you only get a security update, but not an OS update, then the 2014 iPhone 5s is still supported today, since it's last update was in August.

Android devices get Chrome updates many years past end of life.

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#125
post #74

Earlier quoted context omitted.

It's probably not a huge priority, given the replacement cadence of most phone users. https://www.statista.com/statistics/619788/average-smartphon... . If, on average, people are replacing their phone within three years, 5 years or more of support is largely marketing.

I agree with this. 5 years seems like plenty until smartphones sufficiently plateau resulting in longer ownership. I believe this is another case of HN's biases versus the 80-90% that the major players actually build for. And ironically, I highly doubt the majority of the users here on HN use their devices through their EOL. They just like the idea, philosophically.

I'm still using my iphone 6s plus from 2015. Smartphones sufficiently plateaued for me a long time ago. It's a shame the rest of you fine folks find everything so inefficient ;-)

I'm guessing there's a generational aspect to this as well, and if the devices are the person's only compute device. The assumption on my part is that the younger users are the ones to upgrade quickly as it is upgrading their only compute device. For someone like me, I'll always prefer a desktop/laptop to use for the sheer usability aspect. I just hate the small screen and hunched over posture of using a phablet-like device. That's me and my opinion, and we all like different things.

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#126

Just when it seems like we’ve reached the bottom on the level of Samsung’s incompetence, it just drops deeper. I’ve avoided Samsung anything for years because of their total disregard for security and total contempt towards their users.

Samsung isn't actually that bad. They augment parts of Android's security model under the 'knox' branding (which is mostly marketing, yes, but they do improve a few things, especially because their Enterprise users ask for these). It's not quite grapheneos but I wouldn't call it disregard for security. For example, they have added an IKEv2 VPN client to the supported system VPN options since Android 6 or so.

They also pioneered the work container before Google started offering this as part of AOSP under the name 'Work Profile'. A feature which is really nice for privacy, separating a user's personal activity from their work activity.

And they're really good at rolling out security patches. Even before apps like SnoopSnitch drew attention to Android OEMs playing loose and fast with patch levels and missing out patches, Samsung was one of the most complete in this area. https://9to5google.com/2018/04/12/android-security-update-mi...

I was a mobile MDM admin of a huge fleet until last year. No commercial involvement with the vendors though because in our company each country picks their own models but technical management is global.

I do have complaints about Samsung like the huge amount of crapware they ship. Upday, facebook, etc. And their ads in their apps. And it's bugging the users to sign up for a personal onedrive account even when they're already signed in to a corporate one :(

But on security I consider them quite good for an Android vendor.

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#127

Earlier quoted context omitted.

You are lucky to have an Unlocked device. Most people don’t and get the carrier’s kitchen sink of added bloat.

Is that a thing anywhere outside of the US? I thought Europe moved past that.

We do, I've not come across a locked device in recent years. Only the cheapest prepaid ones still are. Most people I know don't buy them with a contract anyway, they just buy the device outright. Obviously it's always unlocked then.

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#128
post #96
post #59

Earlier quoted context omitted.

No.

Why not? Do the Android packages Samsung sends to its own TVs use a different key or security mechanism? (Do we expect Samsung better protects its TV keys, than its smartphone keys?)

For starters: Because there are no Samsung TVs running Android which should be trivially verifiable via Google. :)

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#129

Earlier quoted context omitted.

You’re saying that Webkit hasn’t been updated on the 5s? How do you know?

The changelog for iOS 12.5.6 mentions a fix for a Webkit exploit, so I guess Webkit was updated? The current version of Webkit/Safari doesn't run on iOS 12 (released in 2018) though (as far as I'm aware). On a side note, if we want to use this a proof of good long term support, then Android is even better. Phones running Android 7 (2016) are using the latest Chrome/Webview version (108). The difference is that update…

> The difference is that updates are delivered via the Play Store and not as system updates.

You're claiming that the security issue detailed in the article will be fixed through the Play Store, for devices no longer receiving updates from the device maker?

There are advantages to the iOS model of six years of full support followed by security updates for many years later, especially when an actively exploited issue is discovered.

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#130

Earlier quoted context omitted.

The changelog for iOS 12.5.6 mentions a fix for a Webkit exploit, so I guess Webkit was updated? The current version of Webkit/Safari doesn't run on iOS 12 (released in 2018) though (as far as I'm aware). On a side note, if we want to use this a proof of good long term support, then Android is even better. Phones running Android 7 (2016) are using the latest Chrome/Webview version (108). The difference is that update…

> The difference is that updates are delivered via the Play Store and not as system updates. You're claiming that the security issue detailed in the article will be fixed through the Play Store, for devices no longer receiving updates from the device maker? There are advantages to the iOS model of six years of full support followed by security updates for many years later, especially when an actively exploited issue…

> You're claiming that the security issue detailed in the article will be fixed through the Play Store, for devices no longer receiving updates from the device maker?

Yes. The Webkit equivalent (Webview) is updated via the Play Store ( https://play.google.com/store/apps/details?id=com.google.and... ). A bug on Webview would be fixed with an app update, which doesn't even require a restart. Makes sense if we think about it... we don't need a system update to update Chrome/Firefox/Edge/Safari on our computer.

On iOS, a fix or new features on the email, photos, phone, messages, etc, apps are presented as a security/new OS update. On Android, you get an app update.

It's not only apps, they can also update system parts. For example, if there's an issue with the "module" that deals with media, wifi/bluetooth, etc, Google can issue an update and the phone receives it via the Play Store. This article (scroll down) has a list of all modules that can be updated: https://blog.esper.io/what-is-project-mainline/ . I don't know if it's from Google or the different SoC makers, but they can also update things like GPU drivers on newer devices (the user obviously doesn't see any of this).

And Google can backport features without updates from the brand. For example, during the pandemic, Apple and Google added support for Covid apps... in Google's case, they released an update via the store and every phone going back to Android 6 (2015) got it. That's also how they added support for earthquake detection/warnings, nearby share (similar to airdrop), etc.

> There are advantages to the iOS model of six years of full support followed by security updates for many years later, especially when an actively exploited issue is discovered.

Long term support is good and Apple is ahead here offering 5 or 6 major updates. However, it's important to understand what these "security updates" bring.

The iPhone 5s isn't as secure as the iPhone 14 because iOS 12 isn't supported any more. This security update, which was essentially a browser update, reminds me of Microsoft releasing a patch for EOL Windows XP or Win 7 because some malware was taking computers left and right. They fixed one problem, but many remain and you can't consider XP to be safe.

I have used iPhones before (iPhone 5) and am aware of the benefits of Apple's system updates, but we're screwed when those 5 or 6 major updates end. Your browser might get a patch like this, but it's still outdated and doesn't support new web features. On Android, because they are detached from the system, the device maker could be out of business and your 6 year old device running an old Android build will have the latest Chrome, photo gallery, email, etc.

Post reply on HN