9 ms·
Yes, Android 14 still allows modification of system certificates
- inetknght 3y agoAllowing a user to add system certificates a good thing. The user owns the device.
- shadowgovt 3y agoEverything in the category "the user owns the device" is tricky. For a lot of users, "It's really hard to break" is a value-add. Every capacity the user has to modify permissions is an opportunity for an attacker to compromise a device. You can see an example of this in web browsers these days, where sites have to `log` a big scary "Don't paste anything someone tells you to paste into here" message into the built-in developer tools because no matter how many safety features get added to the browser security model, the dev tools can bypass them. It is definitely important that the purchaser knows what kind of phone they're getting (whether it's easy or hard to crack open all the layers of its protection model), but "The phone's protection model is easily broken by the owner" as a universal absolute applied to all devices should be considered harmful.
- michaelmrose 3y agoHow do you make something that isn't trivially turned to oppression without allowing users a trivial escape from the devices protection model? Isn't installing your own OS on your general purpose computer a trivial out? Shall we likewise disable that ability on all general purpose computers?
- shadowgovt 3y agoSometimes oppression could come from a central authority, and sometimes it can come from a rampant criminal element taking advantage of exploitable human behavior. We have to balance defending against both. > Shall we likewise disable that ability Not on all computers, no. But I should have the option of buying my grandmother one which is very, very hard for someone to convince her to give them admin rights.
- michaelmrose 3y agoThis use case is well served by a non admin user as opposed to a machine where Dell is the root user. Furthermore what you desire for your grandmother is liable to be imposed on the rest of us if we want the privilege of banking or Netflix and in many cases grossly abused especially in less free countries including ours should we in the US fall into fascism. You would build chains for millions of people so that granny will have to give scammers her money some less convenient way. I'd rather not.
- shadowgovt 3y agoI think that really overstates the risk scenario. If we're going to descend into hyperbole, let's turn it around... If a free and open device is so important, won't some smart hacker always come along to build one? I'd rather my grandmother have an easy life and trust that Neo will be around to save the technorati eventually than make life easier on people who already know how to hack things they want to behave differently at the cost of my grandmother's sense of ease and well-being.
- michaelmrose 3y ago> If a free and open device is so important, won't some smart hacker always come along to build one? This just isn't how the universe works at all. We both grew up in the era roughly analogous to the early era of flight with 100 bad designs competing for most incompetent and are now moving into the an era of commercial jets and here you are arguing that planes wont make a difference in war. If you build an ecosystem where essential services like logging into your work, watching netflix, and banking require you to use locked down devices in which the OEM could be forced to build ANY restriction into the device but mostly use it to keep you from trivialities in the US and Europe you wont notice you've built a tool suitable for any oppression nor will you notice until the frog is well boiled. We have the bones of damn near total control in terms of difficult to root devices, remote attestation to ensure you actually are using such a device, AI to analyze data at scale. The difference between the tools we have now and 1984 is that the telescreen didn't sit in your pocket nor was Big Brother literally listening 100% of the time to 100% of the people. We are describing a literal system you could roll out without inventing anything purely based on existing technology and if you too live in the US then we are doing so in a country that has at least a 1 in 3 chance of descending into a fascist state.
- ori_b 3y ago> Shall we likewise disable that ability on all general purpose computers? It's being worked on with web attestation.
- paulmd 3y agoApple honestly did a pretty good job. You can sideload your own code with a free developer account, but you have to jump through some minor hoops to get “developer” mode set on your account (I went through this to get the tvOS 17 beta). And the app signing expires in 7 days, so it’s really painful for a normal user who isn’t actually developing and testing an app to use like that for a long term thing. If you want more than that, you can pay $99 for a real developer account and that will let you sign apps for up to a year. And that’s a sufficient barrier that Facebook can’t be like “you have to sign up for a dev account if you want to use Facebook!” and expect the average user to just blindly comply. Cause that’s the problem with the EU approach, it works ok when it’s only the EU, but Facebook really wants to bypass those permissions (they’ve already bribed users to install dev credential builds that have full permissions, so they could datamine more effectively), and the moment they can lever open the app-review process with “third party app stores” is the moment the “doesn’t work on iOS, please sideload the native app” banner goes up on Facebook.com. It doesn’t have to be financial but the only alternatives would be some kind of credential verification thing like looking at your LinkedIn or a college transcript or a GitHub account to validate that you’re actually a bona fide developer and not just grandma who got an iTunes gift card to install the spyware build (real example from Facebook). https://techcrunch.com/2019/01/30/apple-bans-facebook-vpn/amp/ https://techcrunch.com/2019/01/30/apple-bans-facebook-vpn/am...
