Android Update Lets Malware Bypass Digital Signature Check
msm1267 writes "A vulnerability exists in the Android code base that would allow a hacker to modify a legitimate, digitally signed Android application package file (APK) and not break the app's cryptographic signature — an action that would normally set off a red flag that something is amiss. Researchers at startup Bluebox Security will disclose details on the vulnerability at the upcoming Black Hat Briefings in Las Vegas on Aug. 1. In the meantime, some handset vendors have patched the issue; Google will soon release a patch to the Android Open Source Project (AOSP), Bluebox chief technology officer Jeff Forristal said. The vulnerability, Bluebox said, affects multiple generations of Android devices since 1.6, the Donut version, which is about four years old. Nearly 900 million devices are potentially affected."
It will be really interesting to see what this vulnerability is, on the 1st of August, since all that can be gathered from the press release is essentially:
It is possible to change an APK without changing its signature, and Android will not notice. That does have big implications, but it isn't enough detail to say anything much more than "Oh, that's not good".
I wonder how many of these 'vulnerabilities' are intentional, and get patched only when caught. Obviously these contraptions are wide open
“He’s not deformed, he’s just drunk!”
With all the fragmented versions of android, I sure hope that everyone(Verizon, att, etc) can get their heads out of their ass to get this patched. Im concerned for the people using these things for business, but consumers could be affected majorly too. I guess we can't be sure exactly how bad of an issue this is until the first though.
If Google were competent they would have shipped Android with a modified HOSTS FILE. Hosts files can protect you from APK modification and cubic time bastards.
...write once, zero-day everywhere!
You know, the keyword governments and like use to show off they have no fscking idea what you're talking about. "Hacker" used by "security researchers" this way (including self-described "hackers" of any self-described hat colour) really mean to say they're uncreative ham-handed hacks with, indeed, no real clue about security.
The downside, as with governments and sensible policy, is that these bozos are ubiquitous in security, and so are like consultants to an IT project: They're making good money in prolonging the problem.
If we want real computer security, we have to start looking through the noise. The simplest way is to ignore anyone who uses "hacker" and "hacking" as "someone or something vaguely related with something computer-y and probably dodgy too".
Name things for what they are, not with fancily abused terms that really have quite a different, and non-nebulous, definition.
Android Update Lets Malware Bypass Digital Signature Check
So an update will allow malware to bypass digital signature check. I'm sure not updating then.
I'm aware of the joke. Soon people will likely forget about APK the hosts file advocate, just as they have forgotten about Twitter the anti-M$ sock puppet master.
But seriously, a hosts file blocks hostnames that you don't want programs on your device to connect to. That's all it does. It won't help when the spooks are MITMing your device's Internet connection to third-party Android package repositories like F-Droid and Amazon and inserting exploits of signature check failures like this.
how dare anyone post anything security related about it. linux is secure, and apple's locking down of the device is evil. etc.
I run: Windows, OS X, Linux, FreeBSD. Just because you have a hammer, doesn't mean everything is a nail.
You state you don't do AC posts http://slashdot.org/comments.pl?sid=3667275&cid=43498013 in April 2013...
&
Yet earlier you said you do in 2011, here http://slashdot.org/comments.pl?sid=2238996&cid=36457458
So which is it?
(You look bad busted on that account as a known online troll being caught posting 1 of 100's of your usually ac submitted spams here http://slashdot.org/comments.pl?sid=3581857&cid=43276741 using your registered luser name.)
* Don't they call Satan "king of liars"? He's in 2nd place compared to you Jeremiah Cornelius.
(After all, you said it above contradicting yourself!)
So, thus: Per my subject-line above:
Fact is, You LIE, + You troll ac & do sockpuppets to "mod yourself up with" & your opponents DOWN with!
(Just like your "pal" tomhudson = barbara, not barbie (same person, pal of JC's no less too & "trolls of a feather" FLOCK TOGETHER + use the same DIRTY tricks, & he/she got caught in & left in May 2012!).
So now you're eating crow for it being exposed & you know it. Your reactions show it as well as your own LIES quoted above!
PLUS - You brought it on yourself for those 100's of ac spamming posts on hosts files (which I dusted you on totally on technical issues regarding them vs. other solutions even) -> http://yro.slashdot.org/comments.pl?sid=3717059&cid=43634223 point by "so-called 'point'" of yours (easily).
APK
P.S.=> You stated you worked for Microsoft & now VMWare? B.S., not in a truly technical capacity, or I wouldn't make such mincemeat out of you repeatedly on technical information in computing also...
... apk
"a hosts file blocks hostnames that you don't want programs on your device to connect to. That's all it does" - by tepples (727027) on Thursday July 04, 2013 @08:11AM (#44187041) Homepage
Custom hosts do more than that tepples & also speed you up 1 of 2 ways too:
---
1.) "Hardcoding" your favorite sites in it (faster ip address resolution from host-domain names locally vs. remote DNS servers).
&
2.) Blocking adbanners (good & bad - which make up up to 40% of most websites' pages).
( + custom hosts files ALSO ADD: Reliability (vs. redirect poisoned or "downed" DNS servers), aid "anonymity" to an extent (vs. DNS request logs, + getting past DNSBLs), & add "layered-security"/"defense-in-depth" (blocking known malicious sites/servers/hosts-domains that are malscripted OR serve up malwares/botnets etc.-et al))
---
* LASTLY - I wrote you on this via your wiki page, email, & regarding points you made on hosts with corrections, not in a "malicous way" either ( & on "# of the beast" you discussed here too), here -> http://slashdot.org/comments.pl?sid=3738579&cid=43696537 (use it!!!)
---
The only "joke" around here is how EASILY I make mincemeat out of naysayers on tech points on this subject, every single time they *try* me on it!
APK
P.S.=> For a FULL list of benefits custom hosts files provide in (which I invite ANY "naysayers" to disprove me on no less):
A.) Added speed
B.) Added reliability
C.) Added "layered-security"/"defense-in-depth"
D.) Added "anonymity" (to an extent vs. DNS request logs + skirting DNSBL's too)
See here (enumerated list + a 100% FREE program by "yours truly" that makes creating a custom hosts file from 12 reputable & reliable sources, easy):
http://start64.com/index.php?option=com_content&view=article&id=5851:apk-hosts-file-engine-64bit-version&catid=26:64bit-security-software&Itemid=74
... apk