Researchers Beat Google's Bouncer
An anonymous reader writes "When earlier this year Google introduced Bouncer — an automated app scanning service that analyzes apps by running them on Google's cloud infrastructure and simulating how they will run on an Android device — it shared practically nothing about how it operates, in the hopes of making malicious app developers' scramble for a while to discover how to bypass it. As it turned out, several months later security researchers Jon Oberheide and Charlie Miller discovered — among other things — just what kind of virtual environment Bouncer uses (the QEMU processor emulator) and that all requests coming from Google came from a specific IP block, and made an app that was instructed to behave as a legitimate one every time it detected this specific virtual environment. Now two more researchers have effectively proved that Bouncer can be rather easily fooled into considering a malicious app harmless."
It seems like they just found that the sandbox Google simulates the apps in is a little sloppy in its simulation (IP addresses are predictable), so it's easy to tell you're inside the sandbox. But they could fix that part pretty easily.
Was hoping for something more halting-problem-esque, since it's really difficult to "scan an app for malware" in general.
10 PRINT CHR$(205.5+RND(1)); : GOTO 10
I thought bunch of nerds gave a drubbing to a bouncer at Google-sponsored party. Must be the bad coffee.
Fuck systemd. Fuck Redhat. Fuck Soylent, too. Wait, scratch the last one.
"Google was aware of and blessed the research, and has been apprised of its results so that it can make changes and better secure Google Play against malicious individuals."
"A renowned security researcher who claims he discovered a flaw in iOS was kicked out of Apple's iOS Developers program."
Just sayin'.
Actually any malware that's "smart" enough to fool Bouncer is left alone while the NSA, FBI, and MPAA are alerted. Black helicopters full of hot women in black latex arrive...
https://app.box.com/WitthoftResume Code: https://github.com/cellocgw
News Flash: Any automated security system can be beaten.
In further news, using technology to secure against technology is only as effective as the minds behind it.
Tune in at 11.
Running unsigned apps on a smart phone is just plain stupid. Why not just require android apps to be signed by a revokable certificate.. Charge at least $100 to get the certificate.. and then reward the malware-free app developers with a credit of at least $100 to cover the certificate cost.
Apparently spelling isn't your forte either. And I'm not even going to get started on how much of a racist piece of shit you are.
If they want secure apps in their stores, why don't they just demand that app-salesmen provide the source so that everyone can inspect it? They have the clout to do it, and it's not like any phone apps are going to contain any super-secret algorithms that must be kept secret for economical reasons.
Lets see what we have:
1. Inside Google - A bunch of college boys (no girls, as they are not smart enough for google), very, extremely good at solving entry interview quiz and questions, but extremely poor and incompetent at actually doing what they were hired to do, DEVELOPING.
2. Outside Google - A bunch of software developers, usually old, with a lot of experience, some of them even PhD, and who are actually DEVELOPING a software that google buys, because their bunch is so incompetent...
So to sumarize it:
SURPRISE. The guys outside always outwit the boys inside.
Bounced googles you!
It's almost as though they're trying to achieve security by making information about their service very obscure. Has anyone ever tried this before?
Please, STOP FEEDING THE FUCKING TROLLS!!! Ignore them For God's sake, don't quote them!!! Jesus, man, what the fuck is wrong with you? Anonymous troll is at -1 so you gave him a voice! Mods, please downmod every response to the troll, including mine but especially the parent's, who stupidly quoted the racist bullshit. Fucking trollbiters are often as bad as the fucking trolls.
Free Martian Whores!
Google was aware of and blessed the research, and has been apprised of its results so that it can make changes and better secure Google Play against malicious individuals.
MouseClass extends ScrollClass, which extends TabClass, which extends SidebarClass, which extends PowerClass, w
1 - not using random proxies
2 - not going out of their way to make the VMs look like real machines. This is already a problem with PC viruses, many of them are designed not to infect a VM to slow analysis.
"When information is power, privacy is freedom" - Jah-Wren Ryel
As long as you know what you're doing, obscurity can work just fine as another layer of protection.
The problem is that most people choosing obscurity aren't secure to start with, so it's the *only* layer of protection.
The problem that Bouncer is trying to solve (telling whether an app is malicious or not) is otherwise known as program verification. Rice's theorem states that this is undecidable, not totally unlike the Y2K problem. It may even be highly undecidable, so even if Google had a hypercomputer at their disposal, Bouncer would still lose.
So if Google wants to keep malware out, Bouncer is fundamentally the wrong approach.
Pawned.