Android app flaw allows 'easy piracy'
By Tom Brewster,
Most apps in the Android Market can have their licensing protection stripped away, making them easy targets for pirates, it has been claimed.
In a report from the Android Police, the author claimed minor changes could easily be made to an app’s code, meaning it could be copied and then reconfigured to help it pass Google’s Licence Verification Library (LVL).
By this time, of course, it will not longer be an official app but a pirated one.
Most Android apps are written in Java, the author explained, and these apps are compiled into byte-code. There are numerous software suites that can easily disassemble bytecode, which is in itself “fairly readable”, leaving it more open for tampering.
Hackers can then reassemble the code of an app and make alterations to bypass the LVL verification process, therefore placing a pirated app on the marketplace.
The author called for improved solutions for preventing pirated apps finding their way onto the Android Market, such as “ways to confirm an application was installed through official means.”
Tim Bray, from the Android developers team, responded to the Android Police findings in a blog post defending LVL.
“Android Market is already a responsive, low-friction, safe way for developer to get their products to users,” Bray said.
“The licensing server makes it safer and we will continue to improve it.”
Bray also pointed out developers can write custom authentication checks for each of their applications.
Furthermore, all attacks on apps seen by the official Android developer team had so far been on apps which did not feature obfuscated code, providing a further layer of protection, he said.
Bray added: “100 per cent piracy protection is never possible in any system that runs third-party code, but the licensing server, when correctly implemented and customised for your app, is designed to dramatically increase the cost and difficulty of pirating.”
You may also like...
Sponsored Links
advertisement
You may also like...
Latest Security Analysis & Insight
What is your password worth?
Would you be tempted to sell off company passwords for a fee? If not, seems like you're in the minority, acccording to research.
- Macs under attack?
- Intel: security inside
- Are you spending too much on IT security?
- Does the government want to snoop on your data?
- Eurocrats versus the cyber criminals
- The truth about spam
- Google and privacy: What’s the problem?
- Q&A: Symantec’s CISO on the source code hack
- RSA: Back from the breach?
Latest Security Reviews
Check Point 2210 Appliance review
Rating: ![]()
advertisement
Most popular
- Yahoo CEO resigns after CV debacle
- Apple iPad 3 vs iPad 2 head-to-head review
- Macs under attack?
- HP to bring indestructible plastic displays and Memristor storage to market
- Fusion-IO share price soars on back of Dell merger rumours
- Android users warned of fake app store malware risk
- Dell PowerEdge R820 review
- Is BT the key to broadband Britain?
- What is your password worth?
- Police quiz UK teen over TeamPoison attacks
Latest News Videos in Security
IT PRO Podcast: Are UK data protection laws flawed?
We bring in two experts to talk about the problems with UK data protection law and the way it is managed.
Register for IT PRO
You'll get exclusive member benefits including free whitepapers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.




