Folks, this is bad news. Very, very bad. Hackers and/or malicious insiders have leaked the platform certificates of several vendors. These are used to sign system apps on Android builds, including the "android" app itself. These certs are being used to sign malicious Android apps!

bugs.chromium.org/p/apvi/issue

@MishaalRahman I only have one question. I am not in tech what does this mean to me? Answer like I am a little child with fork in one hand and outlet in reach. Should I worry? OK that's 2 I can't count.

Follow

@Dandydandy @MishaalRahman What that means to you: Don't trust apps if you are not sure where it comes from. Some apps may even seem legitimate (even to a computer, as there is a digital sign on it that tells them so). Unfortunately, these signs are like keys to enter a save box for the data of an app. That makes sense, as some apps should be able to share data. These malicious apps can access these private boxes. So, no need to worry more, just follow the general safety measures.

Sign in to participate in the conversation
Librem Social

Librem Social is an opt-in public network. Messages are shared under Creative Commons BY-SA 4.0 license terms. Policy.

Stay safe. Please abide by our code of conduct.

(Source code)

image/svg+xml Librem Chat image/svg+xml