Mobile
6/19/2014
02:10 PM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

Google Play Apps Expose Users To Attack

Researchers discover thousands of Android app developers store secret keys in their apps.

A homegrown crawler built by researchers at Columbia University found that thousands of Android app developers in Google Play store their secret keys in their app software -- including developers designated by Google Play as "Top Developers."

The researchers' so-called PlayDrone tool slipped past Google Play security to download more than 1.1 million Android apps and decompile some 880,000 free apps in order to test the security of the store and its apps.

"Google Play has more than one million apps and over 50 billion app downloads, but no one reviews what gets put into Google Play -- anyone can get a $25 account and upload whatever they want. Very little is known about what’s there at an aggregate level," says Jason Nieh, professor of computer science at Columbia Engineering and a member of the university's Institute for Data Sciences and Engineering’s Cybersecurity Center. "Given the huge popularity of Google Play and the potential risks to millions of users, we thought it was important to take a close look at Google Play content."

PlayDrone provided other insight into the Google Play store as well, including a performance issue and the fact that about one-fourth of all free apps there are duplicates.

But the biggest finding was that thousands of secret authentication keys sit in apps in the store, which could be used by attackers to steal data or resources from Amazon and Facebook, for example. "We’ve been working closely with Google, Amazon, Facebook, and other service providers to identify and notify customers at risk, and make the Google Play store a safer place," says Columbia PhD candidate Nicolas Viennot, who along with Nieh presented a paper on the findings this week. "Google is now using our techniques to proactively scan apps for these problems to prevent this from happening again in the future."

Google is currently notifying app developers about the findings, urging them to remove the secret keys.

Security experts say PlayDrone exposed an embarrassing lack of vetting by Google of the Google Play store. "PlayDrone is interesting on many levels. It's academics using hacking for good and is completely embarrassing one of the world's biggest tech giants in the process. Not to mention that they basically showed the 'security by obscurity' approach so many app developers were taking," says Jonathan Sander, strategy and research officer with StealthBits Technologies.

"What PlayDrone has exposed is that many app developers left their secret keys on the equivalent of a post note stuck to the monitor because they thought their office door was locked. Using that key, an attacker can log into their system, steal data that's there (including data about anyone who has downloaded that app), and even rig systems in that virtual store to do more harm or syphon off more data," Sander tells us. "I'm sure stuffing those secret keys into the apps made things easier for the developers to get their apps out just a bit faster to gain an edge."

According to data from SafeNet, 74% of organizations store crypto keys in software. "This is the IT security equivalent of leaving house keys under the dormat," says Prakash Panjwani, president and CEO of SafeNet.

The Columbia University paper is available here for download.

Kelly Jackson Higgins is Executive Editor at DarkReading.com. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
mjordan081
50%
50%
mjordan081,
User Rank: Apprentice
6/21/2014 | 8:47:34 AM
Different than Apple?
I see some posts on here comparing this to Apple. Is there evidence somewhere that Apple vets their own store similarly? We know they vet their applications for content violations but know very little about their security vetting including inclusion of crypto keys within app code. Are we getting into a false sense of security based on assumption, or do we have verification about a similar process at Apple? Otherwise it would seem Google is taking the lead in security at this point if they're adopting this process.
Christian Bryant
100%
0%
Christian Bryant,
User Rank: Ninja
6/19/2014 | 6:21:58 PM
Kudos to PlayDrone
I appreciate what the PlayDrone authors have done here.  The paper is excellent as a case study of not just the PlayDrone development, but also in terms of how one should go about documenting such work.  While we all knew the Google Play model and other stores that follow it is flawed from a configuration management/build/release and security perspective, PlayDrone has the potential to be acquired by Google as a security testing tool to identify risk and set up audits against future application releases.  Kudos.
Kelly Jackson Higgins
50%
50%
Kelly Jackson Higgins,
User Rank: Strategist
6/19/2014 | 6:09:48 PM
Re: Next up...
So true, @Randy. It's long overdue for Google to raise the bar to Apple's standard for the app store. 
Randy Naramore
50%
50%
Randy Naramore,
User Rank: Ninja
6/19/2014 | 3:51:02 PM
Re: Next up...
Google apps are not as scrutinized as apple apps, maybe this will be a hint that this needs to change. 
Marilyn Cohodas
50%
50%
Marilyn Cohodas,
User Rank: Strategist
6/19/2014 | 3:46:39 PM
Re: Next up...
Egg on Google's face to be sure, but at least they are notifying app developers about the findings and "urging them" to remove the secret keys. I hope Google will be forthcoming about which developers have complied with their request and which have not. 
Zimdog
50%
50%
Zimdog,
User Rank: Apprentice
6/19/2014 | 3:27:05 PM
Next up...
...google chrome extensions.  If Google has this problem in apps uploaded into the Play Store, you can bet there are a ton of malicious chrome extensions out there as well.  These guys need to come up with a crawler that will examine those.  Put a little more egg on Google's face...
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Five Emerging Security Threats - And What You Can Learn From Them
At Black Hat USA, researchers unveiled some nasty vulnerabilities. Is your organization ready?
Flash Poll
Dark Reading Strategic Security Report: The Impact of Enterprise Data Breaches
Dark Reading Strategic Security Report: The Impact of Enterprise Data Breaches
Social engineering, ransomware, and other sophisticated exploits are leading to new IT security compromises every day. Dark Reading's 2016 Strategic Security Survey polled 300 IT and security professionals to get information on breach incidents, the fallout they caused, and how recent events are shaping preparations for inevitable attacks in the coming year. Download this report to get a look at data from the survey and to find out what a breach might mean for your organization.
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-7445
Published: 2015-10-15
The Direct Rendering Manager (DRM) subsystem in the Linux kernel through 4.x mishandles requests for Graphics Execution Manager (GEM) objects, which allows context-dependent attackers to cause a denial of service (memory consumption) via an application that processes graphics data, as demonstrated b...

CVE-2015-4948
Published: 2015-10-15
netstat in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x, when a fibre channel adapter is used, allows local users to gain privileges via unspecified vectors.

CVE-2015-5660
Published: 2015-10-15
Cross-site request forgery (CSRF) vulnerability in eXtplorer before 2.1.8 allows remote attackers to hijack the authentication of arbitrary users for requests that execute PHP code.

CVE-2015-6003
Published: 2015-10-15
Directory traversal vulnerability in QNAP QTS before 4.1.4 build 0910 and 4.2.x before 4.2.0 RC2 build 0910, when AFP is enabled, allows remote attackers to read or write to arbitrary files by leveraging access to an OS X (1) user or (2) guest account.

CVE-2015-6333
Published: 2015-10-15
Cisco Application Policy Infrastructure Controller (APIC) 1.1j allows local users to gain privileges via vectors involving addition of an SSH key, aka Bug ID CSCuw46076.

Dark Reading Radio
Archived Dark Reading Radio
Security researchers are finding that there's a growing market for the vulnerabilities they discover and persistent conundrum as to the right way to disclose them. Dark Reading editors will speak to experts -- Veracode CTO and co-founder Chris Wysopal and HackerOne co-founder and CTO Alex Rice -- about bug bounties and the expanding market for zero-day security vulnerabilities.