Pulser_G2 · May 26, 2013 at 09:00 am

Sky UK Apps Compromised on Play Store, Uninstall Them!

sky_apps_playstore_hacked

Today is Sunday, 26th May, and across the world, many people have woken up following a leisurely lie-in to the small notification of an updated app being available. Nothing unusual there, or so you’d think.

The only difference is that today, some of these app updates may well have been malicious updates, pushed to some of the Sky UK official Android apps. As reported by PC Pro and Android Police; the  Sky Go, Sky+, SKY WiFi, and Sky News apps all appeared to be targeted in the attacks that involved updates being pushed to the Google Play Store for these applications.

Fortunately, the compromise was more than a little obvious, with the app listing being defaced, including the header banner, description, and screenshots of the Play Store listing, which have since been removed (Thanks to AndroidPolice for the image).

Obviously, the best advice here is to uninstall any Sky apps that you have installed. This ought to alleviate most risk (unless these apps contained an unknown, zero-day exploit that permitted them to break beyond the application container). This is highly unlikely though, and uninstalling the app should be sufficient a precaution to take.

The question here is: Would anyone have noticed this attack had the Play Store listing not been visibly changed? Had the listing not been defaced, would anyone be aware of this surreptitious update which had been installed? I believe nobody would be aware, and everyone would be sitting, none-the-wiser, with a ticking time-bomb on their phones and tablets. These are not small-time apps, with the Sky Go app having between 1 and 5 million users, so the potential for building a silent bot-net of devices is not insignificant.

Later today, we’ll take a dive in and look at the implications of this attack, and what it means for app developers, and users alike. In the meantime, stay safe, and uninstall any Sky apps on your phone. Doing this, you should be reasonably protected against any further risks of this compromise.

Finally, one last piece of advice for Sky or anyone else affected by a similar security incident in the future: When you do announce the breach via Twitter, please do so and link to something verifiable on your own website that details it (in light of recent Twitter accounts being hacked), rather than making a grammatically incorrect and rushed tweet that raises the question of if your Twitter account is compromised:

skysecurityfail

 [Source: AndroidPolice; PC Pro]


_________
Want something on the XDA Portal? Send us a tip!
TAGS:

Pulser_G2

Pulser_G2 is an editor on XDA-Developers, the largest community for Android users. View posts and articles below.

Developer Admin at xda-developers, interested in everything in mobile and security. A developer and engineer, who would re-write everything in C or Assembler if the time was there.
Mathew Brack · Mar 6, 2015 at 01:24 pm · no comments

Kirin: A Processor the Western World Should Look Out For

Yesterday, we discussed the second part of our tech giants coming to the west series with Huawei. What people may not know, however, is that Huawei owns a company by the name of HiSilicon. Hisilicon's processor department may not be the most popular in the west but their technology is impressive, with year on year improvements being easily seen. In the coming years, manufacturers such as Qualcomm may have to face the fact that there are other companies just as able...

XDA NEWS
Emil Kako · Mar 6, 2015 at 12:00 pm · no comments

Best Bang-for-the-Buck Phone You Can Get Today?

There are many great Android handsets on the market today that are much cheaper than the flagships from the major players like Samsung and HTC. The OnePlus One and Nexus 5 are two great examples of high-end phones being offered at prices much cheaper than competitors. But there are phones in the mid-range that may offer even more bang for your buck. Let us know which smartphone deal you think has the best value.

DISCUSS
Mathew Brack · Mar 6, 2015 at 11:27 am · 1 comment

TapDeck Beta: Smart Wallpaper Discovery

TapDeck which has just entered beta, is a smart wallpaper app that allows you to change to a random wallpaper by simply double tapping your screen. After selecting images you like from a selection, your wallpapers will be chosen based on similar images from Flickr, Imgur, Reddit and Wikipedia. If you see one you like, simply swipe up and you will see information relevant to the image. After spending a day with this app it is clear that it is still...

XDA NEWS
Share This