Live data from Hacker News

More Than 1M Google Accounts Breached by Gooligan

blog.checkpoint.com

81–90 of 183 posts

Re: More Than 1M Google Accounts Breached by Gooligan

#81

Malware on your Android device picked up from third party app stores (FDroid? Amazon?) that steals email accounts and auth tokens. Looks like it only works on the older Android 4 Jellybean software (and some Android 5 Lollipop) and below, so mostly concentrated in Asia where there are lower-end phones. You can see if your account has been affected here: https://gooligan.checkpoint.com/

Do you actually know which stores they mean? I'd hate for F-Droid to be vilified. F-Droid isn't just a store, it's an Android Repository Browser[1]. It would be a shame if the F-Droid repository was exploited beyond the concessions[2] that they allow. [1] https://f-droid.org/wiki/page/Known_Repositories [2] https://f-droid.org/wiki/page/Antifeatures

I do not, just wanted to throw a couple that I know of out there. Hopefully neither of those third party stores because I like and use them both. I hope it was clear from the question marks in my post that those were just examples, certainly don't want to smear either one.

Re: More Than 1M Google Accounts Breached by Gooligan

#82
post #60
post #40

We were just reading "Android security in 2016 is a mess"[1] 2 days ago and now we have another great example for it. https://news.ycombinator.com/item?id=13056288

"Windows is a mess because you can install a virus executable on it." "You can't install Windows software outside App Store anymore, MS is taking muh freedoms." You can't win.

You can win. Sane defaults. Allowing the potentially unsafe method "expert mode" is OptIn. I wouldn't buy a car if the dealer held the only key to the hood, still I don't expect everyone to be a grease monkey nor do I think it remarkably safe.

Re: More Than 1M Google Accounts Breached by Gooligan

#84
post #29

Malware on your Android device picked up from third party app stores (FDroid? Amazon?) that steals email accounts and auth tokens. Looks like it only works on the older Android 4 Jellybean software (and some Android 5 Lollipop) and below, so mostly concentrated in Asia where there are lower-end phones. You can see if your account has been affected here: https://gooligan.checkpoint.com/

Thanks for making this comment. This post is a wonderful example of the rampant marketing that has given the security industry a bad name. - The title is technically accurate, which is the best kind of accurate for clickbait. This is not a novel vulnerability representative of an application security flaw within Google - the malware campaign specifically targets older devices using previously known vulnerabilities.[1…

That's not to say Google has no responsibility in this. Google's OS has a terrible security-update policy. Being able to buy a new computing device from a store that will receive no security updates is terrible, and is fairly common in Android devices.

Now, there are valid technical reasons that Google can't be as good as Microsoft at pushing out updates to every device running their OS, but still, it's hard to say that Google has made fixing this problem a priority. Even their own 1st-party devices have a pathetic 2-year upgrade window from launch, which, I'll remind you, still means somebody can buy last year's device on a store shelf and stop getting security updates before the device is even out of warranty.

Re: More Than 1M Google Accounts Breached by Gooligan

#85

Malware on your Android device picked up from third party app stores (FDroid? Amazon?) that steals email accounts and auth tokens. Looks like it only works on the older Android 4 Jellybean software (and some Android 5 Lollipop) and below, so mostly concentrated in Asia where there are lower-end phones. You can see if your account has been affected here: https://gooligan.checkpoint.com/

>Looks like it only works on the older Android 4 Jellybean software (and some Android 5 Lollipop) and below, so mostly concentrated in Asia where there are lower-end phones.

But devices running Android 5 and below "only" comprise the vast majority of devices out there https://developer.android.com/about/dashboards/index.html

Re: More Than 1M Google Accounts Breached by Gooligan

#87
post #82
post #60

Earlier quoted context omitted.

"Windows is a mess because you can install a virus executable on it." "You can't install Windows software outside App Store anymore, MS is taking muh freedoms." You can't win.

You can win. Sane defaults. Allowing the potentially unsafe method "expert mode" is OptIn. I wouldn't buy a car if the dealer held the only key to the hood, still I don't expect everyone to be a grease monkey nor do I think it remarkably safe.

What's "insane" about explicitly having to opt-in to 3rd party application installs in Android ? That switch existed for years and was praised upon. The media opinion only shifted after Android becoming most widely distributed phone OS. It's just easy clicks.

Android is fine.

Re: More Than 1M Google Accounts Breached by Gooligan

#88
post #28

Just to be clear, they didn't obtain any passwords, but auth tokens. This would potentially allow them to log into accounts, but only as long as the tokens are valid. Also, they don't reveal which "third party app stores" served infected apps, but they do provide a list of infected apps, and searching for these yields some real shady download sites: http://imgur.com/a/0luW3

Couldn't Google just revoke all of those access tokens? It'd be a minor inconvenience for some, but it would hardly be a big deal, right? You'd just have to grant access again.

Re: More Than 1M Google Accounts Breached by Gooligan

#89
post #29

Malware on your Android device picked up from third party app stores (FDroid? Amazon?) that steals email accounts and auth tokens. Looks like it only works on the older Android 4 Jellybean software (and some Android 5 Lollipop) and below, so mostly concentrated in Asia where there are lower-end phones. You can see if your account has been affected here: https://gooligan.checkpoint.com/

Thanks for making this comment. This post is a wonderful example of the rampant marketing that has given the security industry a bad name. - The title is technically accurate, which is the best kind of accurate for clickbait. This is not a novel vulnerability representative of an application security flaw within Google - the malware campaign specifically targets older devices using previously known vulnerabilities.[1…

>the malware campaign specifically targets older devices using previously known vulnerabilities.[1] There is no new exploit research here.

That is a false statement where you are implying a certainty that has not yet been established. A Google employee says that as far as they have been able to investigate, several variants use known vulnerabilities.

In any case, there is indeed a giant security flaw when an application executing in a supposed sandbox can get root access. It points to severe design flaws in the application model as well as the underlying OS. The fact that elevation of privilege is almost expected should be unacceptable. Given the terrible state of security updates in Android, I would say it is worth drawing as much publicity as possible to these events.

Re: More Than 1M Google Accounts Breached by Gooligan

#90
post #29

Malware on your Android device picked up from third party app stores (FDroid? Amazon?) that steals email accounts and auth tokens. Looks like it only works on the older Android 4 Jellybean software (and some Android 5 Lollipop) and below, so mostly concentrated in Asia where there are lower-end phones. You can see if your account has been affected here: https://gooligan.checkpoint.com/

Thanks for making this comment. This post is a wonderful example of the rampant marketing that has given the security industry a bad name. - The title is technically accurate, which is the best kind of accurate for clickbait. This is not a novel vulnerability representative of an application security flaw within Google - the malware campaign specifically targets older devices using previously known vulnerabilities.[1…

Checkpoint has been notorious for this kind of exaggerated marketing, especially within the past few years. My theory is that their security appliance line has been suffering due to superior competitors (source: personal experience; could be wrong without global sales numbers), so I think they're trying to get their name back in people's minds.

This research is definitely good and beneficial, but yes, it's threat intelligence research, not vulnerability research or any sort of revelation. Definitely not deserving of a logo.

Post reply on HN