Inner workings revealed for “Predator,” Android malware that exploited 5 0-days
arstechnica.com
arstechnica.com
Probably some immutable Linux distro would be better. Are there guides out there how to do that for non-experts?
Without being opposition in some of that state, most of us handle money in their insecure devices. Can we be sure that "ordinary" criminals don't have enough access for their purposes?
The real lesson here is to not have unsupported devices in your possession. This malware uses 5 exploits which were from 2021.
> Probably some immutable Linux distro would be better. Are there guides out there how to do that for non-experts?
Android is an immutable system, but it doesn't help when people won't upgrade to a supported device. A "linux distribution" isn't going to help when there are proprietary firmware components that aren't updated.
> Without being opposition in some of that state, most of us handle money in their insecure devices. Can we be sure that "ordinary" criminals don't have enough access for their purposes?
Easiest way is to minimize having unsupported devices. The Pixels have a 5 Y support period that includes the underlying firmware.
This article is misleading, they're not "zero days" when they were discovered 2 years ago.
Manufacturers which don't fix CVEs within 90 days must accept returns at full sale price.
That would fix the whole economics around vulnerablities.
I think further provisions are necessary, such as source code escrow; once you go out of business or drop software support for a product, the entire code repository should open up to the public to fix it themselves, including the necessary keys to load the replacement software. It shouldn't matter if you use the same code base for other devices that you do support, if you're maintaining that code you may as well push those fixes out to older devices.
The biggest issue with phones and tablets is that often the problem lies within kernel driver that the manufacturer has no control over. Qualcomm and friends are the biggest crooks here, sometimes dropping software support for their chips after only two or three years, with no realistic alternatives for sourcing SoCs.
How does that help when most vulnerabilities are found after the phone was sold?
It'd have some side effects of centralizing handset manufacture into a few manufacturers (and core component suppliers) and/or pushing more into using straight-Android.
But making the economics more aligned with security, in a predictable way for the manufacturer, seems important enough to make the trade-off.
Mandating fixes for CVEs in 90 days sounds nice on paper… Not sure about the implications of that
Mandating a time to fix puts a lot of pressure on manufacturers to have security teams ready at all times and make sure their patch process works pretty flawlessly.
The implications on device prices is certainly an increase by 10% but a lot of knock off devices would stop making economical sense.
If by $BigTech you mean Google. Apple just released a patch for iPhone 5S devices (circa 2013) earlier this year.
No, the real lesson from any similar discussion is to never, ever, ever trust any cell phone, or any other form of computer, period. It literally doesnt matter who assembles device, codes/builds OS or does full stack creation of components. It doesnt matter how many gigatons of Apple's koolaid you drank. If you are smart, use other ways or at least change very frequently burner phones (not very ecological but once you are a target for anybody powerful enough, unfortunately such concerns evaporate). The idea that 'this next solution solves everything' is really dumb, it failed spectacularly every single time so far.
The chain of elements from screen to packets sent over network, and network itself is extremely long and to claim each of the piece is 100% secure is not naive, just stupidly ignorant. Especially with all the scandals from manufacturers, NSA/CIA, Snowden revalations etc.
Or just dont do anything else that everybody else is doing, states nor corporations have no reason yet to go after almost everybody out there. But if you hold any position of power, even completely apolitical then you are already a target for decades and no amount of OS updates will make your phone actually secure.
I thought lack of publication made them 0-days. If it's published it's not a 0-day anymore?
That's of course a minimum requirement. But the analysis showed that it took e.g. Samsung 8 months from distributing vulnerable code to distributing the fix for one the CVEs. Google was faster, but even them it took several months.
> Android is an immutable system,
OK, system might not be a uniquely defined term here. As always it depends where you draw your system border. If you mean the system firmware image, it is probably immutable. Not sure whether all vendors use dmverity.
However, I meant "the whole phone". Obviously Android phones are not immutable, you can install apps. And after rebooting they are still there and can again use the same vulnerability if there is one. What I meant by immutable is there is no way to install any executable code, because all storage that is writable is noexec. And even if a vulnerability exists and allows to mess with RAM, the corruption is gone at reboot (well, unless the write protection, code signing / dmverity itself is affected by the vulnerability). Without having really worked with most of them I understand Vanilla OS, Fedora CoreOS, Fedora Silverblue, and SUSE ALP all go into that direction (although they still allow installing additional containerized apps).
Including a browser and an email client into the base image and removing the option to install anything else is what I meant with immutable Linux distro.
When you update it, you install another signed image. Of course the supply chain for that image is then the risky part, you'll never have zero risk.
Of course, this is a terrible state to have to be in.
> Probably some immutable Linux distro would be better.
Nope
> Without being opposition in some of that state, most of us handle money in their insecure devices. Can we be sure that "ordinary" criminals don't have enough access for their purposes?
Generally "ordinary" criminals find it to be more cost-effective to phish you
A Android or iOS full chain is likely worth a couple million American each. Due to the extreme prices you can be sure when governments use it they do their best to hide their tracks to not burn the vulnerabilities.
Stealing someone’s money is probably a very noticeable way to burn your exploits or at least alert someone to fact that their device has been compromised.
I'm interested to find out why too.
anyway Israel isn't the only one selling spyware software. There are a metric ton of sellers, operators, and people just selling zero-days to any bidder
the answer to their question is that Israel is a dense, highly educated country with a lot of expertise in computer security and other technology areas. VRED is a difficult and exciting area of work, and the pipeline from gaining these skills in the military and translating it to private industry is very real. it has nothing to do with freedom of the press, journalists, or human rights
They also have a steady stream of IDF graduates from Unit 8200 [1] (and other bits of the IDF) who are young, smart and know each other as a cohort. You'll meet groups of them at lots of Israeli firms; and lots of older cohorts will have good networks across the sector because of this.
Also bear in mind Israel crippling vulnerability to organised terror whose leaders cruelty know no limits and view every jew as a legitimate target. Especially in a freedom loving society this is intolerable so every step is considered in fighting this menace.
I'm not making a moral judgement on this, I'm just saying I understand why there are a lot of companies that create weapons in a country at war for most of its existence.
For someone in such position deciding "do I want to work on things that rip people to shreds, or would I rather work on surveillance software?" The surveillance software choice can be considered a lesser evil and potentially something that can save lives etc.
No other Western-aligned country has such a pipeline - the US has it partially, but wannabe-competitors have a harder time acquiring customers, as non-Americans have to deal with ITAR and other export controls.