3 ms·
Samsung’s Android app-signing key has leaked, is being used to sign malware
- diemscott 4y agoThis seems catastrophic unless they can be revoked?
- willyt 4y agoSo if you’ve installed a malicious app from Samsung store or you’ve sideloaded a malicious app, it has close to root access and can access data from any other app on the phone? The keys leaked in 2016 and these signing keys are still being used by Samsung now. Is that right? Is it normal to install apps outside of google play store and should Samsung users that have done this assume that they are compromised? I just read this on Ars and came to look for the discussion here and I’m surprised nobody is talking about it. Is there another thread under a different title somewhere?
- readyplayeremma 4y agoThis is the original thread: https://news.ycombinator.com/item?id=33823946 https://news.ycombinator.com/item?id=33823946