14 ms·
More Than 1M Google Accounts Breached by Gooligan
- ohyoutravel 10y agoMalware on your Android device picked up from third party app stores (FDroid? Amazon?) that steals email accounts and auth tokens. Looks like it only works on the older Android 4 Jellybean software (and some Android 5 Lollipop) and below, so mostly concentrated in Asia where there are lower-end phones. You can see if your account has been affected here: https://gooligan.checkpoint.com/ https://gooligan.checkpoint.com/
- deleted 10y ago[deleted]
- an_account 10y agoHow did they get a list of compromised email accounts?
- tyingq 10y agoThis explains it better: https://plus.google.com/+AdrianLudwig/posts/GXzJ8vaAFsi https://plus.google.com/+AdrianLudwig/posts/GXzJ8vaAFsi
- wnevets 10y ago>Malware on your Android device picked up from third party app stores well ok then.
- tyingq 10y ago>Malware on your Android device picked up from third party app stores They say that, but then Google's G+ post[1] says "These apps are most often downloaded outside of Google Play" You could read "most often" as "some of these were downloaded from Google Play". Either way, they are exploiting known vulnerabilities. The big issue to me is that phone manufacturers / carriers, by choice, stop patching phones whenever they please. [1]https://plus.google.com/+AdrianLudwig/posts/GXzJ8vaAFsi https://plus.google.com/+AdrianLudwig/posts/GXzJ8vaAFsi
- dri_ft 10y ago"Most often" might just be hedging.
- tyingq 10y agoSearched a bit more. This family of malware (Ghost Push) was being downloaded from the Play Store...at least in the past. http://www.cmcm.com/blog/en/security/2015-10-14/825.html http://www.cmcm.com/blog/en/security/2015-10-14/825.html "Apps infected with this Trojan have been found in Google Play as well as other popular app markets"
- ocdtrekkie 10y agoAdrian also stated they were removing affected apps from the Play Store. Many of the more recent vulnerabilities even show up in the Play Store first. Adrian's constant defense hinges on saying "stick with the Play Store, where we protect you", but the Play Store really isn't much better, it's just that saying it is scares people from looking at competitors' markets.
- guelo 10y agoIf you read further down in the G+ post it says: - Removing apps from Play: We’ve removed apps associated with the Ghost Push family from Google Play. We also removed apps that benefited from installs delivered by Ghost Push to reduce the incentive for this type of abuse in the future. Downloading apps from Google Play, rather than from unknown sources [https://goo.gl/9rqdiH https://goo.gl/9rqdiH], is a good practice and will help reduce the threat of installing one of these malicious apps in the future.
- dsacco 10y agoThanks for making this comment. This post is a wonderful example of the rampant marketing that has given the security industry a bad name. - The title is technically accurate, which is the best kind of accurate for clickbait. This is not a novel vulnerability representative of an application security flaw within Google - the malware campaign specifically targets older devices using previously known vulnerabilities.[1] There is no new exploit research here. - There's a logo and cute name for something which is, again, not a novel vulnerability.[2] - Scaremongering tactics are used throughout to hype up the finding.[3][4] Deliberately ominous language like "...for now" is perhaps tolerable when it's coming from a media outlet, but it's certainly unacceptable from a firm conducting original security research. All things told, this is closer to "threat intelligence" than real security research. A much better source for this news is the blog post by Google's Director of Android Security, Adrian Ludwig (first footnote, linked elsewhere in this thread as well). In particular, notice the succinctness and the serious, yet detached professionalism associated with the post. In any case, there are legitimate arguments to be made in favor of extending software or device support lifetimes for vulnerability patches, but the onus is on device manufacturers to coordinate this. In the meantime, it would be great if fewer firms practiced this sort of manic self-promotion, but unfortunately there's little incentive not to. ------- 1. https://plus.google.com/+AdrianLudwig/posts/GXzJ8vaAFsi https://plus.google.com/+AdrianLudwig/posts/GXzJ8vaAFsi 2. http://blog.checkpoint.com/wp-content/uploads/2016/11/goo_blog.jpg http://blog.checkpoint.com/wp-content/uploads/2016/11/goo_bl... 3. http://blog.checkpoint.com/wp-content/uploads/2016/11/info_4_REVISED_11.23.16.jpg http://blog.checkpoint.com/wp-content/uploads/2016/11/info_4... 4. http://blog.checkpoint.com/wp-content/uploads/2016/11/info_2_REVISED-11.23.16-Copy.jpg http://blog.checkpoint.com/wp-content/uploads/2016/11/info_2...
- mola 10y agoIn a similar vain a Google employee has a very obvious incentive to downplay this campaign.
- zepto 10y agoThe fact that most consumers aren't aware they most Android devices are susceptible to these kind of vulnerability argues for more noise about these issues - not calming press releases talking about how the issues are moot with the latest build.
- tonyplee 10y agoIf it is just auth tokens instead of email password, should google be able to invalidate all these auth tokens in their backend immediately? Force those uses to re-login and get new auth tokens?
- KingMachiavelli 10y agoThe malware is still installed and would just capture the new auth tokens. And forcing the user to login would also give the malware an opportunity to capture the actual password.
- deleted 10y ago[deleted]
- tonyplee 10y agoI see. Google should log other signatures such as device id, ip, network, region where the request coming from and use those data as additional layer of security in the backend to help id the folks/org behind hack.
- undersuit 10y agoDo you actually know which stores they mean? I'd hate for F-Droid to be vilified. F-Droid isn't just a store, it's an Android Repository Browser[1]. It would be a shame if the F-Droid repository was exploited beyond the concessions[2] that they allow. [1] https://f-droid.org/wiki/page/Known_Repositories https://f-droid.org/wiki/page/Known_Repositories [2] https://f-droid.org/wiki/page/Antifeatures https://f-droid.org/wiki/page/Antifeatures
- ohyoutravel 10y agoI do not, just wanted to throw a couple that I know of out there. Hopefully neither of those third party stores because I like and use them both. I hope it was clear from the question marks in my post that those were just examples, certainly don't want to smear either one.
- JshWright 10y agoIf you're going to name app stores, I would think places like Baidu would be more likely, given their size and popularity with users of lower-tier Android devices.
- ohyoutravel 10y agoAgreed, however until you posted this, I didn't know Baidu had an app store.
- curt15 10y ago>Looks like it only works on the older Android 4 Jellybean software (and some Android 5 Lollipop) and below, so mostly concentrated in Asia where there are lower-end phones. But devices running Android 5 and below "only" comprise the vast majority of devices out there https://developer.android.com/about/dashboards/index.html https://developer.android.com/about/dashboards/index.html
- JamesSwift 10y agoYep, I'm stuck on 4.4.2 because verizon doesn't provide OTA updates any more and the 4.4 update ensures that the phone bricks if you go through the process of installing cyanogenmod.
- TenOhms 10y agoWas the same, went for an Iphone 7. I'll never blindly buy a locked Verizon phone ever again. Damn them, damn them to hell.
- wfunction 10y agoIs there some way to check without actually submitting our email address?
- Yetanfou 10y agoIt is not likely that this malware is picked up through F-Droid as that 'store' only contains software which was built from source by the store maintainers. Any non-free code is removed from the build before the package is hosted on the download server. As such an Android device can be used (in a useful way) without having Google Play services (or, for that matter, any other Google apps) installed. I've been doing just that for more than 5 years now without having the feeling I'm missing out on something. AOSP or a tailor-made Cyanogenmod (with all the Cyanogen-account related stuff removed) plus F-Droid gives you a perfectly usable device. https://f-droid.org/about/ https://f-droid.org/about/
- alexcason 10y agoCached: http://webcache.googleusercontent.com/search?q=cache:http://blog.checkpoint.com/2016/11/30/1-million-google-accounts-breached-gooligan/ http://webcache.googleusercontent.com/search?q=cache:http://...
- mapleoin 10y agoDoes anyone else use a special account for their Android phone that they don't use for anything else?
- boredinballard 10y agoThat's a good idea! I may start doing that.
- 4rtemis 10y agoI don't use a Google account on my android phone. Cyanogenmod sans google anything.
- YCode 10y agoSo I guess you don't have access to Google Play? How do you get apps?
- undersuit 10y agoI use F-droid for many apps, but I also still use Google Play.
