{"id":12929,"date":"2018-07-27T12:10:09","date_gmt":"2018-07-27T20:10:09","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2018\/07\/27\/news-6696\/"},"modified":"2018-07-27T12:10:09","modified_gmt":"2018-07-27T20:10:09","slug":"news-6696","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2018\/07\/27\/news-6696\/","title":{"rendered":"New Android P includes several security improvements"},"content":{"rendered":"<p><strong>Credit to Author: Gleb Malygin| Date: Fri, 27 Jul 2018 19:12:28 +0000<\/strong><\/p>\n<p>According to the Android developer\u00a0<a href=\"https:\/\/developer.android.com\/preview\/overview\" target=\"_blank\" rel=\"noopener\">Program Overview,<\/a> the next major version of Android, Android 9.0 or P, is set to arrive soon. Their plans show a final release within the next three months (Q3 2018).<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"24878\" data-permalink=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/07\/mobile-menace-monday-android-p-security-improvements\/attachment\/timeline2x\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/07\/timeline@2x.png\" data-orig-size=\"1264,239\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"timeline@2x\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/07\/timeline@2x-300x57.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/07\/timeline@2x-600x113.png\" class=\"wp-image-24878 aligncenter\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/07\/timeline@2x-600x113.png\" alt=\"\" width=\"669\" height=\"126\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/07\/timeline@2x-600x113.png 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/07\/timeline@2x-300x57.png 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/07\/timeline@2x.png 1264w\" sizes=\"auto, (max-width: 669px) 100vw, 669px\" \/><\/p>\n<p>The end of the Android P beta program is approaching, with the first release candidate built and released in July. As a security company, we simply can&#8217;t help but take a close look at what kind of security updates will be included in Android&#8217;s newest version.<\/p>\n<p>We are not going to write about new <a href=\"https:\/\/developer.android.com\/preview\/features\" target=\"_blank\" rel=\"noopener\">features<\/a>\u00a0of Android P, but instead will focus our attention on security improvements. Android P introduces a number of updates that enhance the security of your apps and the devices that run them.<\/p>\n<h3>Improved fingerprint authentication<\/h3>\n<p>For our own safety, most devices (and many apps) have an authentication mechanism. The new Android P OS provides improved <a href=\"https:\/\/blog.malwarebytes.com\/101\/2018\/04\/securing-financial-data-of-the-future-behavioral-biometrics-explained\/\" target=\"_blank\" rel=\"noopener\">biometrics-based<\/a> authentication. In Android 8.1, there were\u00a0<a href=\"https:\/\/source.android.com\/security\/biometric\/\" target=\"_blank\" rel=\"noopener\">two new metrics<\/a>\u00a0that helped its biometric system repel attacks: Spoof Accept Rate (SAR) and Imposter Accept Rate (IAR). Along with a new model that splits biometric security into weak and strong, biometric authentication becomes more reliable and trustworthy in Android P.<\/p>\n<p>Android P also promises to deliver a standardized look, feel, and placement for the dialog that requests a fingerprint. This increases user&#8217;s confidence that they are interacting with a trusted source. App developers can trigger the new system fingerprint dialog using a new <a href=\"https:\/\/developer.android.com\/reference\/android\/hardware\/biometrics\/BiometricPrompt\" target=\"_blank\" rel=\"noopener\">BiometricPrompt API<\/a>, and it&#8217;s recommended to switch over to the new system dialog as soon as possible. The platform itself selects an appropriate biometric to authenticate with; thus developers don\u2019t need to implement this logic by themselves.<\/p>\n<p>Biometric authentication mechanisms are becoming increasingly popular and they have a lot of potential, but only if designed securely, measured accurately, and implemented correctly.<\/p>\n<h3>Signature Scheme v3<\/h3>\n<p>Android P pushes support for APK Signature Scheme v3. The major difference from v2 is key rotation support. Key rotation will be useful for developers, as this scheme has ApkSignerLineage included. As the <a href=\"https:\/\/android-review.googlesource.com\/c\/platform\/tools\/apksig\/+\/589594\/\" target=\"_blank\" rel=\"noopener\">review committee<\/a> states:<\/p>\n<blockquote>\n<p><em>\u201cThe signer lineage contains a history of signing certificates with each ancestor attesting to the validity of its descendant. Each additional descendant represents a new identity that can sign an APK. In this way, the lineage contains a proof of rotation by which the APK containing it can demonstrate, to other parties, its ability to be trusted with its current signing certificate, as though it were signed by one of its older ones. Each signing certificate also maintains flags which describe how the APK itself would like to trust the old certificates, if at all, when encountered.\u201d<\/em><\/p>\n<\/blockquote>\n<p>This gives you an opportunity to sign with a new certificate easily. You simply link the APK files to the ones with which they are now signed.<\/p>\n<p>Although Scheme v3 turns on by default, note that you can still use an old signing certificate.<\/p>\n<h3>HTTP Secure (<em>HTTPS<\/em>) by default<\/h3>\n<p>Nowadays, many apps are still transmitting users\u2019 information unencrypted, making personal data vulnerable to hackers. People bothered by potential for breach or invasion of privacy can feel more secure knowing their transmissions in Android P will be secure by default.<\/p>\n<p>In Android P, third-party developers will have to enable HTTPS (It was optional in Android 8.0) for their apps. However, they can still ignore the advice and specify certain domains that will deliver unencrypted traffic.