5 ms·
Presumably the Play Store will reject any app signed with these keys. I'd appreciate them making a statement to this affect. And someone double checking.
by fowl2 4y ago
Presumably the Play Store will reject any app signed with these keys. I'd appreciate them making a statement to this affect. And someone double checking.
- MishaalRahman 4y agoYeah, I'd be surprised if Google Play wasn't already on the lookout to flag newly uploaded apps signed with these keys.
- ShredKazoo 4y agoHonestly, if it's true that the Android security model allows an OEM-signed app to escalate privileges, Google should always be monitoring OEM-signed apps on the Play store very carefully. There shouldn't be more than a few hundred of them. Can't be that hard. And when installing a OEM-signed app, instead of the normal permissions dialogue, there should be a giant red warning that says the app can basically root your device. If the OEMs don't like it, they can set up a second key pair with no privilege escalation capability to sign updates for most of their apps (the ones that don't need elevated privileges).
- ShredKazoo 4y agoAnother idea: Before installing an OEM-signed app, send the hash to Google and check if it's on an allowlist.
- lern_too_spel 4y agoEasier than that. Only the vendor's publisher account should be allowed to sign with the vendor's keys. Implement the same policy for everybody, so if one publisher uploads a package signed with the same keys as another, the original publisher should be notified.
- ShredKazoo 4y agoOne would certainly hope. But until we know how these private keys were stolen, I would be suspicious of any updates signed by the affected organizations. If they just rotate the key without improving their security, the new key could get stolen too.