Live data from Hacker News

Samsung’s Android app-signing key has leaked, is being used to sign malware

arstechnica.com

21–30 of 134 posts

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#21

Earlier quoted context omitted.

My S9 was getting updates as late as a few weeks ago.

What's the latest security update? I just checked S9 I have in a drawer and it's from March 2022.

My ultra cheap, as in free, Samsung is running Android 12 with security updates from October 1 2022.

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#22
post #7

Earlier quoted context omitted.

It’s my understanding that most Android devices don’t get OEM updates for very long

This is true in the sense that most android devices are small/cheap off brand or Chinese devices sold across low-income markets, like Africa and the Middle East. Any mid- or top-tier Android devices, such as Pixels and Galaxy devices which compete directly with Apple, are usually on a monthly security update cadence for at least 3 years.

3 years of updates is no competition for Apple.

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#23

Earlier quoted context omitted.

I used to feel that way, but since the S10 series, there are very few things built into the Galaxy line that fall in the description of shitware anymore. McAfee's device protection shit definitely, but other than that, I can't think of any forced crapware on my last 3 unlocked Galaxy devices.

You are lucky to have an Unlocked device. Most people don’t and get the carrier’s kitchen sink of added bloat.

Is that a thing anywhere outside of the US? I thought Europe moved past that.

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#24
post #5

I mean considering the level of shitware samsung install on their phones (and make difficult to remove or disable) it will be hard to tell the difference between the official stuff and straight up honest malware.

I used to feel that way, but since the S10 series, there are very few things built into the Galaxy line that fall in the description of shitware anymore. McAfee's device protection shit definitely, but other than that, I can't think of any forced crapware on my last 3 unlocked Galaxy devices.

You have no Samsung-built software beyond the minimum needed to make it work well on the hardware!?

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#25
post #10

Earlier quoted context omitted.

It’s an app signing key. I don’t think it will work for firmware. But I’m not sure. Can someone more knowledgeable about Android’s chain of trust chime in?

Signing your app using this key would allow you to name your app system.uid.android, effectively giving you root for free. You probably won't be able to sign firmware in the Linux sense of the word, but in android world "firmware" is loosely defined and is often used to talk about the android ROM.

that's what i am looking for. any ideas on how to find the key?

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#26
post #22

Earlier quoted context omitted.

This is true in the sense that most android devices are small/cheap off brand or Chinese devices sold across low-income markets, like Africa and the Middle East. Any mid- or top-tier Android devices, such as Pixels and Galaxy devices which compete directly with Apple, are usually on a monthly security update cadence for at least 3 years.

3 years of updates is no competition for Apple.

It got better in the past 2 years. The latest Pixel or Samsung gives you 5 years of support. 3 major updates + 2 years of security updates on the Pixel and 4 major updates + 1 year of security updates on a Samsung. An iPhone gets you 6 major iOS updates, I think.

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#27
post #4

> “Samsung takes the security of Galaxy devices seriously. We have issued security patches since 2016 upon being made aware of the issue“ They’ve known about it since 2016!?!

Who's in charge of certificate stuff in these situations?

No post body was provided.

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#28
post #10

Earlier quoted context omitted.

It’s an app signing key. I don’t think it will work for firmware. But I’m not sure. Can someone more knowledgeable about Android’s chain of trust chime in?

Signing your app using this key would allow you to name your app system.uid.android, effectively giving you root for free. You probably won't be able to sign firmware in the Linux sense of the word, but in android world "firmware" is loosely defined and is often used to talk about the android ROM.

On android only the apps and updates are signed. In the normal system state is the only writable part the encrypted data partition, system,vendor and product are readonly mounted and can be only be mounted in the writable mode after an update is verified and the update binary mounts the partition writable.

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#29
post #5

I mean considering the level of shitware samsung install on their phones (and make difficult to remove or disable) it will be hard to tell the difference between the official stuff and straight up honest malware.

I used to feel that way, but since the S10 series, there are very few things built into the Galaxy line that fall in the description of shitware anymore. McAfee's device protection shit definitely, but other than that, I can't think of any forced crapware on my last 3 unlocked Galaxy devices.

Do you specifically mean Galaxy S?

I bought a Galaxy A33 the other day for my mother. It came full of crapware. All kinds of Samsung this-or-the-other. Some of the apps can be disabled, but not all. Like parts of Bixby (= Samsung's assistant? no idea) can be disabled if you click through a warning, but others cannot.

There is also a bunch of 3rd party crap pre-installed, like MS Onedrive, Facebook, Tiktok.

And it pushes hard to use Onedrive instead of google drive.

There's also a separate, Samsung store, and some functions seem to require a Samsung account.

Re: Samsung’s Android app-signing key has leaked, is being used to sign malware

#30
post #20

Earlier quoted context omitted.

This is true in the sense that most android devices are small/cheap off brand or Chinese devices sold across low-income markets, like Africa and the Middle East. Any mid- or top-tier Android devices, such as Pixels and Galaxy devices which compete directly with Apple, are usually on a monthly security update cadence for at least 3 years.

3 years of support sounds like the bare minimum you can expect, and that is what the most expensive brand offer?

A new Samsung Galaxy S22 (and above) has 5 years of support. 4 major Android updates and 1 year of security updates. For the Pixel 6/7/Pro (including the cheaper 6a), it's also 5 years, but only 3 major Android upgrades and 2 of security updates.

Not as good as an iPhone (5-6 years), but it's improving.

Post reply on HN