How a few legitimate app developers threaten the entire Android userbase (Ars Technica)
How a few legitimate app developers threaten the entire Android userbase (Ars Technica)
Posted Oct 18, 2015 23:04 UTC (Sun) by zblaxell (subscriber, #26385)In reply to: How a few legitimate app developers threaten the entire Android userbase (Ars Technica) by josh
Parent article: How a few legitimate app developers threaten the entire Android userbase (Ars Technica)
It allows the malware developers to freeload. It's expensive to weaponize other people's bugs. It's much cheaper to extract an existing battle-tested exploit from a demonstrably successful product. Ordinary exploit PoC code doesn't get peer review, updates and maintenance like these tools do.
It's not just saving just time and money, either. Using a popular published exploit tool cuts down on identifiable traits that are often useful to forensic investigators. The black hats win twice here.
The tools wouldn't exist at all if vendors didn't insist on not providing legitimate access to the device firmware in the first place.
Posted Oct 19, 2015 2:34 UTC (Mon)
by dlang (guest, #313)
[Link] (3 responses)
I expect that they are creating these apps by watching the malware lists and piggy-backing on them rather than the other way around.
Posted Oct 19, 2015 4:11 UTC (Mon)
by zblaxell (subscriber, #26385)
[Link] (2 responses)
Posted Oct 19, 2015 5:18 UTC (Mon)
by dlang (guest, #313)
[Link] (1 responses)
I always question people who claim that any collection of exploits contains a bunch of new exploits never seen before.
Posted Oct 19, 2015 6:44 UTC (Mon)
by zblaxell (subscriber, #26385)
[Link]
That's still a net advantage for black hats even if the total number of theoretically available vulnerabilities remains constant.
How a few legitimate app developers threaten the entire Android userbase (Ars Technica)
How a few legitimate app developers threaten the entire Android userbase (Ars Technica)
How a few legitimate app developers threaten the entire Android userbase (Ars Technica)
How a few legitimate app developers threaten the entire Android userbase (Ars Technica)