- jasonkostempski 10y agoI've got a few crutches I'm not ready to give up so I'm on regular Android but I've been starting down the path of using F-Droid only apps so I can trasition more smoothly when I'm ready. The only app I've got left is Maps, OsmAnd is a little too tedious for me but I'll convince myself it's worth it eventually. I'm also concerned that I might not be able to get Project Fi working quite right.
- deep_attention 10y agoI am using "Here WeGo" https://here.com/ https://here.com/ (originally developed by Nokia), quite a good alternative to Google Maps. It does not need any Google services installed. Downloaded it directly from the Google Play store with Raccoon.
- lucb1e 10y agoSo wait this is phishing, not actually hacking into Google to breach accounts if I understood it correctly? In that case, I suppose the title might be technically correct (those accounts are indeed breached), but it makes it sound like Google is to blame.
- deleted 10y ago[deleted]
- tyingq 10y agoNot really phishing, just malware hosted on different app stores. And the Google post[1] seems to indicate perhaps some of them were on the official Play store. I read "These apps are most often downloaded outside of Google Play" as "maybe some were downloaded from Google Play". [1]https://plus.google.com/+AdrianLudwig/posts/GXzJ8vaAFsi https://plus.google.com/+AdrianLudwig/posts/GXzJ8vaAFsi
- Figs 10y agoNo, it's a Trojan horse. Users installed what they thought was a legit app, but it came bundled with malware that stole their auth token.
- jrochkind1 10y ago> While Google implemented multiple mechanisms, like two-factor-authentication, to prevent hackers from compromising Google accounts, a stolen authorization token bypasses this mechanism and allows hackers the desired access as the user is perceived as already logged in. What's the right fix here? Should auth tokens be ip-address-tied? How much will that break? Or would that not even fix it?
- cheeze 10y agoI'm not sure what the solution is, but my worry with tying to an IP address is the mobile setting where I may transition from work wifi to bus wifi to home wifi, with a mobile carrier in between all of those steps. Maybe something like a device ID, although I assume that that can be easily stolen and spoofed.
- haswell 10y agoI'm not sure what the right solution is, but tying tokens to IP addresses is probably not workable. Better mechanisms for protecting tokens stored on the device seems like the only way to reasonably improve this situation.
- rolodato 10y agoToken binding would solve this by binding OAuth tokens to TLS connections, so they can't be used even if stolen: https://tools.ietf.org/html/draft-jones-oauth-token-binding-00 https://tools.ietf.org/html/draft-jones-oauth-token-binding-...
- notJim 10y agoWould this mean that the token is only good for the duration of the connection though? Most apps on mobile hold tokens that ~never expire (iirc I've never had to re-auth the Gmail app.)
- deleted 10y ago[deleted]
- pierrec 10y ago
- pierrec 10y agoJust to be clear, they didn't obtain any passwords, but auth tokens. This would potentially allow them to log into accounts, but only as long as the tokens are valid. Also, they don't reveal which "third party app stores" served infected apps, but they do provide a list of infected apps, and searching for these yields some real shady download sites: http://imgur.com/a/0luW3 http://imgur.com/a/0luW3
- knz 10y agoDoes 2FA help in this situation? If the token signs in from a previously unknown device/server wouldn't it prompt for authentication details?
- ec109685 10y agoNo. The malware steals a secret stored on the device that gives the attacker the same access to your google account as your own phone.
- haswell 10y agoFTA: > While Google implemented multiple mechanisms, like two-factor-authentication, to prevent hackers from compromising Google accounts, a stolen authorization token bypasses this mechanism and allows hackers the desired access as the user is perceived as already logged in. The trouble is that auth tokens are generally not tied to a specific device or IP. There aren't really any mechanisms for this in standard OAuth 2.0 flows (if indeed this is what they're using).
- rolodato 10y agoNo, but this would be solved if Google and client applications implemented OAuth token binding: https://tools.ietf.org/html/draft-jones-oauth-token-binding-00 https://tools.ietf.org/html/draft-jones-oauth-token-binding-...
- ryangittins 10y agoCouldn't Google just revoke all of those access tokens? It'd be a minor inconvenience for some, but it would hardly be a big deal, right? You'd just have to grant access again.
