4 ms·
Any technical info on how the app was compromised? If I worked for the government and I wanted to break into an app, I'd simply send a letter to the app store
by csense 6y ago
Any technical info on how the app was compromised?
If I worked for the government and I wanted to break into an app, I'd simply send a letter to the app store saying "Yeah you have to post this app update that contains code written by government hackers to leak the keys / messages of (investigation targets | everyone). If you don't, your executives / employees will (be sent to jail | be kidnapped by black ops forces, shot, and buried in an unmarked grave). Ditto if you tell anyone about this letter."
- Crosseye_Jack 6y agoNot 100% sure about the iOS side of things (my guess is because App Store apps are signed by Apple and you can get a new dev cert issued to you from Apple, Apple could sign what ever app the 3 letter agency supplied them. But but someone will notice that there was a new update and it wouldn’t take long before news of which would get back to the devs, same would also apply to Android), On Android you used to have to sign your apps yourself before uploading them to the play store. The store wouldn’t accept an app signed with a different key. Even if you bypassed that (by sideloading the app for example) the OS would still refuse to update the app. It was fairly common to see on Android dev forums people posting “I’ve lost my signing key, what do I do?” To he told they gotta upload under a different package name and hope their existing users would migrate over to the “new app” Now these days Google offer to hold your signing keys for you (cause if you lose your keys you lose the ability to update the app) and if you want to use Googles App Bundle ability you have to opt in (because Google repackage your app for different device types automatically) but you are still free to hold the keys yourself and sign your builds without Google taking a peak at them. Opting into App Bundles for an existing app requires you to upload your existing signing key, so Google can sign on your behalf and devices with your existing app will accept the updates Google’s bundle process produce. Now of cause Google could push some updates to Android as a whole and make a back door to bypass app sig checking, but that would be opening holes on a lot of devices, most of which won’t actually be your target. And if we are going to go down the road of back roofing OS’s to allow apps from unknown keys, might as well just back door the OS and skip the process of creating a fake update for that one app. Now if the app is using Google’s App Bundle feature, it would be possible. But if you were creating a “secure messaging app” why would you hand the keys to the kingdom to anyone else? Just write some extra build scripts, compile the different builds your self and keep those security brownie points.
- Aerroon 6y agoIf a government habitually did this, then you can be sure that people working for such a government would be treated the same way. You need to at least have the illusion of fairness. If you don't, then it eventually explodes in your face.
- rstuart4133 6y ago> If I worked for the government and I wanted to break into an app, I'd simply send a letter to the app store saying ... There is no need for the "if" qualifier. How about this: You pass a law that says the government can compel any software company to assist them in any way they deem fit. For example they might demand Apple assist them by modifying their iPhone keyboard so it sent all the keys tapped together with the app they sent those keys to (eg, the key strokes the sent to Signal). The law could also demand Apple provides access to any device they target by auto installing the new keyboard app via auto updates. For good measure, the law could carry an automatic gag order, preventing any disclosure of these requests for Assistance and Access. The country that actually passed such a law is Australia. It's called the "Assistance and Access Bill 2018". [0] So there you go, it's already been done. There is no need to speculate about what might happen - it's already happened. [0] https://www.aph.gov.au/Parliamentary_Business/Bills_Legislation/Bills_Search_Results/Result?bId=r6195 https://www.aph.gov.au/Parliamentary_Business/Bills_Legislat...
- Pick-A-Hill2019 6y agoSure thing - https://www.vice.com/en/article/3aza95/how-police-took-over-encrochat-hacked https://www.vice.com/en/article/3aza95/how-police-took-over-... (sourced from https://hn.algolia.com/?q=encrochat https://hn.algolia.com/?q=encrochat )