Bluebox scares me

Somewhere, someone is going to make this a thing. Only, it's not really a thing. So let's just get out in front of it here.

Bluebox — the group behind this "Master Key" scare — has an app that will tell you if the exploit is on your phone, or if it's been patched. Cool. But remember:

  1. We're really not all worried about this. Here's the long version of why we're not worried about it.
  2. It's an exploit that needs to be fixed, and it's being fixed.
  3. Google took care of things on the server side, in Google Play.
  4. Google is patching things in the code side and working with the manufacturers to get it pushed out.

What we don't like to see is all of those scary "Unable to scan app xxxxxx, it may be trying to evade the scanner" lines. As if the apps themselves — apps we've been using for years — are to blame. That's bullshit.

And a word of advice, folks: If you're going to try Bluebox's little scanner app here, make sure you download it directly from Google Play, so you know it's safe. It'd be bad if someone used the "Master Key" exploit to circulate a malware-laden version of the scanner app without breaking the signature.

Us? We're uninstalling this thing ASAP.

Bluebox Security Scanner attempts to scare the living shit out of you



My guess is that Play is patched, so anything downloaded through the Play app is fine. Sideloading is vulnerable because the signature check is part of the OS.

Too many applications are avoiding scan what does that mean? Is this a flaw in your application or the applications being scanned? This doesn't tell me if their bad or not. Which ultimately leaves me apprehensive on what to do. Do you think this offers me any sense of security? I think not!

Posted via Android Central App

Interesting that the only apps it was unable to scan on my N4 came from the play store. Incredibly accurately named article!

Posted via Android Central App

A-ha, the other shoe drops! I wondered if or when Bluebox[1] would try to capitalize on the flaw. Sounds like a full-speed, hard stop FACE PLANT that their "detection app" is so hysterical. Crapware, indeed.

[1] Google it if you're younger than 50 and dont know the reference. Back in the 70s ESQUIRE published a superb article about blue box hackers. Jobs and Woz were blueboxers IIRC.

Splattered for your amusement... via the AC App

Btw if you're offended by language, industrial strength sarcasm, and pejorative POV, DO NOT read THE REGISTER. So what if you miss out on great writing, "they're only words." :-\

Splattered for your amusement... via the AC App

