Mobile
6/19/2014
02:10 PM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

Google Play Apps Expose Users To Attack

Researchers discover thousands of Android app developers store secret keys in their apps.

A homegrown crawler built by researchers at Columbia University found that thousands of Android app developers in Google Play store their secret keys in their app software -- including developers designated by Google Play as "Top Developers."

The researchers' so-called PlayDrone tool slipped past Google Play security to download more than 1.1 million Android apps and decompile some 880,000 free apps in order to test the security of the store and its apps.

"Google Play has more than one million apps and over 50 billion app downloads, but no one reviews what gets put into Google Play -- anyone can get a $25 account and upload whatever they want. Very little is known about what’s there at an aggregate level," says Jason Nieh, professor of computer science at Columbia Engineering and a member of the university's Institute for Data Sciences and Engineering’s Cybersecurity Center. "Given the huge popularity of Google Play and the potential risks to millions of users, we thought it was important to take a close look at Google Play content."

PlayDrone provided other insight into the Google Play store as well, including a performance issue and the fact that about one-fourth of all free apps there are duplicates.

But the biggest finding was that thousands of secret authentication keys sit in apps in the store, which could be used by attackers to steal data or resources from Amazon and Facebook, for example. "We’ve been working closely with Google, Amazon, Facebook, and other service providers to identify and notify customers at risk, and make the Google Play store a safer place," says Columbia PhD candidate Nicolas Viennot, who along with Nieh presented a paper on the findings this week. "Google is now using our techniques to proactively scan apps for these problems to prevent this from happening again in the future."

Google is currently notifying app developers about the findings, urging them to remove the secret keys.

Security experts say PlayDrone exposed an embarrassing lack of vetting by Google of the Google Play store. "PlayDrone is interesting on many levels. It's academics using hacking for good and is completely embarrassing one of the world's biggest tech giants in the process. Not to mention that they basically showed the 'security by obscurity' approach so many app developers were taking," says Jonathan Sander, strategy and research officer with StealthBits Technologies.

"What PlayDrone has exposed is that many app developers left their secret keys on the equivalent of a post note stuck to the monitor because they thought their office door was locked. Using that key, an attacker can log into their system, steal data that's there (including data about anyone who has downloaded that app), and even rig systems in that virtual store to do more harm or syphon off more data," Sander tells us. "I'm sure stuffing those secret keys into the apps made things easier for the developers to get their apps out just a bit faster to gain an edge."

According to data from SafeNet, 74% of organizations store crypto keys in software. "This is the IT security equivalent of leaving house keys under the dormat," says Prakash Panjwani, president and CEO of SafeNet.

The Columbia University paper is available here for download.

Kelly Jackson Higgins is Executive Editor at DarkReading.com. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
mjordan081
50%
50%
mjordan081,
User Rank: Apprentice
6/21/2014 | 8:47:34 AM
Different than Apple?
I see some posts on here comparing this to Apple. Is there evidence somewhere that Apple vets their own store similarly? We know they vet their applications for content violations but know very little about their security vetting including inclusion of crypto keys within app code. Are we getting into a false sense of security based on assumption, or do we have verification about a similar process at Apple? Otherwise it would seem Google is taking the lead in security at this point if they're adopting this process.
Christian Bryant
100%
0%
Christian Bryant,
User Rank: Ninja
6/19/2014 | 6:21:58 PM
Kudos to PlayDrone
I appreciate what the PlayDrone authors have done here.  The paper is excellent as a case study of not just the PlayDrone development, but also in terms of how one should go about documenting such work.  While we all knew the Google Play model and other stores that follow it is flawed from a configuration management/build/release and security perspective, PlayDrone has the potential to be acquired by Google as a security testing tool to identify risk and set up audits against future application releases.  Kudos.
Kelly Jackson Higgins
50%
50%
Kelly Jackson Higgins,
User Rank: Strategist
6/19/2014 | 6:09:48 PM
Re: Next up...
So true, @Randy. It's long overdue for Google to raise the bar to Apple's standard for the app store. 
Randy Naramore
50%
50%
Randy Naramore,
User Rank: Ninja
6/19/2014 | 3:51:02 PM
Re: Next up...
Google apps are not as scrutinized as apple apps, maybe this will be a hint that this needs to change. 
Marilyn Cohodas
50%
50%
Marilyn Cohodas,
User Rank: Strategist
6/19/2014 | 3:46:39 PM
Re: Next up...
Egg on Google's face to be sure, but at least they are notifying app developers about the findings and "urging them" to remove the secret keys. I hope Google will be forthcoming about which developers have complied with their request and which have not. 
Zimdog
50%
50%
Zimdog,
User Rank: Apprentice
6/19/2014 | 3:27:05 PM
Next up...
...google chrome extensions.  If Google has this problem in apps uploaded into the Play Store, you can bet there are a ton of malicious chrome extensions out there as well.  These guys need to come up with a crawler that will examine those.  Put a little more egg on Google's face...
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: You should see what I wear on my work from home days!
Current Issue
The Changing Face of Identity Management
Mobility and cloud services are altering the concept of user identity. Here are some ways to keep up.
Flash Poll
Containing Corporate Data on Mobile Devices
Containing Corporate Data on Mobile Devices
If you’re still focused on securing endpoints, you’ve got your work cut out for you. WiFi network provider iPass surveyed 1,600 mobile workers and found that the average US employee carries three devices -- a smartphone, a computer, and a tablet or e-reader -- with more than 80% of them doing work on personal devices.
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-7445
Published: 2015-10-15
The Direct Rendering Manager (DRM) subsystem in the Linux kernel through 4.x mishandles requests for Graphics Execution Manager (GEM) objects, which allows context-dependent attackers to cause a denial of service (memory consumption) via an application that processes graphics data, as demonstrated b...

CVE-2015-4948
Published: 2015-10-15
netstat in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x, when a fibre channel adapter is used, allows local users to gain privileges via unspecified vectors.

CVE-2015-5660
Published: 2015-10-15
Cross-site request forgery (CSRF) vulnerability in eXtplorer before 2.1.8 allows remote attackers to hijack the authentication of arbitrary users for requests that execute PHP code.

CVE-2015-6003
Published: 2015-10-15
Directory traversal vulnerability in QNAP QTS before 4.1.4 build 0910 and 4.2.x before 4.2.0 RC2 build 0910, when AFP is enabled, allows remote attackers to read or write to arbitrary files by leveraging access to an OS X (1) user or (2) guest account.

CVE-2015-6333
Published: 2015-10-15
Cisco Application Policy Infrastructure Controller (APIC) 1.1j allows local users to gain privileges via vectors involving addition of an SSH key, aka Bug ID CSCuw46076.

Dark Reading Radio
Archived Dark Reading Radio

The cybersecurity profession struggles to retain women (figures range from 10 to 20 percent). It's particularly worrisome for an industry with a rapidly growing number of vacant positions.

So why does the shortage of women continue to be worse in security than in other IT sectors? How can men in infosec be better allies for women; and how can women be better allies for one another? What is the industry doing to fix the problem -- what's working, and what isn't?

Is this really a problem at all? Are the low numbers simply an indication that women do not want to be in cybersecurity, and is it possible that more women will never want to be in cybersecurity? How many women would we need to see in the industry to declare success?

Join Dark Reading senior editor Sara Peters and guests Angela Knox of Cloudmark, Barrett Sellers of Arbor Networks, Regina Wallace-Jones of Facebook, Steve Christey Coley of MITRE, and Chris Roosenraad of M3AAWG on Wednesday, July 13 at 1 p.m. Eastern Time to discuss all this and more.