Live data from Hacker News

UC Browser for Android, Desktop Exposes 500M Users to MiTM Attacks

bleepingcomputer.com

21–30 of 62 posts

Re: UC Browser for Android, Desktop Exposes 500M Users to MiTM Attacks

#21
post #19

> using unprotected channels It's not man in the middle. I have seen this mistake a lot lately. Man in the middle only involves encryption. Otherwise it is just injection or redirection. It is not a man in the middle attack merely because something happened in the middle of a transmission. There is always stuff that happens in the middle of transmission if you want to get technical about packet switching ARP resoluti…

Not going to down-vote just because you’re wrong, since you bring up a cogent argument. But it’s still wrong nevertheless. I’ve skimmed the linked Wikipedia article. Could you quote from that article that MITM requires intercepting a certificate or key request?

> As an attack that aims at circumventing mutual authentication, or lack thereof, an MITM attack can succeed only when the attacker can impersonate each endpoint to their satisfaction

According to the Wikipedia definition a MITM attack must impersonate the end point to each end point. Altering the integrity of a communication or reading the contents thereof does not meet that definition. Also, every part of the Defense and Detection section of the article is specifically about encryption, particularly PKI keys and CA issued certificates.

You never said how I am wrong.

Re: UC Browser for Android, Desktop Exposes 500M Users to MiTM Attacks

#22
post #4

People really use this browser?

Sure, lots of people install custom browsers because they don't like the standard ones, myself included. Fennec (Firefox but from f-droid) is super slow, Chrome is not an option for privacy, but Lightning[1] is fast and has most of the features I want so that's what I use at the moment. It might be vulnerable for something, but I'm taking my chances with some lesser-known browser versus having the pain of a super slow browser all the time. This is also one of the reasons I don't have a banking app installed or have ssh keys on my phone or something: my phone is just not as trusted as my laptop.

I remember that UC is one of the ones I looked at, probably even installed to try it out.

Edit: sibling comments mention popularity in India or Asia, but I'm from the Netherlands. My brother also has a habit of finding custom things (independently from me), sometimes quite questionable apps... it's not just asians that install non-google apps.

[1] https://f-droid.org/en/packages/acr.browser.lightning/

Re: UC Browser for Android, Desktop Exposes 500M Users to MiTM Attacks

#23
post #16

Just had a quick Google and this company is owned by Alibaba: https://en.wikipedia.org/wiki/UC_Browser Seems like they've already been in hot water for vulnerabilities in their browser: https://www.cbc.ca/news/canada/spy-agencies-target-mobile-ph...

What conclusion do you draw from that company being owned by Alibaba? I don't see the relevance of this.

Re: UC Browser for Android, Desktop Exposes 500M Users to MiTM Attacks

#25
post #23
post #16

Just had a quick Google and this company is owned by Alibaba: https://en.wikipedia.org/wiki/UC_Browser Seems like they've already been in hot water for vulnerabilities in their browser: https://www.cbc.ca/news/canada/spy-agencies-target-mobile-ph...

What conclusion do you draw from that company being owned by Alibaba? I don't see the relevance of this.

https://www.uc.cn/

If you are meaning of the evidence of UC connected to Alibaba, I think this site is convincing enough.

[EDIT: Fix link]

Re: UC Browser for Android, Desktop Exposes 500M Users to MiTM Attacks

#26
post #23

Earlier quoted context omitted.

What conclusion do you draw from that company being owned by Alibaba? I don't see the relevance of this.

https://www.uc.cn/ If you are meaning of the evidence of UC connected to Alibaba, I think this site is convincing enough. [EDIT: Fix link]

You misunderstood me. I firmly believe UC is owned by Alibaba, but I insist that I don't understand why is that important.

Re: UC Browser for Android, Desktop Exposes 500M Users to MiTM Attacks

#27
post #5
post #4

People really use this browser?

According to Google Play [1] it has >500M installs and about 20M reviews. [1] https://play.google.com/store/apps/details?id=com.UCMobile.i...

That only represents the data of Google Play. Considering China is one of the largest markets of UC, yet doesn't have access to Google Play, the actual number would be a lot more than that.

According to iResearch[1], it has 311m "monthly unique devices" in China in Feb 2019.

[1]. https://index.iresearch.com.cn/app/detail?id=12&Tid=73 (Chinese)

Re: UC Browser for Android, Desktop Exposes 500M Users to MiTM Attacks

#28

> using unprotected channels It's not man in the middle. I have seen this mistake a lot lately. Man in the middle only involves encryption. Otherwise it is just injection or redirection. It is not a man in the middle attack merely because something happened in the middle of a transmission. There is always stuff that happens in the middle of transmission if you want to get technical about packet switching ARP resoluti…

> Man in the middle only involves encryption.

This doesn't feel right to me, so I would like to explore it if you are willing to help me understand. I've grabbed a couple of sources below which appear to contradict your assertion, but I'll admit I'm not expert on this topic so if I'm misunderstanding things, I'd appreciate being put right.

The Wikipedia article you linked to includes the following section:

> A notable non-cryptographic MITM attack was perpetrated by a Belkin wireless network router in 2003. Periodically, it would take over an HTTP connection being routed through it: this would fail to pass the traffic on to destination, but instead itself responded as the intended server. The reply it sent, in place of the web page the user had requested, was an advertisement for another Belkin product.

OWASP's definition uses plaintext HTTP as its primary example of a MITM attack:

https://www.owasp.org/index.php/Man-in-the-middle_attack

> For example, in an http transaction the target is the TCP connection between client and server. Using different techniques, the attacker splits the original TCP connection into 2 new connections, one between the client and the attacker and the other between the attacker and the server, as shown in figure 1. Once the TCP connection is intercepted, the attacker acts as a proxy, being able to read, insert and modify the data in the intercepted communication.

> The MITM attack is very effective because of the nature of the http protocol and data transfer which are all ASCII based

Re: UC Browser for Android, Desktop Exposes 500M Users to MiTM Attacks

#29
post #26

Earlier quoted context omitted.

https://www.uc.cn/ If you are meaning of the evidence of UC connected to Alibaba, I think this site is convincing enough. [EDIT: Fix link]

You misunderstood me. I firmly believe UC is owned by Alibaba, but I insist that I don't understand why is that important.

Useful context for me as I haven't heard of the browser so no knowledge as to how they can have such a large userbase.

I don't think the intention was draw a correlation between Alibaba and security lapses.

Re: UC Browser for Android, Desktop Exposes 500M Users to MiTM Attacks

#30
"It’s impossible to be sure that cybercriminals will never get ahold of the browser developer’s servers or use the update feature to infect hundreds of millions of Android devices."

Apparently they didn't consider the same sentence would be just as valid if they replaced "browser developer" with Google...

This is an example of the authoritarian security sensationalism that's far too common today, and it only leads to the big companies like Google getting even more power over users. One of the most secure places is in an isolated prison cell.

Post reply on HN