3 ms·
An Update on Android Market Security
- credo 16y ago>>On Tuesday evening, the Android team was made aware of a number of malicious applications published to Android Market. Within minutes of becoming aware, we identified and removed the malicious applications. As per http://www.reddit.com/r/Android/comments/fvepu/someone_just_ripped_off_21_popular_free_apps_from/ http://www.reddit.com/r/Android/comments/fvepu/someone_just_... the developer of the original app had been trying to get Google to remove the offending apps for more than a week. Google took no action until after a third party reported the problem on reddit. The post says that Google acted "within minutes". However, it doesn't even mention the fact that the problem existed on the market for more than a week. Posting an update is fine, but it is troubling to see a post that refuses to acknowledge basic facts. If they aren't willing to acknowledge a problem, it will be very difficult for them to prevent this and other problems from recurring.
- foobarbazetc 16y ago"within minutes" is pretty much an outright lie. Just the PR equivalent of "nothing to see here, move along. app review? what's that? rainbows and unicorns and Androids!".
- SamReidHughes 16y agoTwo million is a number of minutes.
- zmmmmm 16y agoCare to explain what they "lied" about? It's pretty well documented that the apps were gone within 5 minutes of them being notified of a security problem.
- trotsky 16y agoWhile I don't want to minimize the pain of having your app copied and republished, I'd be very surprised if the author had submitted a properly sworn DMCA takedown notice, which is the correct way to get action on these matters. I submitted a DMCA notice for the Android market in november, and the offending application was gone within 24 hours. I'm fairly sure apple requires a DMCA takedown notice to pull copyrighted content from the app store as well. http://www.google.com/support/bin/request.py?contact_type=lr_dmca&product=androidmarket http://www.google.com/support/bin/request.py?contact_type=lr...
- nexneo 16y agoThis isn't about DMCA notice. I'm not android developer but user and I don't like Trojan stay on official market for entire week until it went to public. That means if original author didn't cared this will stay on market forever.
- trotsky 16y agoIt is about a DMCA notice. The GPP said "the developer of the original app had been trying to get Google to remove the offending apps for more than a week." He wasn't complaining about trojans, he didn't know about them, he was complaining about copyright infringement. I'd be very surprised if they would have remained for long at all if he had submitted a DMCA compliant complaint correctly. Once they were reported as trojans they were pulled the same day. I'm not sure what is expected from google here: Clearly they need to get a better handle on licensees pushing minor updates. That privesc has been around forever, and it's still there on my phone and that's super shitty - updating is android's achilles heel. But even if they get real good at that there will still be some exploits out there, every platform has them. Do people expect google should be able to make it so no malicious code can ever be run? Seems like that's a battle nobody has won. Do people expect google to switch to a curated, only google approved apps marketplace? I'd sure be unhappy if they did. Do people expect google to pull apps from the marketplace on copyright complaints even if they aren't submitted/sworn correctly and potentially let all kinds of fraudulent takedown mayhem occur (because the submitter wouldn't be liable)? Seems unwise. Do people expect google to do automated scans and blocks of suspicious code on the marketplace? Sounds like what they are planning on doing.
- russell_h 16y agoWe are adding a number of measures to help prevent additional malicious applications using similar exploits from being distributed through Android Market Am I the only one thinking they might be planning to leverage their recent acquisition of zynamics on this front? In particular, zynamics seems to have developed some tools[1] for classifying malware based on (as I understand it) some sort of static control-flow analysis. I'm far from an expert on the matter, but that sounds like it has some potential with regards to keeping malicious apps out of the Android Market. [1] http://www.zynamics.com/vxclass.html http://www.zynamics.com/vxclass.html
- GeneralMaximus 16y ago... and Android turns into Windows. Pre-Win7 Windows, that is. This time the threat is more serious. Android powers always connected communications devices that have access to all your email, social network profiles, contact information etc.
- zmmmmm 16y agoI'm somewhat heartened by this. I really thought they were just going to sweep it under the carpet and say nothing about it which would have really left the impression that they just don't care about the market at all. I'm particularly glad that they are following up with law enforcement - as fruitless as it may be, the only up front protection that the Android market has is from the threat that attempts to compromise it will be aggressively followed up. This should at least ensure there's a first line of defense against basic idiots who might try to put compromised apps into the market just for sake of it.
- Indyan 16y agoTime has come for Google to make serious changes. This entire saga raises several questions. Obviously, as Android’s popularity continues to surge, more and more hackers and malware writers will target it. Unfortunately, it’s clear that Google is simply in no position to mitigate these attacks before they occur. The “openness” of the Market is becoming Android’s biggest security weakness. Although most Android users have nothing but disdain for any app review system, I would welcome a change in the Market policy, whereby all submitted apps are screened for signs of malicious or fraudulent activities. Google might also need to give a serious thought to how it deploys security updates. Apple and Microsoft have full control over deploying critical system updates, unlike Google, which is at the mercy of handset manufacturers and carriers. Although the bug that was exploited by DroidDream was fixed in Android 2.2.2, hundreds of thousands of handsets were successfully compromised because Android 2.2.2 isn’t yet available for a substantial number of handsets. Unless Google can reign in the fragmentation problem, it might have to start deploying hotfixes for different versions of Android to patch critical security vulnerabilities, i.e. employ a Windows like model of distributing patches to different OS versions. [The above bit is a repost from http://bit.ly/g9xIfg http://bit.ly/g9xIfg , which is written by me]