Best Review

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Saturday, 20 July 2013

Android Master Key Bug Not a Risk if You Stick With Google Play

Posted on 19:27 by Unknown

A vulnerability in the Android operating system lets attackers take an existing app, inject malicious code, and repackage it in such a way that it can pretend to be the original app. Should you be worried?

Researchers at Bluebox Security found the flaw in the way cryptographic signatures for apps are verified, Jeff Forristal, CTO of Bluebox, wrote on the company blog July 3. This means attackers could modify the app without changing its cryptographic signature, Forristal said. 

The flaw has been around since Android 1.6 ("Donut") and made "99 percent" of devices, or "any Android phone released in the last four years" vulnerable to attack, Forristal claimed. 

The scary scenario goes something like this: a legitimate app (for example, a Google app) is modified to steal passwords or connect the device to a botnet and released for users to download. Since both apps have the same digital signature, it will be difficult for users to know which is real and which is fake.

Well, not really.

Am I in Danger?
Google updated Google Play so that there are checks in place to block any malicious apps using this exploit to masquerade as some other app.

If you install apps and updates from Google Play, then you are not at risk from this exploit, since Google has taken steps to secure the app marketplace. If you do download apps from third-party marketplaces, even semi-official ones such as Samsung and Amazon app stores, then you are at risk. For the time being, it may be worth holding off on using those marketplaces.

Google recommends that users stay away from third-party Android app markets.

What Else Can I Do?
It's also important to remember that you should always look at who the developer is. Even if a Trojanized app does make it through Google Play, or if you are on a different app store, the app won't be listed under the original developer. For example, if attackers repackage Angry Birds using this vulnerability, the new version would not be listed under Rovio's account.

If you want to make sure you can't install apps from third-party sources, go into Settings > Security and make sure the checkbox for installing apps from "unknown sources" is not checked.

If you have the latest version of Android, then you are also protected by the built-in app-scanning system as it scans apps that came from sources other than Google Play. That means even if you mistakenly install a bad app, your phone could still block the malicious code.

There are also security apps for Android which can detect malicious behavior and alert you about the offending app. PCMag recommends our Editors' Choice Bitdefender Mobile Security.

Is an Attack Likely?
"Just because the 'master key' has not yet been exploited, doesn't mean we can rest on our laurels," Grayson Milbourne, security intelligence director at Webroot, told SecurityWatch. Mobile security should be about protecting the device from all sidesidentity protection to protect passwords and other personal information, blocking malware and malicious-apps, and being able to find the device if it is lost or stolen, Milbourne said.

Bluebox reported the flaw to Google back in February and Google has already pushed out a patch to its hardware partners in the Open Handset Alliance. Several handset manufacturers have already released patches to fix the problem. The carriers now have to push the fix down to their end users.

"It's up to device manufacturers to produce and release firmware updates for mobile devices (and furthermore for users to install these updates)," Forristal said. Bluebox plans to reveal more details during the Black Hat conference in Las Vegas at the end of this month.

Pau Oliva Fora, an engineer with mobile security company viaForensics, posted a proof of concept exploiting the vulnerability on github July 8. Fora created the shell script after reading details of the bug posted by the Cyanogenmod team. Cyanogenmod is a popular version of Android that users can install onto their devices. The team has already patched the flaw.

If you are among the lucky few users who receive an Android update from your carrier, make sure you download and install it right away. Even if the risks are low, updating the OS is just plain good security sense.


Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Posted in News | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • RGT Force Feedback Pro Clutch Edition
    The RGT Force Feedback Pro Clutch Edition wheel and pedal set gives you the features and customization tools you want for a realistic racing...
  • France Drops Internet Disconnection From '3 Strikes' Piracy Law
    France has struck down the port...
  • Intel 335 Series 180GB SSD
    Intel has had a prominent role in the consumer solid-state drive (SSD) market since it launched its 80GB X25-M solid-state drive back i...
  • Microsoft Ending MSN TV Sept. 30
    Time to give the bad news to gr...
  • Accounting Software: Tips for First Time Users
    If you're like most business owners, you prefer to focus on the things that got you started satisfying clients, making a quality produc...
  • Tech Made in the U.S.A.
    Desktops ...
  • Brother MFC-9130CW
    Projectors PCMag.com provides up...
  • Epson Artisan 730
    Epson touts the Epson Artisan 730 ($199.99 direct) as an all-in-one for the photo hobbyista more accurate description than you might as...
  • The 5 Best Scanners for Macs
    OB Roundup As a Mac owner, ...
  • Review: Nikon Coolpix S6500
    Introduction Nikon's Coolpix S6500 combines Wi-Fi connectivity with a 12x optical zoom lens and a 16 million pixel sensor, all of which ...

