Home

Android Phone Makers’ Encryption Keys Stolen and Used in Malware

Leave a comment

Click the link below the picture

.

While Google develops its open-source Android mobile operating system, the “original equipment manufacturers” who make Android smartphones, like Samsung, play a large role in tailoring and securing the OS for their devices. But a new finding that Google made public on Thursday​ reveals that a number of digital certificates used by vendors to validate vital system applications were recently compromised and have already been abused to put a stamp of approval on malicious Android apps.As with almost any computer operating system, Google’s Android is designed with a “privilege” model, so different software running on your Android phone, from third-party apps to the operating system itself, are restricted as much as possible and only allowed system access based on their needs. This keeps the latest game you’re playing from quietly collecting all your passwords while allowing your photo editing app to access your camera roll, and the whole structure is enforced by digital certificates signed with cryptographic keys. If the keys are compromised, attackers can grant their own software permissions it shouldn’t have. 

Google said in a statement on Thursday that Android device manufacturers had rolled out mitigations, rotating keys, and pushing out the fixes to users’ phones automatically. And the company has added scanner detections for any malware attempting to abuse the compromised certificates. Google said it has not found evidence that the malware snuck into the Google Play Store, meaning that it was making the rounds via third-party distribution. Disclosure and coordination to address the threat happened through a consortium known as the Android Partner Vulnerability Initiative.

“While this attack is quite bad, we got lucky this time, as OEMs can quickly rotate the affected keys by shipping over-the-air device updates,” says Zack Newman, a researcher at the software supply-chain security firm Chainguard, which did some analysis of the incident. 

.

Photograph: Thiago Prudencio/Getty Images

.

.

Click the link below for the article:

https://www.wired.com/story/android-platform-certificates-malware/?utm_source=pocket_discover_technology

.

__________________________________________

Leave a comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.

TradingClubsMan

Algotrader at TRADING-CLUBS.COM

Comedy FESTIVAL

Film and Writing Festival for Comedy. Showcasing best of comedy short films at the FEEDBACK Film Festival. Plus, showcasing best of comedy novels, short stories, poems, screenplays (TV, short, feature) at the festival performed by professional actors.

Bonnywood Manor

Peace. Tranquility. Insanity.

Warum ich Rad fahre

Take a ride on the wild side

Madame-Radio

Découvre des musiques prometteuses dans la sphère musicale française (principalement, mais pas que...).

Ir de Compras Online

No tiene que Ser una Pesadilla.

Kana's Chronicles

Life in Kana-text (er... CONtext)

Cross-Border Currents

Tracking money, power, and meaning across borders.

Jam Writes

Where feelings meet metaphors and make questionable choices.

emotionalpeace

Finding hope and peace through writing, art, photography, and faith in Jesus.

Wearing Two Gowns.COM

What to do when your career implodes and your friends betray you!? You say "GOOD!"

...

love each other like you're the lyric to their music

Luca nel laboratorio di Dexter

Comprendere il mondo per cambiarlo.

Tales from a Mid-Lifer

Mid-Life Ponderings

Hunza

Travel,Tourism, precious story "Now in hundreds of languages for you."

freedomdailywriting

I speak the honest truth. I share my honest opinions. I share my thoughts. A platform to grow and get surprised.

The Green Stars Project

User-generated ratings for ethical consumerism

Cherryl's Blog

Travel and Lifestyle Blog

Sogni e poesie di una donna qualunque

Questo è un piccolo angolo di poesie, canzoni, immagini, video che raccontano le nostre emozioni

My Awesome Blog

“Log your journey to success.” “Where goals turn into progress.”

pierobarbato.com

scrivo per dare forma ai silenzi e anima alle storie che il mondo dimentica.

Thinkbigwithbukonla

“Dream deeper. Believe bolder. Live transformed.”

Vichar Darshanam

Vichar, Motivation, Kadwi Baat ( विचार दर्शनम्)

Komfort bad heizung

Traum zur Realität

Chic Bites and Flights

Savor. Style. See the world.

ومضات في تطوير الذات

معا نحو النجاح

Broker True Ratings

Best Forex Broker Ratings & Reviews

Blog by ThE NoThInG DrOnEs

art, writing and music by James McFarlane and other musicians

fauxcroft

living life in conscious reality

Srikanth’s poetry

Freelance poetry writing

JupiterPlanet

Peace 🕊️ | Spiritual 🌠 | 📚 Non-fiction | Motivation🔥 | Self-Love💕

Sehnsuchtsbummler

Reiseberichte & Naturfotografie

Spotlight Choices

astrology - life coaching - optimistic reality

INFINITE ENERGY

"قوتك تبدأ من هنا"

Mesime ÜNALMIŞ

Her çocuk hikayelerle büyümeli

Treasurable Life: The Dirty, Divine Truth of Becoming

No shame. No filters. Just everything we were told to hide.

Dr. Edward McInnis

Doctor of Medicine

Ishaya Zephaniah

Explore the dynamic relationship between faith and science, where curiosity meets belief. Join us in fostering dialogue, inspiring discovery, and celebrating the profound connections that enrich our understanding of existence.

Through Pain Suffering , Mental Health , Addictions , Cancer , Death , Drs

Living with Purpose: Finding Meaning Amidst Life's Challenges