Preinstalled Malware Targeting Mobile Users
blog.checkpoint.com
blog.checkpoint.com
Android security is a joke. Seriously. Don't use an Android phone.
There's a picture of their crappy security in practice. It needs much better and more granular controls for me to consider it secure.
I can't take things like project zero seriously when the same company works hard to weaken Android privacy.
* Not me strictly-speaking, because I’m an iOS user for the reasons specified by GP, among others.
I'm exceedingly disappointed with all current mobile offerings. Holding out distant hope for Ubuntu.
me too! I've recently got one and am eager to get it going. But as it stands now, it's not an alternative.
In that sense, a prison is safer than being outside, too. Should I live in a prison instead then?
I am not trying to bash iOS here, but it is very clear that security in iOS comes at the cost of freedom and not being able to do a lot of things. For example, you can only install apps through the App Store. You cannot mount USB drives and so on.
Security is always a tradeoff.
I mean... I see Android as akin to the situation in The Walking Dead that led to them living in a literal prison, so yes. I've always avoided Mac when possible, but in the mobile space I'd rather use those devices less, and less freely, but more securely. I'll explore my options on my desktop or laptop.
(and, of course, Android is not so nice either without the magic non-Free bits from Google...)
On the Apple developer website, when you make a free dev account.
And yes, it is mac only. But they are a mac company.
Can confirm it sucks. Android Security Patch Level on my phone is 2016-01-01. Funny cause on my old different manufacturer phone before this one I had a more recent security patch. I am pretty sure some nasty stuff came out between now and then.
Can't tell if Android is the issue, the phone manufacturer or both.
The OS limits an app's access to data that belongs to that app, so an app can't gather information you do not give it access too. (e.g. you have to give explicit permission for it to access photos or GPS location). But you do not have any control over other analytics the app may gather and upload, e.g. frequency of app use or info you enter.
Not saying this isn't an important finding, but that part was a bit self-serving.
Edit: I guess I never fully drank the mobile kool aid anyway... It's been what 10 years, the gee-whiz-bang effect has worn off, and they're revealed to be little more than a leash/tracking device for humans, with a small shitty interface on which you can't use more than 1 or 2 digits (fingers, son). So that's the foundation of indifference the above indifference comes from.
Every one of these was bought used from a third party that installed malware prior to reselling. If you buy a new phone from a manufacturer, major retailer, or major carrier, this doesn't apply to you. If you buy a used phone from a trustworthy friend or family member and reset it for use, you're probably cool. If you buy a used phone from someone you don't know/trust online or off, flash it back to factory condition before you use it.
Rather than giving people a lengthy and arbitrary list of purchase caveats, why not ask why it's so difficult to secure an android phone through the supply chain? And what, if anything, are other phone manufacturers doing that might be making the problem much more secure?
I'm not sure how they consider that 'pre-installed'.
A more appropriate headline might be 'wholesalers install malware on phones before sale'.
Eh, "preinstalled" isn't specific enough. I interpreted it similarly to some of the other folks in the thread, that it meant installed by my mfgs. But whether "preinstalled" is that specific or not is mostly a moot point, since it's apparent that the wording of the title isn't sufficiently precise.
The wording of the title is just fine. This is just a case of someone trying to show how smart they are by nitpicking on insignificant details and feigning non-comprehension.
In doing so, the discussion is no longer on the substance of the article, but rather on insignificant semantics.
So it's up to the phone manufacturers to implement; Google would never be able to implement this in a truly secure fashion, even if they knew all the software installed on the phone a priori.
On a related note, I know that Cisco wants something like this for their hardware, but at runtime instead of just on-boot.
You can change whatever you like, but if it's not stock there's a clear warning. I'm fine with that.
Let's assume that the manufacturer places its cert in ROM so nobody can change it. Great! We are totally secure! Actually, not at all. Where does the signature check take place? In software? Then an attacker could man-in-the-middle and feed the signature check function with a malicious cert. Even if this was not a problem somehow, how would the manufacturer handle key revocation? The cert is burned in, so if their key is compromised, every single device out there is broken.
In summary, unless every single step of the signature check is performed in an isolated environment (e.g., TPM), an attacker will always be able to circumvent the process. Solid crypto is not enough; you need to also ensure that the crypto implementation is tamper-resistant!
Yes, I was poking fun at the name :)
Apparently moto messages can be deleted http://www.droidviews.com/remove-unlocked-bootloader-warning... so it's not handled in read only memory.
Chromebooks do this properly, though. See http://dhanus.mit.edu/docs/ChromeOSSecurity.pdf. Section 3.1.1 talks about the specifics, root keys, etc.
You got me haha :P
> Chromebooks do this properly, though. See http://dhanus.mit.edu/docs/ChromeOSSecurity.pdf. Section 3.1.1 talks about the specifics, root keys, etc.
Looks interesting, I'll check it out.
From my perspective there's been a drastic rise in these kinds of ad posts appearing on the HN front page lately. I dunno if it's vote manipulation via paid viral marketing or something else but it sucks.
"Please don't submit comments complaining that a submission is inappropriate for the site"
I think it's pretty clear from my comment why I'm saying something; it's not just about this one article, there's been a rise in these obvious ads on the site in general (from my point of view), and I feel something needs to be done about it. I've obviously flagged every one of them but that's not enough.
The point of me making a comment about it is to see if other people feel the same way. If you don't agree, you can reply and say "I don't agree, I think these ads are good / I don't see many of them / whatever."
Replying and quoting the guidelines like that is trying to just shut down the discussion and/or just being pedantic.
Surprised this possibility wasn't discussed in the article.