Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

The Straight Story

(48,121 posts)
Thu Jul 4, 2013, 06:48 PM Jul 2013

Android ‘Master Key’ Security Hole Puts 99% Of Devices At Risk Of Exploitation

Android ‘Master Key’ Security Hole Puts 99% Of Devices At Risk Of Exploitation

Mobile security startup Bluebox Security has unearthed a vulnerability in Android’s security model which it says means that the nearly 900 million Android phones released in the past four years could be exploited, or some 99% of Android devices. The vulnerability has apparently been around since Android v1.6 (Donut), and was disclosed by the firm to Google back in February. The Samsung Galaxy S4 has already apparently been patched.

It’s likely that Google is working on a patch for the vulnerability. We’ve reached out to the company for comment and will update this story with any response.

Bluebox intends to detail the flaw at the Black Hat USA conference at the end of this month but in the meanwhile it’s written a blog delving into some detail. The vulnerability apparently allows a hacker to turn a legitimate app into a malicious Trojan by modifying APK code without breaking the app’s cryptographic signature. Bluebox says the flaw exploits discrepancies in how Android apps are cryptographically verified and installed. Specifically it allows a hacker to change an app’s code, leaving its cryptographic signature unchanged — thereby tricking Android into believing the app itself is unchanged, and allowing the hacker to wreak their merry havoc.

The flaw is made worse if an attacker targets a sub-set of apps developed by device makers themselves, or third parties — such as Cisco with its AnyConnect VPN app — that work closely with device makers and are granted system UID access. This sub-set of apps can allow a hacker to tap into far more than just mere app data, with the potential to steal passwords and account info and take over the normal running of the phone. Here’s how Bluebox explains it:

http://techcrunch.com/2013/07/04/android-security-hole/

8 replies = new reply since forum marked as read
Highlight: NoneDon't highlight anything 5 newestHighlight 5 most recent replies
Android ‘Master Key’ Security Hole Puts 99% Of Devices At Risk Of Exploitation (Original Post) The Straight Story Jul 2013 OP
God!!! Quit calling it a "master key"!!! longship Jul 2013 #1
Unless it was put there on purpose. dkf Jul 2013 #2
Yup! Every OS maker just loves when people reveal their deliberate bugs. longship Jul 2013 #3
They don't plan to be found out of course. dkf Jul 2013 #4
Good points. I bet a lot of "bugs" are installed intentionally. nm rhett o rick Jul 2013 #5
There are always people whose job it is to check these things. longship Jul 2013 #7
Donut hole? surrealAmerican Jul 2013 #6
BlackBerry is looking better every day... No disclosed NSA/CIA involvement yet. eom TheBlackAdder Jul 2013 #8

longship

(40,416 posts)
1. God!!! Quit calling it a "master key"!!!
Thu Jul 4, 2013, 07:03 PM
Jul 2013

Sorry. I do not mean the DUer posting the article. I am about the stupid editor who wrote the headline.

It's an operating system bug and they happen all the damned time. Some are more serious than others. The solution is to fix it which is usually a routine matter.

But calling it a "master key" is deceptive as to the character and purpose of the bug. It has no purpose. It's a fucking bug.

Every other news editor should be strangled slowly until this madness stops.

longship

(40,416 posts)
3. Yup! Every OS maker just loves when people reveal their deliberate bugs.
Thu Jul 4, 2013, 07:10 PM
Jul 2013

Every OS has bugs like this. And NO, none of them are deliberate.

Let's see now. Shall I get my tin foil hat, or some popcorn?

Okay...


 

dkf

(37,305 posts)
4. They don't plan to be found out of course.
Thu Jul 4, 2013, 07:13 PM
Jul 2013

Just like the government doesn't intend for us to know anything either.

longship

(40,416 posts)
7. There are always people whose job it is to check these things.
Thu Jul 4, 2013, 10:08 PM
Jul 2013

That's why when I administered Internet servers I ran Linux and kept up with the security warnings and updates.

They happened often enough with even secure and reliable OS like Linux that I would check things often and subscribed to all the proper alerts.

Some holes are bigger than others. This one sounds serious. They'll be on it or they'll lose business.

To suggest that this is deliberate is lunacy.

Latest Discussions»General Discussion»Android ‘Master Key’ Secu...