What can I do to mitigate those risks?
What can I do to mitigate those risks?
And when installing a OEM-signed app, instead of the normal permissions dialogue, there should be a giant red warning that says the app can basically root your device. If the OEMs don't like it, they can set up a second key pair with no privilege escalation capability to sign updates for most of their apps (the ones that don't need elevated privileges).
This article from Malwarebytes reported on a family of malicious apps with over 1M downloads: https://www.malwarebytes.com/blog/news/2022/11/malware-on-th...
This paper analyzed 1238 malicious apps grouped into 134 families: https://people.ece.ubc.ca/mjulia/publications/GooglePlayMalw...
An attacker who can steal these private keys can get malware uploaded to the Google Play store. Getting malware uploaded to Google Play is way easier.
And if Samsung's private key is stolen, I would certainly not be inclined to trust their Galaxy Store.
Now is a great time to go through your phone & uninstall apps you don't use or don't trust -- especially bloatware from the compromised OEMs. If I understand other comments in this thread correctly, the stolen keys allow the thief to escalate privileges from "ability to issue an update for a random app you have installed" to "ability to root your device".
The working hypothesis (gathered from other comments here) is that the main vector of attack for this case may be restricted to the sideloading system-level components (not end-user apps).
It's the end of the world as we know it, and I feel fine.
[0] https://sortatechy.com/android-users-are-there-worldwide/ [1] https://www.statista.com/statistics/1020956/android-app-rele...
Am I supposed to believe Google thoroughly vets all 100,000 of those apps?
My assumption is that any automated vetting system can be defeated by a serious attacker (the sort of attacker who can steal private keys). Just keep tweaking your malware until it gets past the filter.
>Given these facts, it simply does not follow that a family of malicious apps with 1M downloads or an analysis of 1238 malicious apps demonstrates "Malware on the google Play store seems fairly common."
Not sure 100K is the right denominator here -- how many of those 100K receive any attention at all by security researchers? The numbers I quoted appear to demonstrate that when security researchers look for this stuff, it isn't hard to find.
>The working hypothesis (gathered from other comments here) is that the main vector of attack for this case may be restricted to the sideloading system-level components (not end-user apps).
Check out this article: https://www.pcmag.com/news/study-reveals-googles-play-store-...
If 67% of unwanted app installs originate via the Play store, wouldn't it be most natural for attackers looking to exploit a stolen private key to take that most common route?
An attacker who can steal multiple private keys from large multinationals can also get inside the software supply chain for your favorite fart app.
>It's the end of the world as we know it, and I feel fine.
If you're writing software that people use, you have a special obligation to take security seriously. An attacker who gains root access to your phone could e.g. sniff passwords and steal 2FA codes, use them to log into Github/AWS, and do a ton of damage to people who are depending on you.
What world do we live in, then? We live in a world where, even if 1238 new malicious apps were released _per month_, that would still represent fewer than 1% of all apps released. Yet, according to the report you mentioned, the 1238 malicious apps were published between 2016 to 2020. Rough math, then, gives us 1238 malicious apps out of 6M apps over that period. 0.02% of all apps. Not perfect, for sure. But I'm willing to live in that world. By the way, I'm not fixated on the 1238 number as if that's all the malware that existed duyring that time. But on the other hand, the writers of that report took their time and did the best they could to find as many malicous apps as possible for their research. So we have no evidence the true number was significantly higher.
>An attacker who gains root access to your phone could e.g. [do terrible things]
This is true, yet you still miss the point. If "malware on the Google Play store seems fairly common" as you claim, and malicious apps are therefore commonly ripping off passwords, 2FA codes, etc, where is the avalanche of tragic end-user stories we would be compelled to expect, by the laws of mathematics? 0.02% of the 2.7B Android users is still 55 MILLION end users. Yet, nothing near to 55M or 5M or even 50,000 end-users have had remotely catastrophic outcomes due to malicous apps hosted on the Google Play Store in any given sliding 5-year window (such as the one studied in the report).
Anyway, I've been generous with my words here since I sense you are sincere. But only a very few words are needed to reinforce my original point: Your quoted numbers do not support the assetion that malware is fairly common on the Google Play Store.
I'd go one step further, don't install any apps from third party websites. Also think very critically about trusted app stores, make sure you know their signature policy.