Android app flaw allows 'easy piracy'
By Tom Brewster,
Most apps in the Android Market can have their licensing protection stripped away, making them easy targets for pirates, it has been claimed.
In a report from the Android Police, the author claimed minor changes could easily be made to an app’s code, meaning it could be copied and then reconfigured to help it pass Google’s Licence Verification Library (LVL).
By this time, of course, it will not longer be an official app but a pirated one.
Most Android apps are written in Java, the author explained, and these apps are compiled into byte-code. There are numerous software suites that can easily disassemble bytecode, which is in itself “fairly readable”, leaving it more open for tampering.
Hackers can then reassemble the code of an app and make alterations to bypass the LVL verification process, therefore placing a pirated app on the marketplace.
The author called for improved solutions for preventing pirated apps finding their way onto the Android Market, such as “ways to confirm an application was installed through official means.”
Tim Bray, from the Android developers team, responded to the Android Police findings in a blog post defending LVL.
“Android Market is already a responsive, low-friction, safe way for developer to get their products to users,” Bray said.
“The licensing server makes it safer and we will continue to improve it.”
Bray also pointed out developers can write custom authentication checks for each of their applications.
Furthermore, all attacks on apps seen by the official Android developer team had so far been on apps which did not feature obfuscated code, providing a further layer of protection, he said.
Bray added: “100 per cent piracy protection is never possible in any system that runs third-party code, but the licensing server, when correctly implemented and customised for your app, is designed to dramatically increase the cost and difficulty of pirating.”
You may also like...
Sponsored Links
advertisement
You may also like...
Latest Security Analysis & Insight
Do British police get cyber security?
Davey Winder listens to telephone conversations between the FBI and the Metropolitan Police, courtesy of Anonymous, and isn't impressed.
- Who to trust after the VeriSign hack?
- Striving to solve the security skills crisis
- Would you employ a hacker or malware writer?
- Q&A: Raj Samani, CTO McAfee
- Erase and rewind: the EU and privacy
- My email address is [CENSORED]
- Is there such a thing as a secure tablet?
- 2011: The year in news
- BYOD: Old or new, good or bad?
Latest Security Reviews
Check Point 2210 Appliance review
Rating: ![]()
advertisement
Most popular
- Ubuntu vs. Windows 7 on the business desktop
- York researchers heat storage to speed up data
- BlackBerry Bold 9790 review
- OneNote hits Google?s Android
- O2 trials Olympic-scale remote working
- Will someone rid me of these troublesome Macs?
- Lenovo beats expectations again
- Who to trust after the VeriSign hack?
- Google to promise fairness after Motorola buy
- Report: Google cloud storage coming soon
Latest News Videos in Security
IT PRO Podcast: Are UK data protection laws flawed?
We bring in two experts to talk about the problems with UK data protection law and the way it is managed.
Register for IT PRO
You'll get exclusive member benefits including free whitepapers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.





