5 ms·
Hmm... Well deserved, or a poor security choice for Android? The vulnerability appears to be that any app can overwrite an APK downloaded to external storage wi
by ppseafield 6y ago
Hmm... Well deserved, or a poor security choice for Android? The vulnerability appears to be that any app can overwrite an APK downloaded to external storage with a FileObserver. How is that not pathologically bad security on Android's part?
> Any app with the WRITE_EXTERNAL_STORAGE permission can substitute the APK immediately after the download is completed and the fingerprint is verified. This is easily done using a FileObserver. The Fortnite Installer will proceed to install the substituted (fake) APK.
- berdario 6y agoDefinitely Well deserved. That's not Android fault: you're asking Android to give you access to an unrestricted storage area (e.g. because you want to edit photos shot with your Camera app), and the fact that other apps can read/write to it, is the whole point of that storage. Hence you need to treat it as untrusted, and validate that you're going to install the APK that you thought you were going to install.
- Groxx 6y agoThe flaw appears to be that there is no way to validate in external storage, since the contents can be changed after validation. Which, yes, is a reason to not use external storage. But for large downloads it's undeniably the norm, since internal storage is frequently limited. Since Android doesn't appear to provide a way to use the SD card and also prevent this, that part of it is an Android flaw IMO. As evidence, note the external storage options say "can another app access it? yes, if it's in external storage": https://developer.android.com/training/data-storage https://developer.android.com/training/data-storage
- berdario 6y agoThey shouldn't have used external storage while using API for silent installs, full stop. https://developer.android.com/guide/topics/data/data-storage#filesInternal https://developer.android.com/guide/topics/data/data-storage... The fact that the norm is different is a good point, but the norm is also not to implement your own app stores. In fact, if internal storage is so limited that you don't have space for the APK, you'll get errors due to lack of space even while installing apps from the Play store
- Groxx 6y agoSure, normally you need about 2x to install anything (both apps are kept until the new version is done and validated). But that's less than the 3x, if you also kept the download there. Anyway. Yeah, silent installs make this dangerous, no disagreement there at all (tho they're always more dangerous. I'd prefer to never have them). But there's also no reason that Android can't provide a protected external store, except that they've been self-destructively hostile to external storage in any form. It won't work if you remove the SDCard and manipulate it elsewhere, but that's not the attack vector here - it's entirely possible to protect from things on-device, just like they do for internal storage. They even partially achieve it now, with "adopted" internal storage, so it's absolutely possible.
- UncleMeat 6y agoAndroid offers app-local storage that no other app can write to. Epic simply failed to use it. The alternative would be no shared filesystem at all, but then people would complain about that as well since things like file browsers wouldn't function and sharing things like photos between apps becomes tricky. Notably, all operating systems that allow programs to write to files have this "pathologically bad security". Download a .exe file on Windows and check its hash before installing and you have a TOCTOU bug where malware can sub the file after you've checked the hash. Another alternative is to not permit any application to be installed unless it is signed by the OS manufacturer or some other finite trusted list of signers - but then we are right back at the app store model that pisses people off.
- scarface74 6y ago"sharing things like photos between apps becomes tricky." That's a solved problem. Apps on iOS can request access to the photo library. Why Apple still doesn't allow write access to the music library is frustrating. It would be nice if you had a universal "folder picker" where multiple apps could be given access to a user created folder on ios, admittedly.