Home

Android Phone Makers’ Encryption Keys Stolen and Used in Malware

Leave a comment

Click the link below the picture

.

While Google develops its open-source Android mobile operating system, the “original equipment manufacturers” who make Android smartphones, like Samsung, play a large role in tailoring and securing the OS for their devices. But a new finding that Google made public on Thursday​ reveals that a number of digital certificates used by vendors to validate vital system applications were recently compromised and have already been abused to put a stamp of approval on malicious Android apps.As with almost any computer operating system, Google’s Android is designed with a “privilege” model, so different software running on your Android phone, from third-party apps to the operating system itself, are restricted as much as possible and only allowed system access based on their needs. This keeps the latest game you’re playing from quietly collecting all your passwords while allowing your photo editing app to access your camera roll, and the whole structure is enforced by digital certificates signed with cryptographic keys. If the keys are compromised, attackers can grant their own software permissions it shouldn’t have. 

Google said in a statement on Thursday that Android device manufacturers had rolled out mitigations, rotating keys, and pushing out the fixes to users’ phones automatically. And the company has added scanner detections for any malware attempting to abuse the compromised certificates. Google said it has not found evidence that the malware snuck into the Google Play Store, meaning that it was making the rounds via third-party distribution. Disclosure and coordination to address the threat happened through a consortium known as the Android Partner Vulnerability Initiative.

“While this attack is quite bad, we got lucky this time, as OEMs can quickly rotate the affected keys by shipping over-the-air device updates,” says Zack Newman, a researcher at the software supply-chain security firm Chainguard, which did some analysis of the incident. 

.

Photograph: Thiago Prudencio/Getty Images

.

.

Click the link below for the article:

https://www.wired.com/story/android-platform-certificates-malware/?utm_source=pocket_discover_technology

.

__________________________________________

Advertisement

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out /  Change )

Facebook photo

You are commenting using your Facebook account. Log Out /  Change )

Connecting to %s

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Natural Health Tips

Home remedies

Specimen Days

Words alone are certain good

TRIBEMENT

The ornaments of tribe

Banter Republic

It's just banter

KnowlExplo

Unlock the World of Knowledge with KnowlExplo

WhatMojo

Your go-to platform for answering online "what" questions on a wide range of topics, providing accurate and reliable information to satisfy your curiosity.

Academills

The mill of academic learning

mylovefairy.com

this love fairy fell in love with her ghost

Travelling Light UK and beyond

Seeing the sights on and off the Harley-Davidson

Flip Side - Word Up!

I will endeavor to present you with a Word Up blog that may be completely flip side to popular opinion! I pray that all my reads challenge you the reader!

Stil unic!

Stilul face diferența!

Guideshelf

Shelves of Guidance

Laws and Claws

Like you, but with claws.

ASSHOLES WATCHING MOVIES

Our opinions don't stink!

Fantastic Planet 25

A Portal To Another Green World

heard + felt

navigating life after trauma

DER KAMERAD

Για του Χριστού την Πίστη την Αγία και της Πατρίδος την Ελευθερία...!

masks and tales

bunch of atoms, with a bunch of masks and tales

Cuentos, relatos, poemas y crónicas de

Chalo, 95' Soy lo que juré crear y destruir. Escribo para ser libre

pàtienciaticiese

Right writing , speaking and loving

LOS MEJORES POEMAS DE AMOR DE PEHIRU

POEMAS ROMANTICOS DE AMOR Y DESAMOR.

The Sage Page

Philosophy for today

ALOYA IDEAS

Ideas, opinion, tips, advice, inspiration, and motivation of daily life.

Water for Camels

Encouragement and Development for Social Workers and Those with a Mission of Helping Others

The Orthosphere

Wherever an altar is found, there civilization exists - Joseph de Maistre

Clouds Curiosity Corner

A community of movie lovers to discuss all things cinema related! Reviews, suggestions, and more! <3

A dreamAchieve.wordspress.com

Achieve your goals with hard work

Hackaday

Fresh hacks every day

Babsje Heron

Great Blue Herons: A study in patience and grace

Print Test Page

Check Your Printer Quality

paeansunpluggedblog

songs unheard by the poet next door

This, that and the other thing

Looking at life through photography and words

The Wild Coach

You are an important nexus of energy

Cindy Bruchman

Photography. Observations. Adventures. Let's talk.

Time To Talk Beauty

A world of beauty ... from Scotland

Julia's books

Sharing my passion for books with views, news and reviews

Tasty Eats

Tasty recipes from chef Ronit Penso's kitchen

%d bloggers like this: