An attacker who can steal these private keys can get malware uploaded to the Google Play store. Getting malware uploaded to Google Play is way easier.
And if Samsung's private key is stolen, I would certainly not be inclined to trust their Galaxy Store.
Now is a great time to go through your phone & uninstall apps you don't use or don't trust -- especially bloatware from the compromised OEMs. If I understand other comments in this thread correctly, the stolen keys allow the thief to escalate privileges from "ability to issue an update for a random app you have installed" to "ability to root your device".
Android has a global user base of around 2.7 billion[0] and nearly 100,000 NEW apps are released on the platform every month[1]. Given these facts, it simply does not follow that a family of malicious apps with 1M downloads or an analysis of 1238 malicious apps demonstrates "Malware on the google Play store seems fairly common."
The working hypothesis (gathered from other comments here) is that the main vector of attack for this case may be restricted to the sideloading system-level components (not end-user apps).
It's the end of the world as we know it, and I feel fine.
>nearly 100,000 NEW apps are released on the platform every month[1]
Am I supposed to believe Google thoroughly vets all 100,000 of those apps?
My assumption is that any automated vetting system can be defeated by a serious attacker (the sort of attacker who can steal private keys). Just keep tweaking your malware until it gets past the filter.
>Given these facts, it simply does not follow that a family of malicious apps with 1M downloads or an analysis of 1238 malicious apps demonstrates "Malware on the google Play store seems fairly common."
Not sure 100K is the right denominator here -- how many of those 100K receive any attention at all by security researchers? The numbers I quoted appear to demonstrate that when security researchers look for this stuff, it isn't hard to find.
>The working hypothesis (gathered from other comments here) is that the main vector of attack for this case may be restricted to the sideloading system-level components (not end-user apps).
If 67% of unwanted app installs originate via the Play store, wouldn't it be most natural for attackers looking to exploit a stolen private key to take that most common route?
An attacker who can steal multiple private keys from large multinationals can also get inside the software supply chain for your favorite fart app.
>It's the end of the world as we know it, and I feel fine.
If you're writing software that people use, you have a special obligation to take security seriously. An attacker who gains root access to your phone could e.g. sniff passwords and steal 2FA codes, use them to log into Github/AWS, and do a ton of damage to people who are depending on you.
You missed my point about the number of new apps published per-month. I was not making any particular claims about how well they are each vetted, I was rather contrasting that to the "1238 malicious apps" you had referenced. Now, the perfect number of malicious apps in an official app store would certainly be zero, but sadly, we don't live in a perfect world.
What world do we live in, then? We live in a world where, even if 1238 new malicious apps were released _per month_, that would still represent fewer than 1% of all apps released. Yet, according to the report you mentioned, the 1238 malicious apps were published between 2016 to 2020. Rough math, then, gives us 1238 malicious apps out of 6M apps over that period. 0.02% of all apps. Not perfect, for sure. But I'm willing to live in that world. By the way, I'm not fixated on the 1238 number as if that's all the malware that existed duyring that time. But on the other hand, the writers of that report took their time and did the best they could to find as many malicous apps as possible for their research. So we have no evidence the true number was significantly higher.
>An attacker who gains root access to your phone could e.g. [do terrible things]
This is true, yet you still miss the point. If "malware on the Google Play store seems fairly common" as you claim, and malicious apps are therefore commonly ripping off passwords, 2FA codes, etc, where is the avalanche of tragic end-user stories we would be compelled to expect, by the laws of mathematics? 0.02% of the 2.7B Android users is still 55 MILLION end users. Yet, nothing near to 55M or 5M or even 50,000 end-users have had remotely catastrophic outcomes due to malicous apps hosted on the Google Play Store in any given sliding 5-year window (such as the one studied in the report).
Anyway, I've been generous with my words here since I sense you are sincere. But only a very few words are needed to reinforce my original point: Your quoted numbers do not support the assetion that malware is fairly common on the Google Play Store.
This article from Malwarebytes reported on a family of malicious apps with over 1M downloads: https://www.malwarebytes.com/blog/news/2022/11/malware-on-th...
This paper analyzed 1238 malicious apps grouped into 134 families: https://people.ece.ubc.ca/mjulia/publications/GooglePlayMalw...
An attacker who can steal these private keys can get malware uploaded to the Google Play store. Getting malware uploaded to Google Play is way easier.
And if Samsung's private key is stolen, I would certainly not be inclined to trust their Galaxy Store.
Now is a great time to go through your phone & uninstall apps you don't use or don't trust -- especially bloatware from the compromised OEMs. If I understand other comments in this thread correctly, the stolen keys allow the thief to escalate privileges from "ability to issue an update for a random app you have installed" to "ability to root your device".