- devy 10y agoWe were just reading "Android security in 2016 is a mess"[1] 2 days ago and now we have another great example for it. https://news.ycombinator.com/item?id=13056288 https://news.ycombinator.com/item?id=13056288
- tdkl 10y ago"Windows is a mess because you can install a virus executable on it." "You can't install Windows software outside App Store anymore, MS is taking muh freedoms." You can't win.
- UweSchmidt 10y agoUhm, definitively let me install software on my computer when/how I want? Get the security model right, works for unix.
- raesene6 10y agoThere absolutely is a trade-off here between freedom to operate and likely security (with the exception of highly skilled technical people with a lot of time on their hands, who can likely have both). Personally I'd say that most non-technical computer users are better off using a more locked down/secure OS (e.g. iOS) as they are generally ill-equipped to manage an open computing platform with the current level of threats that there are out there.
- zepto 10y agoYou actually can win. Apple makes the choice with iOS to be closed. People hate on that because they distrust a centralized authority with good reason, however it is far safer for those who don't mind giving up control. Google makes the choice with Android to be open. People hate on that because they want the system to be safe, however it is in the control of the end user for those who don't mind taking responsibility for the safety of their own device. Both absolutely win at what they are trying to be. MS on the other hand tries to pretend to be both while actually not delivering the benefits of either. That is certainly a way not to win.
- burkaman 10y ago
- n1tro 10y agoI used to work in an ad-tech company focused on mobile cpi offers that for several months paid the salaries of everyone involved by injecting malware in cracked apps on several third party app stores (they were making a profit out of it enough to dedicate a team only for this). They even managed to automate all the process of "selling" cracked apps on third party stores. It is amazing how easy it is to trick broke 13yr old kids into installing stuff on their phones. I left shortly after i found out about this.
- Normal_gaussian 10y agoThis is one of the reasons we may need to look into self-regulation. Name them?
- Filligree 10y agoNever mind self-regulation, what he described is outright illegal. In most countries, so is not reporting them to the police once you know about it.
- Normal_gaussian 10y agoAbsolutely, however with self regulation and a standards body they will find it much harder to get Engineers in the first place.
- deleted 10y ago[deleted]
- jalajc 10y agoIs there a way to know if my email is on list of breached?
- favadi 10y agoRight in the article: https://gooligan.checkpoint.com https://gooligan.checkpoint.com.
- santiagobasulto 10y agoHave you installed any of the apps listed in the "Appendix A"?
- deleted 10y ago[deleted]
- deleted 10y ago[deleted]
- m00dy 10y agoChecking your email address in such sites looks like a great way to collect email addresses
- mathrawka 10y agoHey Eren, It's not like that email addresses are that hard to find when they are listed on websites publically... ereny*gdir*n[@AT]gm*il
- bisby 10y agoIndeed. Literally all you are providing to the site is an email address. I could check my coworkers' email addresses. They have a list, I'm checking to see if something is on the list. Any site that requires you to provide an email address and password (or any other "verifiable info") to check is probably a scam.
- m00dy 10y agoIt requires manual interaction and obviously not scalable.
- steelbird 10y agoFine print: "Check Point will not collect, store, or use your email address for any other purpose."
- X86BSD 10y agoThe difference between iOS and android could not be more clear in this regard. It's interesting to see the difference in security between the two. It's night and day. Google has some serious problems to address. But it seems like they don't care. Their track record is deplorable regarding android security. Is this really the best google can do?
- tdb7893 10y agoMost android isn't stock and there are a ton of old versions out there so it's a little apple to oranges. I think if you would have a phone created by google and keep it up to date it would probably be pretty secure.
- bitCode 10y agolike the pixel phone?
- deleted 10y ago[deleted]
- dep_b 10y agoI didn't hear any customer beg for a customized version of Android. Rather "stock Android" seems to be a selling point nowadays. It's just a bunch of marketing weenies looking for "an unique opportunity to put focus on the brand". Seldom I see things (like multitasking in some Samsung devices before it came to Android) that would really help the end user.
- deleted 10y ago[deleted]
- neotek 10y agoAnd still people complain that Apple refuses to allow third-party app stores.
- jazoom 10y agoI get from this that the thing Apple did right wasn't preventing other install sources, but rather that they control all their updates.