- JimDabell 3y ago> Apple honestly did a pretty good job. They did. Over here, there are regular news articles and warnings from the government as yet more Android users get conned into installing fake banking app APKs that let attackers steal all their money. It’s always the same news article and the same warning – only Android users affected. Elsewhere in this thread, people are saying that you can’t protect people from themselves… but Apple seem to be doing a good job of it. When was the last time a side-loaded IPA stole bank credentials from iPhone users? I personally think that Apple should be a little more open. Having some sort of developer mode with plenty of warnings would be better. But the idea that Apple’s approach doesn’t improve security in meaningful ways to the average user is wishful thinking based more in ideology than what actually happens in the real world.
- amalcon 3y ago"Easily, but there's a big scary warning that the person asking you to do this might be trying to hack you" is still "easily". That obviously seems more consumer friendly than either extreme.
- shadowgovt 3y agoThose warnings only go so far against a talented social engineer.
- 3np 3y agoAt some point, you can not protect people from themselves.
- Spivak 3y agoI don't think you deserve the downvotes, this is exactly right and is incredibly frustrating. Programmers, and increasingly folks who don't consider themselves to be writing malware, have no concept of a thing that should never be done by an application and only by the end user. If it's possible to do I should be allowed to do it! If they didn't want me doing it they should have stopped me! The amount of guides on the internet not targeted toward developers that teach users to go through the "create an application" flow and grant some random app access to their account in a more privileged way than would be allowed by the app itself is embarrassing for our industry. "Just add this configuration profile!", "Just paste in your API key." The moment you allow users to add custom root certs ad blocker apps are going to ask users to add one for "advanced" network level ad blocking. You can't win with this crap. Nobody considers themselves a "not advanced" user so no amount of warning will ever work. Have you ever tried doing something, saw some warning that said this was for advanced users in your way to do the thing, and stopped? Me neither.
- loa_in_ 3y ago> sites have to `log` a big scary "Don't paste anything someone tells you to paste into here" message into the built-in developer tools because no matter how many safety features get added to the browser security model, the dev tools can bypass them. That doesn't seem all that much work. Hardening things like that should be a dedicated job, but of course it doesn't "create value" so it's mostly left to rot until it's a source of bad PR.
- inetknght 3y ago> For a lot of users, "It's really hard to break" is a value-add. "It's really hard to break" should not be conducive to the dumbing down of the populace. Enabling power users is therefore more desirable. And importantly, the two do not have to be mutually exclusive.
- simondotau 3y agoI agree with you in theory, but in practice half the population are never going to become security experts and it's impractical to force them to learn through necessity. If a hacker can get root on your smartphone, they can probably get access to your bank account (and the 2FA), your email, your private/intimate photos, your medical issues, your sexual secrets, and so on. A smartphone is far higher stakes than anything else which has come before it. To be clear, I think our right to have a smartphone we control is an absolute. It's extremely important. I would march on the street to protect that right. But I'm equally protective of my right to have a smartphone I cannot control no matter what button I press. I'm glad for devices like the iPhone where the manufacturer works damn hard to make sure that it's always under the manufacturer's control.
- __MatrixMan__ 3y agoI agree with your first sentence. The second seems to get less and less true all the time.
- userbinator 3y agoThe former is a necessary condition of the latter.
- hospitalJail 3y agoGosh I love linux/root. I havent needed it on recent androids due to WFH and spending more time on my laptop, but back when I was flying more for work, I was much more into my phone. Cant remember if it was my motorolla or nexus, but I felt like I had a full fledged laptop in my pocket back then. Meanwhile, one of the straws that broke the camels back for Windows was the insane difficulty/impossibility of remove bloatware/malware that comes preinstalled with windows 11. In 2023, its mind boggling to think you have easier access to modify a cellphone OS than a desktop OS.
- __MatrixMan__ 3y agoI recently got tired of trying to hack together a sane workflow on the windows computers in the lab at my university, so installed nix-on-droid and gotty on my phone. Now I just open a tab to my phone's IP address and benefit from the big screen and full sized keyboard while still having exactly the tools I'm used to having elsewhere. When I get home and want to resume work on beefier hardware, I just push from my phone, pull from my desktop, and I'm just where I left off, except now with more resources. You have to be a bit austere about your tool choices to make the similarity happen (sorry VSCode), but it feels like a bit of a superpower just the same.
