news.volyx.in

Platform certificates used to sign malware (bugs.chromium.org)

684 points by arkadiyt · 1375 days ago · 234 comments on HN

Article summary

Platform certificates used to sign Android system apps were compromised, allowing malware to be signed with legitimate certificates. The compromise was disclosed recently, but the exact timeline and details of the incident are unclear. Affected devices may be vulnerable to malware, particularly if they are no longer receiving updates. The impact of the compromise appears to be limited to specific brands and models of devices.

Main themes

  • Android security
  • platform certificate compromise
  • malware signing
  • key management practices
  • device updates and support
  • sideloading and attack vectors
  • state actor attacks and cybersecurity threats

What commenters say

  • The compromise of platform certificates is a serious security issue that could have been mitigated with better key management practices.
  • The delay in disclosing the compromise may have limited the time available for Android devices to receive updates with new keys.
  • Sideloading of apps is a potential attack vector for malware signed with compromised certificates, but it is not the only possible vector.
  • Some commenters argue that the compromise is likely the result of a state actor attack, while others suggest it could be the result of poor key management practices by device manufacturers.
  • The use of hardware security modules and secure workflows for signing artifacts could help prevent similar compromises in the future.
  • The impact of the compromise is likely to be limited to devices that are no longer receiving updates, and users who only install apps from the Play Store are at lower risk.
  • There is a need for greater transparency about the affected devices and the mitigation steps being taken by manufacturers.
  • Some commenters disagree about the significance of the compromise and the potential risks to users, with some arguing that it is a minor issue and others arguing that it is a serious security threat.