Forgot your password?

typodupeerror
Google Android Security IT Technology

Researchers Beat Google's Bouncer 44

Posted by timothy
from the sneak-in-the-back-way dept.
An anonymous reader writes "When earlier this year Google introduced Bouncer — an automated app scanning service that analyzes apps by running them on Google's cloud infrastructure and simulating how they will run on an Android device — it shared practically nothing about how it operates, in the hopes of making malicious app developers' scramble for a while to discover how to bypass it. As it turned out, several months later security researchers Jon Oberheide and Charlie Miller discovered — among other things — just what kind of virtual environment Bouncer uses (the QEMU processor emulator) and that all requests coming from Google came from a specific IP block, and made an app that was instructed to behave as a legitimate one every time it detected this specific virtual environment. Now two more researchers have effectively proved that Bouncer can be rather easily fooled into considering a malicious app harmless."
This discussion has been archived. No new comments can be posted.

Researchers Beat Google's Bouncer

Comments Filter:
  • by Trepidity (597) <delirium-slashdot.hackish@org> on Friday July 27, 2012 @12:18PM (#40791867)

    It seems like they just found that the sandbox Google simulates the apps in is a little sloppy in its simulation (IP addresses are predictable), so it's easy to tell you're inside the sandbox. But they could fix that part pretty easily.

    Was hoping for something more halting-problem-esque, since it's really difficult to "scan an app for malware" in general.

  • by schitso (2541028) on Friday July 27, 2012 @12:21PM (#40791925)
    "Google was aware of and blessed the research, and has been apprised of its results so that it can make changes and better secure Google Play against malicious individuals."

    "A renowned security researcher who claims he discovered a flaw in iOS was kicked out of Apple's iOS Developers program."

    Just sayin'.
  • by crmarvin42 (652893) on Friday July 27, 2012 @12:33PM (#40792097)
    My impression was that they kicked him out for submitting the app to the store (for customers to purchase), not for finding the vulnerability. I know it's a bit of splitting hairs, but I suspect no penalty would have occured had he limited his actions to telling apple about the problem. Still think it was a bad response though.

    If Apple wants to seriously engage the security community there ought to be a way for the researchers to submit proof of concept apps to the app store to see if their current review process can catch them (obviously the reviewers would need to be blinded as to the identity of the submitter). They could improve their review process, catch security issues, AND avoid the negative press of booting a developer like this.
  • by mcgrew (92797) * on Friday July 27, 2012 @03:24PM (#40794679) Journal

    Please, STOP FEEDING THE FUCKING TROLLS!!! Ignore them For God's sake, don't quote them!!! Jesus, man, what the fuck is wrong with you? Anonymous troll is at -1 so you gave him a voice! Mods, please downmod every response to the troll, including mine but especially the parent's, who stupidly quoted the racist bullshit. Fucking trollbiters are often as bad as the fucking trolls.

Thufir's a Harkonnen now.

Working...