<\/p>\n<h3>Protected confirmation<\/h3>\n<p>A protected confirmation API exists in all devices launched with Android P. Using this API, apps can use the\u00a0<a href=\"https:\/\/developer.android.com\/reference\/android\/security\/ConfirmationPrompt.html\" target=\"_blank\" rel=\"noopener\">ConfirmationPrompt<\/a>\u00a0class to display confirmation prompts to the user, asking them to approve a short statement. This statement allows the app to confirm that the user would like to complete a sensitive transaction, such as making a bill payment.<\/p>\n<p>Right after the statement acceptance, your app receives a cryptographic signature, protected by a keyed-hash message authentication code (HMAC). The signature is produced by the trusted execution environment (TEE). This protects the display of the confirmation dialog, as well as user input. The signature indicates, with high confidence, that the user has seen the statement and has agreed to it.<\/p>\n<h3>Hardware security module<\/h3>\n<p>Here\u2019s an additional update that benefits everyone: Devices with Android P will be supporting a StrongBox Keymaster. The module contains its own CPU, secure storage, and a true random number generator. It also protects against package tampering and unauthorized sideloading of apps.<\/p>\n<p>In order to support StrongBox implementations, Android P uses subset of algorithms and key sizes, such as:<\/p>\n<ul>\n<li>RSA 2048<\/li>\n<li>AES 128 and 256<\/li>\n<li>ECDSA P-256<\/li>\n<li>HMAC-SHA256 (supports key sizes between 8 bytes and 64 bytes, inclusive)<\/li>\n<li>Triple DES 168<\/li>\n<\/ul>\n<h3>Peripherals background policy<\/h3>\n<p>With Android P, apps will not be able to access your smartphone\u2019s microphone, camera, or sensors. Users get a notification when apps attempt to access these in the background. On attempting, the microphone will report empty audio, cameras will disconnect (causing an error if the app tries to use them), and all sensors will stop reporting events.<\/p>\n<h3>Backup data encryption update<\/h3>\n<p>It\u2019s not a secret that Android backs up data from your device. Users can then restore data after signing into their Google account from another device. Starting with Android P, it&#8217;ll start using a\u00a0<em>client-side<\/em>\u00a0secret method for its encryption. This means encryption will be done locally on the device, whereas before, a backup of your device was encrypted directly on the server.<\/p>\n<p>Because of this new privacy measure, users will need the device&#8217;s PIN, pattern, or password to restore data from the backups made by their device.<\/p>\n<h3>Wrapping things up<\/h3>\n<p>All these improvements mean only one thing: It&#8217;ll be significantly harder for criminals to access your data when they shouldn&#8217;t be able to. With the massive <a href=\"https:\/\/blog.malwarebytes.com\/101\/2018\/03\/the-data-breach-epidemic-no-info-is-safe\/\" target=\"_blank\" rel=\"noopener\">amounts of breaches<\/a> over the last two years, this should come as a relief for consumers, who simply want to use their phones without fear of privacy being compromised.<\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/07\/mobile-menace-monday-android-p-security-improvements\/\">New Android P includes several security improvements<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/07\/mobile-menace-monday-android-p-security-improvements\/\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: Gleb Malygin| Date: Fri, 27 Jul 2018 19:12:28 +0000<\/strong><\/p>\n<table cellpadding='10'>\n<tr>\n<td valign='top' align='center'><a href='https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/07\/mobile-menace-monday-android-p-security-improvements\/' title='New Android P includes several security improvements'><img src='https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/07\/Untitledt4-1.png' border='0'  width='300px'  \/><\/a><\/td>\n<\/tr>\n<tr>\n<td valign='top' align='left'>With its release around the corner, we take a close look at the Android P security improvements and how the newest version of Android will better protect the privacy and data of its users.<\/p>\n<p>Categories: <\/p>\n<ul class=\"post-categories\">\n<li><a href=\"https:\/\/blog.malwarebytes.com\/category\/cybercrime\/\" rel=\"category tag\">Cybercrime<\/a><\/li>\n<li><a href=\"https:\/\/blog.malwarebytes.com\/category\/cybercrime\/mobile\/\" rel=\"category tag\">Mobile<\/a><\/li>\n<\/ul>\n<p>Tags: <a href=\"https:\/\/blog.malwarebytes.com\/tag\/android\/\" rel=\"tag\">Android<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/android-p\/\" rel=\"tag\">Android P<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/google\/\" rel=\"tag\">Google<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/mobile\/\" rel=\"tag\">Mobile<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/privacy\/\" rel=\"tag\">privacy<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/security\/\" rel=\"tag\">security<\/a><\/p>\n<table width='100%'>\n<tr>\n<td align=right>\n<p><b>(<a href='https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/07\/mobile-menace-monday-android-p-security-improvements\/' title='New Android P includes several security improvements'>Read more&#8230;<\/a>)<\/b><\/p>\n<\/td>\n<\/tr>\n<\/table>\n<\/td>\n<\/tr>\n<\/table>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/07\/mobile-menace-monday-android-p-security-improvements\/\">New Android P includes several security improvements<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[10462,19084,4503,1670,10554,5897,714],"class_list":["post-12929","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-android","tag-android-p","tag-cybercrime","tag-google","tag-mobile","tag-privacy","tag-security"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/12929","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=12929"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/12929\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=12929"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=12929"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=12929"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}