3 ms·
I don't get it, the problem has been known for awhile so why hasn't the key been replaced? Anyone can do a ELI5 on the app signing key replacement difficulty?
by largepeepee 4y ago
I don't get it, the problem has been known for awhile so why hasn't the key been replaced?
Anyone can do a ELI5 on the app signing key replacement difficulty?
It isn't covered in the article and seems too high level for a layman like me.
- g_p 4y agoIn the world of Android, apps are signed (including system/platform apps) through a trust-on-first-use system. There's no PKI with roots and intermediates which could support easily enabling a quick fix. On Android, an updated app is validated by the system to be signed by the same signing key hash as was used previously. The most recent (v3, IIRC) apk signing scheme allows you to update an APK and sign it with the old key, and committing a future new signing key, which permits re-keying an app. To use this, I believe you need to ship a platform (operating system) update, as the underlying apps are signed using old APK signing schemes. These OEMs are likely not always shipping the latest OS version, but could look to techniques used in the custom firmware world, where there are tools to allow reflashing the OS without losing app data when changing system signing key. It requires engineering effort for already released devices though, so I suspect we will see very little action - as usual, the eyes are on the future products, not on previously released products. I assume Google play protect will be used to carefully patrol and detect apps on devices signed by the leaked keys, but this isn't hugely helpful for anyone concerned about "zeroday" style targeted attacks against them.
- phkahler 4y ago
- deleted 4y ago[deleted]
- kar5pt 4y agoSo why exactly can't they do an OS update with the new signing keys? OEMs put out OS updates all the time. Plus if they don't want to do that, they could update their individual apps to use the v3 signing schema. They've had 6 years to figure this out.
- altfredd 4y agoThey can but don't want to. There is no multi-billion profit in that.
- zitterbewegung 4y agoSo the signing key for Samsung Android phones were leaked so that any software that is loaded is signed such that it comes from the App Store is trusted. The problem for OEMs is that developing and distributing a new key requires a Firmware update and it isn't trivial to develop for QA/QC because if they make a mistake with the keys then devices could be unable to load apps from the App Store.
- phkahler 4y ago>> and it isn't trivial to develop for QA/QC because if they make a mistake with the keys then devices could be unable to load apps from the App Store. Well then they better do some f..ing testing. They're only one of the biggest tech companies in existence. Making phones isn't trivial either!
- mschuster91 4y agoMaking a phone is dead easy: contract one of the ton of third party manufacturers in China to supply you with one of their white-label designs, pay for them and ship them. The stuff around it is where the complexity lies: making sure you get updates and have infrastructure to distribute these to customers, that you apply for and get certifications from regulatory agencies and, in the US, carriers, deal with e-waste and warranty regulatory requirements (which is a pain in the EU), establish a supply chain for spare parts...
- lern_too_spel 4y agoNot any app installed from the app store but any app signed using Samsung's keys. Such an app could get any permission it pleases when installed. The app store can easily block apps signed with Samsung's keys, but a few people can probably be convinced to download the app outside the app store, which could easily be flagged by Play Protect if it is a Google-flavored phone, preventing install. I don't know if these systems have actually been updated to do this, but I imagine they would be.