5 ms·
What risks does this cause me as an android user? Does this mean my phone might accept auto updates that install malware onto my device? What can I do to mitig
by ro_bit 4y ago
What risks does this cause me as an android user? Does this mean my phone might accept auto updates that install malware onto my device?
What can I do to mitigate those risks?
- MishaalRahman 4y agoNo, you should be safe so long as you only accept updates to system apps through official app stores, like Google Play or the Galaxy Store. Do not sideload updates to system apps through third-party websites.
- tgsovlerkhgsel 4y agoFrom the description in the bug "Any other application signed with the same certificate can declare that it wants to run with the same user id, giving it the same level of access to the Android operating system.", so this applies to all app installations and updates.
- deleted 4y ago[deleted]
- fowl2 4y agoPresumably the Play Store will reject any app signed with these keys. I'd appreciate them making a statement to this affect. And someone double checking.
- MishaalRahman 4y agoYeah, I'd be surprised if Google Play wasn't already on the lookout to flag newly uploaded apps signed with these keys.
- ShredKazoo 4y agoHonestly, if it's true that the Android security model allows an OEM-signed app to escalate privileges, Google should always be monitoring OEM-signed apps on the Play store very carefully. There shouldn't be more than a few hundred of them. Can't be that hard. And when installing a OEM-signed app, instead of the normal permissions dialogue, there should be a giant red warning that says the app can basically root your device. If the OEMs don't like it, they can set up a second key pair with no privilege escalation capability to sign updates for most of their apps (the ones that don't need elevated privileges).
- ShredKazoo 4y agoAnother idea: Before installing an OEM-signed app, send the hash to Google and check if it's on an allowlist.
- lern_too_spel 4y agoEasier than that. Only the vendor's publisher account should be allowed to sign with the vendor's keys. Implement the same policy for everybody, so if one publisher uploads a package signed with the same keys as another, the original publisher should be notified.
- ShredKazoo 4y agoOne would certainly hope. But until we know how these private keys were stolen, I would be suspicious of any updates signed by the affected organizations. If they just rotate the key without improving their security, the new key could get stolen too.
- anshumankmr 4y agoI have YouTube vanced. Should I remove it?
- ShredKazoo 4y agoMalware on the Google Play store seems fairly common. This article from Malwarebytes reported on a family of malicious apps with over 1M downloads: https://www.malwarebytes.com/blog/news/2022/11/malware-on-the-google-play-store-leads-to-harmful-phishing-sites https://www.malwarebytes.com/blog/news/2022/11/malware-on-th... This paper analyzed 1238 malicious apps grouped into 134 families: https://people.ece.ubc.ca/mjulia/publications/GooglePlayMalware_2022.pdf https://people.ece.ubc.ca/mjulia/publications/GooglePlayMalw... An attacker who can steal these private keys can get malware uploaded to the Google Play store. Getting malware uploaded to Google Play is way easier. And if Samsung's private key is stolen, I would certainly not be inclined to trust their Galaxy Store. Now is a great time to go through your phone & uninstall apps you don't use or don't trust -- especially bloatware from the compromised OEMs. If I understand other comments in this thread correctly, the stolen keys allow the thief to escalate privileges from "ability to issue an update for a random app you have installed" to "ability to root your device".
- ezekiel68 4y agoAndroid has a global user base of around 2.7 billion[0] and nearly 100,000 NEW apps are released on the platform every month[1]. Given these facts, it simply does not follow that a family of malicious apps with 1M downloads or an analysis of 1238 malicious apps demonstrates "Malware on the google Play store seems fairly common." The working hypothesis (gathered from other comments here) is that the main vector of attack for this case may be restricted to the sideloading system-level components (not end-user apps). It's the end of the world as we know it, and I feel fine. [0] https://sortatechy.com/android-users-are-there-worldwide/ https://sortatechy.com/android-users-are-there-worldwide/ [1] https://www.statista.com/statistics/1020956/android-app-releases-worldwide/ https://www.statista.com/statistics/1020956/android-app-rele...
- ShredKazoo 4y ago>nearly 100,000 NEW apps are released on the platform every month[1] Am I supposed to believe Google thoroughly vets all 100,000 of those apps? My assumption is that any automated vetting system can be defeated by a serious attacker (the sort of attacker who can steal private keys). Just keep tweaking your malware until it gets past the filter. >Given these facts, it simply does not follow that a family of malicious apps with 1M downloads or an analysis of 1238 malicious apps demonstrates "Malware on the google Play store seems fairly common." Not sure 100K is the right denominator here -- how many of those 100K receive any attention at all by security researchers? The numbers I quoted appear to demonstrate that when security researchers look for this stuff, it isn't hard to find. >The working hypothesis (gathered from other comments here) is that the main vector of attack for this case may be restricted to the sideloading system-level components (not end-user apps). Check out this article: https://www.pcmag.com/news/study-reveals-googles-play-store-is-main-distributor-of-malicious-apps https://www.pcmag.com/news/study-reveals-googles-play-store-... If 67% of unwanted app installs originate via the Play store, wouldn't it be most natural for attackers looking to exploit a stolen private key to take that most common route? An attacker who can steal multiple private keys from large multinationals can also get inside the software supply chain for your favorite fart app. >It's the end of the world as we know it, and I feel fine. If you're writing software that people use, you have a special obligation to take security seriously. An attacker who gains root access to your phone could e.g. sniff passwords and steal 2FA codes, use them to log into Github/AWS, and do a ton of damage to people who are depending on you.
- Aachen 4y agoOr F-Droid, or other stores you trust. It's about trusted sources, not it originating from Google specifically, right? Theoretically that includes third-party websites, if you can be sure that the download wasn't compromised in transit, that the server isn't compromised, that the uploader is benign...
- jeroenhd 4y agoAny new app can get system privileges if it's signed by a platform key. This doesn't just apply to updates of existing apps. I'd go one step further, don't install any apps from third party websites. Also think very critically about trusted app stores, make sure you know their signature policy.