LWN.net Logo

An Evaluation of the Application ("App") Verification Service in Android 4.2

NCSU Professor Xuxian Jiang has posted an assessment of the application verification service featured in the Android 4.2 release. "However, based on our evaluation results, we feel this service is still nascent and there exists room for improvement. Specifically, our study indicates that the app verification service mainly uses an app's SHA1 value and the package name to determine whether it is dangerous or potentially dangerous. This mechanism is fragile and can be easily bypassed. It is already known that attackers can change with ease the checksums of existing malware (e.g., by repackaging or mutating it)."
(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds