Cryptographic key used to sign one of Facebook's Android apps compromised
androidpolice.com
androidpolice.com
Kudos. I wonder why PlayProtect didn't catch this? On one hand project-zero does stupendously well and on the other a project like PlayProtect fails at checks that an untrusted third-party routinely does. It can't be incompetence? It can't be blind reliance on AI?
Android has a 2B install base, and security will quickly turn into an unprecedented nightmare as more and more people get exposed to scamware, spyware, scareware, malware for the first time. This is not even factoring privacy encroaching viral apps like Helo, ShareChat et al that have in some cases 100M+ installs.
PlayProtect needs to be able to evaluate every app in existence (millions of apps on the Play store, ??? off the play store, and dozens or hundreds of versions of each of these apps). Malware authors are incentivized to perform all manner of tricks to avoid detection (code obfuscation to prevent static analysis, environment detection to prevent dynamic analysis, etc). It needs to do so in a (presumably) fully automated fashion since there are so many apps. It also gets little credit for when it works and instead only makes the news when it fails.
So 100% of the coverage of GPZ is positive and 100% of the coverage of PlayProtect is negative.
That said, the last bit abt a 100% coverage rings true. The signature check; however, seems like one of the important things to do (of course, there are lot of edge cases to be taken care of)? It can't be any more expensive than the AI they run on millions of apps.
Add to this the fact that signing keys are often shared in weird ways (usually with OEMs) and maybe it doesn't make too much sense to use "this is signed weirdly" as sufficient evidence to remove from Play.
so to detect this manually, they'd have to be checking every single app! more likely, they've an automated system that detects new APKs signed with prominent keys.
Although it's very possible that the thing you mentioned is a fluke and somebody decided to ask the question "We should probably keep all the Facebook apps definitely-safe, so which ones are signed with this key?"
We are totally willing to do "weird" things with hardware signing keys in the name of security... it just isn't really clear what the correct thing to do is :(. Should we be using Google Play App Signing for the Play Store, even if we can't do that for other distribution mechanisms? As I kind of remember unrelated stores being able to manage and upgrade apps (particularly free ones) from different stores, as they just get a list of installed apps from the OS, it would seem problematic to use a _lot_ of different keys (such as one per store)? I will again note that, due to our constraint of being pretty sure we will have off-App Store distribution (some of our key markets don't use the Play Store much), we need to solve the key security problem for non-Play Store distribution "anyway", and so can't just fall back on "don't do local signing".
Meanwhile, I didn't even know yet about the Android 9 key rotation feature mentioned in this article, which I could see maybe having major changes on best practices here, though maybe only "going forward" (given how few users have upgraded to Android 9 so far, and now that I think about it probably won't for years to come...). In a world where you can effectively never change your key, it seems really important to have your act together on "day 1" to get stuff right (though I also am not even sure what is reasonably possible, given how I think it all fundamentally relies on a single key? so we can't do some kind of multi-sig? I also don't know if we can do sub-certificates with short signing duration with a root certificate backed by a vaulted key, as people often do for SSL?)
Reproducible builds can also help you to mitigate this risk - so you then can cross check that the source is properly signed and produces the right binary before signing the binary. If you are publishing source code then your customers can also double check this as a second vector, should they want to.
Did someone breach Facebook to steal it, or did Facebook employees post it somewhere?
Curious to learn more details. Probably again much worse then initially being reported on.