Google Has Android Remote App Install Power, Too
Trailrunner7 writes "The remote-wipe capability that Google recently invoked to remove a harmless application from some Android phones isn't the only remote control feature that the company built into its mobile OS. It turns out that Android also includes a feature that enables Google to remotely install apps on users' phones as well. Jon Oberheide, the security researcher who developed the application that Google remotely removed from Android phones, noticed during his research that the Android OS includes a feature called INSTALL_ASSET that allows Google to remotely install applications on users' phones. 'I don't know what design decision they based that on. Maybe they just figured since they had the removal mechanism, it's easy to have the install mechanism too,' Oberheide said in an interview. 'I don't know if they've used it yet.'"
You mean they can remotely install apps over the air just like every other modern phone on every other carrier I've ever seen?
This is a non-story -- OTA install is pretty much required by every carrier out there so they can force you to upgrade your phone.
I think the name is what's most interesting -- INSTALL_ASSET - that has a distinctly govt feel to it. Gotta wonder.
Such flaws are why professional developers do not put in random features that can be exploited. Sure it might be fun toi say that our application has a thousand more features than the competition, but to those that are savvy it is just a thousand more way to be put at risk.
"She's a scientist and a lesbian. She's not going to let it slide." Orphan Black
Excuse my ignorance... but why is this a surprise when android is an open source OS? Why has anyone not noticed this in the source code!! Or is only kernel open source and not the other parts?
My suggestion is that you rely on a land line phone then (were I that worried over it I would go with a vintage rotary phone too - no computer to futz with). All cell phones I know of can add or remove features without your permission. Some may choose not to do so, some may regularly do it, but they all do. Even worse an iPhone, Blackberry, or an Android are *not* phones, they are handheld computers that just so happen to have a cellular device attached to them. You LG flip phone that has no apps other than what is on the rom is fairly stable, your smart phone is a computer and has all the issues associated with a general purpose computer along with the access that the carriers have always wanted but could never demand before. Some are claiming an N900 can't have this happen but before I made that statement I would want some independent party to verify, not just the assumption it can't from what I have seen. The competition that the /. crowd is mostly looking at (the iPhone) is just as bad with respect to ability to do things but hasn't decided to do so (yet) - the Blackberrys fall into the same boat.
Pretty much every carrier out there has these abilities, they do so for a number of reasons (few of them are for your benefit though) and that isn't going to change. Indeed, even just the plain cell phone will generally have features they can remotely turn off and on. The iPhone (and IIRC the new 2.2 androids) can be remotely bricked (sold to us a security feature). I have not seen Google do anything that would particularly make them untrustworthy compared to everyone else - indeed I find them better than most (at least they are upfront about the things I do not like instead of lying to me or trying to convince me that raping me is a Good Thing). That is, of course, a kinda loaded statement as I have little trust for any one else - but since I have no choice but to play in that world they are as good as any of the better ones out there. I treat my phone access like any other non-secure communication - I assume anyone and everyone can see it. For secure access I assume most people can see it.
Plus as the GP says - if the SSL cert is broken then the ability to remote install apps on your phone is the least of our worries. Most phones can be bricked remotely not to mention all the secure sites that rely on x.509 certificates.
------- Sorry about the spelling, I suffer from two problems. Dyslexia makes it difficult to spell well, lazy makes it
one day you look at your phone: hey, there's a bing icon
couple of months later: look at that, a skype icon
it's vaguely unsettling, to be reminded of how raped you are in terms of privacy
intellectual property law is philosophically incoherent. it is your moral duty to ignore it or sabotage it
Meh, they have that kind of software for almost all phones. http://flexispy.com/ and plenty others, I'm sure.
I suppose it might be nefarious that they don't even need physical access to your phone to install it. But the install feature probably asks for user confirmation before receiving a "push" install from your carrier, just like my cheap Samsung dumbphone.
If you really want control, I suppose you could put http://www.cyanogenmod.com/ on your Android phone. Is that affected?
Google wanted control so they pushed http://en.wikipedia.org/wiki/Android_(operating_system)
GPLv2 to bait you in, Apache 2.0 to close you down if needed.
You write the 'free' apps, hunt bugs, preach about the 'freedoms', Google tracks, sells ads, data mines, a push and profit with a sting in the tail it seems.
Domestic spying is now "Benign Information Gathering"
Not to mention, google already announced you will be using this feature before. If you haven't seen this years google I/O then I'll tell you: you will be able to install apps on your phone from any device in the cloud.
And besides, it's not like google is targeting you specificaly, they target all phones with that app installed. The purpose of it is to remove a malicious app before it can do any more damage.
Example: I make an app branded as a porn site viewer, it works as one but it also sends information gathered from your sdcard/phone for some nefarious deeds. Removing it from the market would stop the app from spreading, but it has already been installed on thousands of phones, setting a flag on the market for "uninstall from phone NOW" would fix this.
I know google could be more gentle about it and warn the user and ask for the app to be removed, but it's not like they use it on every app that pisses them, only on those that disregard their stated rules. So far google has been following the rules, so articles like this are just spreading FUD.
He queues just like everyone else, and always offers to pay, but the Apple stores near his house have standing instructions from the other Steve to refuse to take payment from him.
I am TheRaven on Soylent News
Exactly my thought. It's not like Google has never found their servers compromised by China, for example. I'm surprised that the US government isn't a little concerned that Google has just potentially handed China the ability to turn every single Android phone into a bug. I wonder if this is part of the reason why GCHQ does not permit Android phones for government use in the UK...
I am TheRaven on Soylent News
I suppose it might be nefarious that they don't even need physical access to your phone to install it. But the install feature probably asks for user confirmation before receiving a "push" install from your carrier, just like my cheap Samsung dumbphone.
Right. Because the DELETE_ASSET API sure asked for confirmation before deleting those apps from potentially MILLIONS of Android phones.
Oh, wait...