It could also mean people signing their own firmware and freeing those devices.
Samsung’s Android app-signing key has leaked, is being used to sign malware
41–50 of 134 posts
Re: Samsung’s Android app-signing key has leaked, is being used to sign malware
#42Earlier quoted context omitted.
In the world of Android, apps are signed (including system/platform apps) through a trust-on-first-use system. There's no PKI with roots and intermediates which could support easily enabling a quick fix. On Android, an updated app is validated by the system to be signed by the same signing key hash as was used previously. The most recent (v3, IIRC) apk signing scheme allows you to update an APK and sign it with the o…
Quoted post unavailable.
Re: Samsung’s Android app-signing key has leaked, is being used to sign malware
#43I don't get it, the problem has been known for awhile so why hasn't the key been replaced? Anyone can do a ELI5 on the app signing key replacement difficulty? It isn't covered in the article and seems too high level for a layman like me.
In the world of Android, apps are signed (including system/platform apps) through a trust-on-first-use system. There's no PKI with roots and intermediates which could support easily enabling a quick fix. On Android, an updated app is validated by the system to be signed by the same signing key hash as was used previously. The most recent (v3, IIRC) apk signing scheme allows you to update an APK and sign it with the o…
Re: Samsung’s Android app-signing key has leaked, is being used to sign malware
#44Earlier quoted context omitted.
It’s my understanding that most Android devices don’t get OEM updates for very long
My S9 was getting updates as late as a few weeks ago.
Re: Samsung’s Android app-signing key has leaked, is being used to sign malware
#45Earlier quoted context omitted.
Last shitware i can remember was the 3rd party IR remote control software they bundled with Note3/4, because a couple years later it was updated to have ads on lockscreen. But it was easily disableable from the app list. The latest Samsung device i have is tab s8 from this year and the software i would call bloat was all the Google stuff like Youtube, Youtube music, Duo, Chrome, Google search. And worst of all the Go…
You bought a android phone. Google forces Samsung to put their Google crap on it and activate/ configure it a certain way before they certify the device firmware for Google play store download/access. If you don't want it the only option is a non android os such as oxygen.
Re: Samsung’s Android app-signing key has leaked, is being used to sign malware
#46The main issue to me seems to be sideloading apps, playstore apps seem to be protected. Sideloaded apps could be anything since its the app key that is compromised.
> The main issue to me seems to be sideloading apps I think you could phrase that better. Sideloading apps is not an "issue", it's an incredibly important tool that developers can use to audit the behavior of apps.
With the continuing security problems, it is increasingly being proven out that Apple got the app ecosystem right, from the get-go, with their walled garden approach. The benefits of such vastly outweigh the costs to a few tinkerers (and malicious actors) when you're building a product for the average bear.
Re: Samsung’s Android app-signing key has leaked, is being used to sign malware
#47I mean considering the level of shitware samsung install on their phones (and make difficult to remove or disable) it will be hard to tell the difference between the official stuff and straight up honest malware.
I used to feel that way, but since the S10 series, there are very few things built into the Galaxy line that fall in the description of shitware anymore. McAfee's device protection shit definitely, but other than that, I can't think of any forced crapware on my last 3 unlocked Galaxy devices.
To add injury Bixby hijacks a physical button and Samsung Pay a swipe direction.
Re: Samsung’s Android app-signing key has leaked, is being used to sign malware
#48I don't get it, the problem has been known for awhile so why hasn't the key been replaced? Anyone can do a ELI5 on the app signing key replacement difficulty? It isn't covered in the article and seems too high level for a layman like me.
So the signing key for Samsung Android phones were leaked so that any software that is loaded is signed such that it comes from the App Store is trusted. The problem for OEMs is that developing and distributing a new key requires a Firmware update and it isn't trivial to develop for QA/QC because if they make a mistake with the keys then devices could be unable to load apps from the App Store.
Re: Samsung’s Android app-signing key has leaked, is being used to sign malware
#49Re: Samsung’s Android app-signing key has leaked, is being used to sign malware
#50Earlier quoted context omitted.
This is true in the sense that most android devices are small/cheap off brand or Chinese devices sold across low-income markets, like Africa and the Middle East. Any mid- or top-tier Android devices, such as Pixels and Galaxy devices which compete directly with Apple, are usually on a monthly security update cadence for at least 3 years.
3 years of support sounds like the bare minimum you can expect, and that is what the most expensive brand offer?