Home

Android Phone Makers’ Encryption Keys Stolen and Used in Malware

Leave a comment

Click the link below the picture

.

While Google develops its open-source Android mobile operating system, the “original equipment manufacturers” who make Android smartphones, like Samsung, play a large role in tailoring and securing the OS for their devices. But a new finding that Google made public on Thursday​ reveals that a number of digital certificates used by vendors to validate vital system applications were recently compromised and have already been abused to put a stamp of approval on malicious Android apps.As with almost any computer operating system, Google’s Android is designed with a “privilege” model, so different software running on your Android phone, from third-party apps to the operating system itself, are restricted as much as possible and only allowed system access based on their needs. This keeps the latest game you’re playing from quietly collecting all your passwords while allowing your photo editing app to access your camera roll, and the whole structure is enforced by digital certificates signed with cryptographic keys. If the keys are compromised, attackers can grant their own software permissions it shouldn’t have. 

Google said in a statement on Thursday that Android device manufacturers had rolled out mitigations, rotating keys, and pushing out the fixes to users’ phones automatically. And the company has added scanner detections for any malware attempting to abuse the compromised certificates. Google said it has not found evidence that the malware snuck into the Google Play Store, meaning that it was making the rounds via third-party distribution. Disclosure and coordination to address the threat happened through a consortium known as the Android Partner Vulnerability Initiative.

“While this attack is quite bad, we got lucky this time, as OEMs can quickly rotate the affected keys by shipping over-the-air device updates,” says Zack Newman, a researcher at the software supply-chain security firm Chainguard, which did some analysis of the incident. 

.

Photograph: Thiago Prudencio/Getty Images

.

.

Click the link below for the article:

https://www.wired.com/story/android-platform-certificates-malware/?utm_source=pocket_discover_technology

.

__________________________________________

Leave a comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.

MRS. T’S CORNER

https://www.tangietwoods

Adam Rogers - Comedian

Finding The Funny in Life’s Everyday Chaos

Global geopolitics

Decoding Power. Defying Narratives.

Talk Photo

A creative collaboration introducing the art of nature and nature's art.

Movie Burner Entertainment

The Home Of Entertainment News, Reviews and Reactions

Le Notti di Agarthi

Hollow Earth Society

C r i s t i a n a' s Fine Arts ⛄️

•Whenever you are confronted with an opponent, conquer him with love.(Gandhi)

TradingClubsMan

Algotrader at TRADING-CLUBS.COM

Comedy FESTIVAL

Film and Writing Festival for Comedy. Showcasing best of comedy short films at the FEEDBACK Film Festival. Plus, showcasing best of comedy novels, short stories, poems, screenplays (TV, short, feature) at the festival performed by professional actors.

Bonnywood Manor

Peace. Tranquility. Insanity.

Warum ich Rad fahre

Take a ride on the wild side

Madame-Radio

Découvre des musiques prometteuses dans la sphère musicale française (principalement, mais pas que...).

Ir de Compras Online

No tiene que Ser una Pesadilla.

Kana's Chronicles

Life in Kana-text (er... CONtext)

Cross-Border Currents

Tracking money, power, and meaning across borders.

Jam Writes

Where feelings meet metaphors and make questionable choices.

emotionalpeace

Finding hope and peace through writing, art, photography, and faith in Jesus.

WearingTwoGowns.COM

MOVING FORWARD...That's how WINNING is done!”-Rocky Balboa

...

love each other like you're the lyric to their music

Luca nel laboratorio di Dexter

Comprendere il mondo per cambiarlo.

Tales from a Mid-Lifer

Mid-Life Ponderings

Hunza

Travel,Tourism, precious story "Now in hundreds of languages for you."

freedomdailywriting

I speak the honest truth. I share my honest opinions. I share my thoughts. A platform to grow and get surprised.

The Green Stars Project

User-generated ratings for ethical consumerism

Cherryl's Blog

Travel and Lifestyle Blog

Sogni e poesie di una donna qualunque

Questo è un piccolo angolo di poesie, canzoni, immagini, video che raccontano le nostre emozioni

My Awesome Blog

“Log your journey to success.” “Where goals turn into progress.”

pierobarbato.com

scrivo per dare forma ai silenzi e anima alle storie che il mondo dimentica.

Thinkbigwithbukonla

“Dream deeper. Believe bolder. Live transformed.”

Vichar Darshanam

Vichar, Motivation, Kadwi Baat ( विचार दर्शनम्)

Komfort bad heizung

Traum zur Realität

Chic Bites and Flights

Savor. Style. See the world.

ومضات في تطوير الذات

معا نحو النجاح

Broker True Ratings

Best Forex Broker Ratings & Reviews

Blog by ThE NoThInG DrOnEs

art, writing and music by James McFarlane and other musicians

fauxcroft

living life in conscious reality

Srikanth’s poetry

Freelance poetry writing

JupiterPlanet

Peace 🕊️ | Spiritual 🌠 | 📚 Non-fiction | Motivation🔥 | Self-Love💕

Sehnsuchtsbummler

Reiseberichte & Naturfotografie

Spotlight Choices

astrology - life coaching - optimistic reality

INFINITE ENERGY

"قوتك تبدأ من هنا"