Anyone can do a ELI5 on the app signing key replacement difficulty?
It isn't covered in the article and seems too high level for a layman like me.
Anyone can do a ELI5 on the app signing key replacement difficulty?
It isn't covered in the article and seems too high level for a layman like me.
On Android, an updated app is validated by the system to be signed by the same signing key hash as was used previously.
The most recent (v3, IIRC) apk signing scheme allows you to update an APK and sign it with the old key, and committing a future new signing key, which permits re-keying an app.
To use this, I believe you need to ship a platform (operating system) update, as the underlying apps are signed using old APK signing schemes.
These OEMs are likely not always shipping the latest OS version, but could look to techniques used in the custom firmware world, where there are tools to allow reflashing the OS without losing app data when changing system signing key.
It requires engineering effort for already released devices though, so I suspect we will see very little action - as usual, the eyes are on the future products, not on previously released products.
I assume Google play protect will be used to carefully patrol and detect apps on devices signed by the leaked keys, but this isn't hugely helpful for anyone concerned about "zeroday" style targeted attacks against them.
Well then they better do some f..ing testing. They're only one of the biggest tech companies in existence. Making phones isn't trivial either!
The stuff around it is where the complexity lies: making sure you get updates and have infrastructure to distribute these to customers, that you apply for and get certifications from regulatory agencies and, in the US, carriers, deal with e-waste and warranty regulatory requirements (which is a pain in the EU), establish a supply chain for spare parts...