- maven29 3y agoThere are ways to bypass any of these restrictions imposed by the Android system, even if they were real. Android ships with eBPF, so you just need root. https://github.com/gojue/ecapture https://github.com/gojue/ecapture
- post_break 3y agoHow many normal phones can you root these days?
- modeless 3y agoEvery Pixel phone purchased from the Google store
- downWidOutaFite 3y agoAfter wiping all data and losing access to a bunch of features and apps.
- AshamedCaptain 3y agoIncluding everything I could possibly ever want an Android device for, like my bank's 2FA program. It's all been slowly cooking for a decade, yet people will still claim "but you can still do it with root, so it's as free as before!" (or some other ridiculously complicated workaround with lots of nasty side-effects)
- hackermatic 3y agoYup. When I updated my company's secure development requirements, and compared them to others, I was confronted with a lot of choices that would increase security somewhat, but at the expense of user control of their own devices, like refusing to function if the device was jailbroken, or requiring the use of the system keyboard only (which is also an accessibility problem). These are tempting choices, but they go a lot further than, for example, requiring only modern TLS ciphersuites to be used to communicate with my servers. They dictate the state of your entire device, and no one app or company should have that power, unless you work for the company and they issue you the device -- but even then, modern MDM/MAM can and should sandbox company apps from the rest of the device.
- twleo 3y agoLooks good. I hate how IOS does, especially with certificate pinning, so I cannot use my ad-block http mitmproxy to block ads in Apps. EDIT: thanks for people clarifying that pinning is done by Apps and not by IOS.
- jiofj 3y agocert pinning is done by the apps, not by the OS
- ShrimpHawk 3y agoiOS is even easier than Android to add system certificates and can be done without rooting or jailbreaking the device unlike android. cert pinning is done by the apps not the system.
- kelnos 3y agoThat's not necessarily specific to iOS. Certificate pinning is usually done inside an app, not at the OS level. An app can choose to ignore the system certificate store and, for example, pin the cert used to talk to its private API. This is possible both on iOS and Android.
- jeroenhd 3y agoAnother note: cert pinning is made very easy by Android as well (just needs a fingerprint in an XML file). It's a good feature for security (stalkerware remains a huge problem) but it does suck from a reverse engineering standpoint.
- assassinator42 3y agoCan't you still install a CA certificate through Settings like you always could? https://stackoverflow.com/a/65319223 https://stackoverflow.com/a/65319223
- jeroenhd 3y agoYou can, but that's not the system certificate store. Android has two certificate stores (the user store and the system store). The user store can be altered through the method you linked. The system store used to be part of the system image (you could always disable certificates, of course) and will now be moved to an APEX location that Google can update (to prevent the Let's Encrypt issue in the future). To alter the system store, you need root access. At the moment it's just a matter of dropping a file with the right name and encoding at /etc/system/cacerts (through Magisk style overlays, or by modifying the system image) but that will change soon.
- netheril96 3y agoWhat's the practical difference between system store and user store? Do some apps or system operations only trust the system store and not the user store? Not rhetorical questions.
- mvnuweucxqokii 3y agoI don't know the difference between the user and system store, but I do know that apps can choose not to trust certs installed by the user and instead only trust their own that they bring with them. Was frustrated to find this when I was trying to MITM an app to see what it was up to on the wire.
- jeroenhd 3y agoApps used to trust the user store by default, but that changed back in Android 7. Now they only trust the system store by default and need to opt into also loading the user store. So, it's not that they look at the stores and pick one, it's that the user store has effectively been disabled for most apps (browsers usually work, thankfully). Even Firefox for Android will only use the user store if you go through a five step process to open the hidden settings. Some apps do certificate pinning, which basically only validates certificates against a specific certificate authority and completely defeats any system certificate store. You can MitM these apps by injecting code to bypass their restrictions. The eBPF methid linked above works, or you can use Frida in root or rootless mode to inject a variety of existing scripts to defeat certificate validation. This is a lot more involved than installing a certificate authority, but it'll work if you want to reverse an app.
- teakie 3y agodisable CAs is a thing or can you add your own for every domain or something?