Categories

  • Best Review
  • Electronic Review
  • News
  • Review
  • Tutorial

Blog Archive

  • ▼  2013 (500)
    • ▼  July (353)
      • Haswell vs. Ivy Bridge: A Look at Old and New
      • Seagate Unleashes New Ultrathin Hard Disk Drive
      • Glidecam HD-2000
      • Ask Alex: When to Send a Thank-You Email
      • HBO GO, WatchESPN Added to Apple TV
      • Toshiba 39L2300U
      • Panasonic TC-P50ST50
      • New Rules on Kids' Online Privacy Require Adults t...
      • HP LaserJet Enterprise 700 Printer M712dn
      • Viber Updates Windows Phone 8, Desktop Apps
      • From GPS to Watches: Killed by the Cell Phone
      • Panasonic TC-P60ST50
      • Microsoft Tips Windows 8.1 Preview, Smaller Window...
      • Sharp Introduces First THX-Certified, 70-Inch 4K HDTV
      • HP LaserJet Enterprise 700 Printer M712dn
      • At Apple, Steve Jobs' Legacy Lives On
      • Aereo Expanding to Chicago in September
      • IBM Acquires Cloud-Computing Firm SoftLayer
      • Bitdefender's Wildly Different Antivirus Tools Bot...
      • New Dropbox Platform Syncs App Data
      • Digital Storm Virtue
      • Facebook App Beta Testing; Verizon LTE Almost Fini...
      • Why Instagram Videos Stink
      • Intel Lifts the Curtain on Thunderbolt 2
      • Tribeca Film Festival Breaks Out From the Screen
      • Canon Color imageClass MF8280Cw
      • Samsung's 55-Inch Curved OLED Now Selling for $13,000
      • France Drops Internet Disconnection From '3 Strike...
      • How to Turn on Two-Factor Authentication for Facebook
      • Panasonic TC-P65ST50
      • HP LaserJet Enterprise flow MFP M525c
      • Digital Storm Virtue
      • Apple's Cheap Shot Bodes Ill for Company
      • Global LCD TV Shipments Fall for First Time Ever
      • Sony Unveils $2,000 Digital Binoculars With Image,...
      • How to Turn on Two-Factor Authentication For Your ...
      • Seiki SE39UY04
      • Report: Google Developing Android-Powered Game Con...
      • Facebook's New Swedish Data Center Goes Live
      • Nokia Chat Beta for Lumia Phones Goes Global
      • Chromium-Based Opera 15 Arrives on Windows, Mac
      • Yelp Expands Into Food Delivery
      • Seagate Slim for Mac
      • Facebook App Beta Testing; Verizon LTE Almost Fini...
      • Memjet C6010 Powered by Memjet
      • Buying an HDTV: Frequently Asked Questions
      • Comcast Boosts Xfinity Parental Controls
      • Bringing the Checkout Counter to You
      • Advanced Persistent Threats Rare, But We're Still ...
      • GoPro Hero3 Black Edition
      • Mobile Threat Monday: Android Spamware, In-App Bil...
      • Dell B1165nfw Mono Laser Multifunction Printer
      • Amazon Launches Jet City Comics With George R.R. M...
      • Samsung PN60F8500
      • What Is a Resilient City?
      • Sony Action Cam
      • And Now: Frickin' Laser TVs
      • Infographic: The Future Is in the Cloud
      • $3,500 Asus 4K Monitor Now Up for Pre-Order
      • Ubisoft Database Hack; NYC Gets .nyc; Tesla Petiti...
      • Tech Made in the U.S.A.
      • Samsung CLP-680ND
      • Crowdfunding For Environmental Change
      • Drift Innovation HD Ghost
      • Report: Apple, TWC Nearing Deal for Apple TV Progr...
      • Microsoft Opens Build; Nvidia Shield Delayed; FTC ...
      • Your All-in-One Guide to Super Bowl XLVII
      • Researchers Demo 3D Printing of Liquid Metal
      • Infographic: Digital Attacks! Protect Yourself Aga...
      • Hisense 55K610GW
      • Brother MFC-9130CW
      • Samsung PN60F8500
      • Drift Innovation HD Ghost
      • Major Microsoft Shakeup Rumored for Thursday
      • It's Not the iWatch, Deneve May Have Other Designs...
      • Porn Spam on YouTube: The Struggle Against Interne...
      • Are Dual-Boot Android and Windows Laptops Viable?
      • Sony's Howard Stringer to Retire in June
      • Intel 335 Series 180GB SSD
      • Samsung Acquires Boxee for Reported $30M
      • MSN TV Shuttering; Samsung Shares Dip; Apple App S...
      • Apple TV or Bust
      • Samsung PN64F8500
      • GoPro Hero3 Black Edition
      • Are Dual-Boot Android and Windows Laptops Viable?
      • Brother MFC-9330CDW
      • ADV: The Antispyware Center from PCMag.com
      • Nokia Lumia 1020; Garmin HUD Displays Directions; ...
      • NASA to Search for Life on Mars in 2020
      • Report: SSD Prices On the Rise Due to Tight Supply
      • Samsung PN60F8500
      • Lenovo Desktops Scale Down for Small Biz
      • Android Master Key Bug Not a Risk if You Stick Wit...
      • Get Organized: 4 Tips for Organizing iPhone Apps
      • Hisense 50K610GW
      • Netflix, CBS Renew Streaming Deal, Add New Shows t...
      • Sony Action Cam
      • New Dropbox Platform Syncs App Data
      • Is This the New LG Optimus G2?
      • Brother MFC-9340CDW
    • ►  June (147)
Powered by Blogger.

About Me

Unknown
View my complete profile