UPDATED 14:16 EDT / JULY 08 2013

Android’s Achilles’ Heel Poses a Major Threat to Users

Researchers from Bluebox Security have discovered a vulnerability that leaves 99 percent of all Android devices exposed to malware. SiliconANGLE Contributing Editor John Casaretto discussed the findings in a recent interview with NewsDesk host Kristin Feledy.
Android uses cryptographic signatures to verify that application updates originate from developers. John says that the exploit Bluebox uncovered allows attackers to bypass this verification mechanism and modify an application without breaking its unique signature.

The severity of the compromise depends on the application. While an arbitrary app may or may not give attackers access to personal data, a pre-installed application with a platform key can potentially enable them to take over the entire device and co-op it into a botnet.

The bug dates back four years to Android’s 1.6 Donut build. John finds it notable that it took so long to detect, and highlights the importance of security research.

Feledy mentions Google Play, which features a filter mechanism that prevents developers from submitting apps with vulnerable signatures. John explains that Bluebox notified Google about the exploit in February, and points out that the company hasn’t patched it yet because the Android ecosystem is simply too large and too fragmented.

The signature vulnerability affects some 900 million Android devices worldwide, including phones and tablets from dozens of manufacturers. To complicate matters further, low- and mid-range handsets tend to feature older versions of Google’s mobile operating system. For these reasons and others, an all-inclusive update is out of the question. Device-specific patches are more practical, John notes, but only a handful of models have been updated to date.

Users who own unpatched devices should avoid downloading apps from third party sites until a fix or a new version of Android is available.

Check out the video below for the full interview.

 


A message from John Furrier, co-founder of SiliconANGLE:

Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.

  • 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more
  • 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network.
About SiliconANGLE Media
SiliconANGLE Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI.

Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.