Android 'Master Key' Puts Smartphones At Risk
It's estimated that up to 99 per cent of all Android smartphones are vulnerable to a new security vulnerability. The bug involves two of the main security measures used on phones running the popular Android operating system from Google.
The first security measure affected by the bug is the security check used on all applications that run on an Android phone. Every application has a cryptographic signature, which is a code that confirms the application is genuine.
The signature directly correlates to the contents of the application itself, meaning that any attempt to tamper with the contents would change the signature and alert the device that something was wrong.
The second measure is known as the 'permissions' system. On occasion, Android will prompt users to approve of an action before granting an app permission to follow through. This can involve an app dialing a phone number or accessing the device's camera.
"Master Key" Allows Undetected Tampering
But mobile security firm Bluebox says it has found a "master key" that lets it modify applications without altering the cryptographic signature, meaning significant changes would go undetected.
An altered app could therefore be set up to carry out malicious activities, such as passing on confidential data to the hackers. (Source: bluebox.com)
Even more seriously, Bluebox says it has been able to carry out undetected modifications on applications created by the phone's manufacturer. Such applications are commonly set-up to have all permissions active because the system inherently needs to trust the manufacturer.
That means a hacker infiltrating such an app would have almost complete control of an Android phone.
There are limitations, however: hackers would have to find a way to access a phone to modify an app or, more likely, to trick users into downloading and installing a modified version.
Security Patching Could Be Slow Process
Bluebox -- which insists it told Google about the problem five months ago -- says each individual phone manufacturer (working with the smartphone service provider) will need to issue its own security update to fix the problem. (Source: techcrunch.com)
In the meantime, Bluebox suggests users take care when downloading and installing apps. This means checking carefully to make sure they really do come from the advertised publisher.
It may also be worth sticking to the official Google Play store until an update is available.
Most popular articles
- Which Processor is Better: Intel or AMD? - Explained
- How to Prevent Ransomware in 2018 - 10 Steps
- 5 Best Anti Ransomware Software Free
- How to Fix: Computer / Network Infected with Ransomware (10 Steps)
- How to Fix: Your Computer is Infected, Call This Number (Scam)
- Scammed by Informatico Experts? Here's What to Do
- Scammed by Smart PC Experts? Here's What to Do
- Scammed by Right PC Experts? Here's What to Do
- Scammed by PC / Web Network Experts? Here's What to Do
- How to Fix: Windows Update Won't Update
- Explained: Do I need a VPN? Are VPNs Safe for Online Banking?
- Explained: VPN vs Proxy; What's the Difference?
- Explained: Difference Between VPN Server and VPN (Service)
- Forgot Password? How to: Reset Any Password: Windows Vista, 7, 8, 10
- How to: Use a Firewall to Block Full Screen Ads on Android
- Explained: Absolute Best way to Limit Data on Android
- Explained: Difference Between Dark Web, Deep Net, Darknet and More
- Explained: If I Reset Windows 10 will it Remove Malware?
My name is Dennis Faas and I am a senior systems administrator and IT technical analyst specializing in cyber crimes (sextortion / blackmail / tech support scams) with over 30 years experience; I also run this website! If you need technical assistance , I can help. Click here to email me now; optionally, you can review my resume here. You can also read how I can fix your computer over the Internet (also includes user reviews).
We are BBB Accredited
We are BBB accredited (A+ rating), celebrating 21 years of excellence! Click to view our rating on the BBB.