{"id":4296,"date":"2017-06-21T09:54:26","date_gmt":"2017-06-21T13:54:26","guid":{"rendered":"https:\/\/www.thesslstore.com\/blog\/?p=4296"},"modified":"2017-06-23T03:48:32","modified_gmt":"2017-06-23T07:48:32","slug":"samsung-abandons-s-suggest","status":"publish","type":"post","link":"https:\/\/www.thesslstore.com\/blog\/samsung-abandons-s-suggest\/","title":{"rendered":"Samsung Abandons \u201cS Suggest\u201d Creating Security Vulnerability for Millions"},"content":{"rendered":"<h2>Abandoned Software is a Security Risk That Manufactures Must Take Responsibility For<\/h2>\n<p>A researcher found that Samsung abandoned its \u201cS Suggest\u201d app which could have opened a security vulnerability for millions of users.<\/p>\n<p><a href=\"http:\/\/www.samsung.com\/in\/support\/skp\/faq\/839474\" rel=\"nofollow\">S Suggest<\/a> is an app and widget for Android that recommends other apps that Samsung had preinstalled on most of its phones \u2013 including flagship devices like the Galaxy S III \u2013 <a href=\"https:\/\/www.androidpit.com\/from-the-note-7-to-s-suggest-samsung-please-stop-making-mistakes\" rel=\"nofollow\">between 2012 and 2014<\/a>. After failing to gain popularity, Samsung shut down the service in 2014 and later let the ssuggest.com domain expire, too. The app communicates with that domain to download new content report data about the user\u2019s device.<span id=\"newline\"><\/span><\/p>\n<p>Anyone could notice that ssuggest.com was available, register it and begin serving malicious content or recording device data.<\/p>\n<p>Samsung gave a statement to <a href=\"https:\/\/motherboard.vice.com\/en_us\/article\/samsung-left-millions-vulnerable-to-hackers-because-it-forgot-to-renew-a-domain\" rel=\"nofollow\">Motherboard<\/a> denying that this posed a security risk, stating that controlling the S Suggest domain \u201cdoes not allow you to install malicious apps, it does not allow you to take control of users&#8217; phones.\u201d<\/p>\n<p>However the S Suggest app\u2019s <a href=\"https:\/\/www.appbrain.com\/app\/s-suggest\/com.sec.android.app.samsungapps\" rel=\"nofollow\">permissions contradict that statement<\/a>. The most dangerous of them was the ability to install apps and packages. It also had the ability to retrieve a list of the user\u2019s running apps, view their network and Wi-Fi connections, and delete other apps.<\/p>\n<p>There would have been plenty of other ways to use the ssuggest.com domain in harmful ways, too \u2013 such as replacing existing assets with tracking scripts or advertisements that could have been used to generate profit for criminal hackers.<\/p>\n<p>Samsung should have avoided this vulnerability by keeping ownership of the domain or updating the app to disconnect it from the site (though that would expose some users who don\u2019t update).<\/p>\n<p>Luckily Jo\u00e3o Gouveia, <a href=\"https:\/\/twitter.com\/jgouv\/status\/874296684993445888\" rel=\"nofollow\">the researcher who discovered the domain was available<\/a>, has registered the domain to prevent it from being misused. This practice is known as \u201csinkholing\u201d and refers to the act of discarded\/deleting traffic sent to that addresses. This is the same <a href=\"https:\/\/www.thesslstore.com\/blog\/wannacry-ransom-total\/\">technique used to defeat the \u201cWannaCry\u201d ransomware<\/a> which attacked millions of unpatched Windows devices last month.<\/p>\n<p>Gouveia recorded connections from more than 2.1 million unique devices in a 24 hour period \u2013 and those devices were frequently connecting to the ssuggest.com domain (a total of 620 million times).<\/p>\n<p>So while Samsung is finished with its S Suggest service, millions of users are still using phones that came with the app pre-installed.<\/p>\n<p>Thanks to Gouveia no harm has been done but this vulnerability highlights the role that manufacturers have in keeping devices secure.<\/p>\n<h2>Manufacturers\u2019 Responsibility To Support The Software They Force on Users<\/h2>\n<p>Android handset manufacturers often struggle to differentiate themselves from their competitors.<\/p>\n<p>Because Android is easy and affordable to license there are literally hundreds of choices that offer nearly identical features. Samsung, like many other major brands, creates additional (and often proprietary) features that can be unique selling points for its phones.<\/p>\n<p>This is mostly copycat software that tries to compete with \u2018big name\u2019 features on other phones like Apple\u2019s App Store or Google\u2019s \u201cOk Google\u201d voice commands.\u00a0 Brands like Samsung, LG, and HTC have all <a href=\"https:\/\/techcrunch.com\/2017\/06\/16\/samsungs-bixby-voice-assistant-is-finally-coming-to-the-u-s-but-only-as-a-preview\/\" rel=\"nofollow\">created similar functionality<\/a> which <a href=\"http:\/\/www.phonearena.com\/news\/Samsung-owners-do-you-ever-use-the-Galaxy-app-store_id95134\" rel=\"nofollow\">usually goes unnoticed<\/a>.<\/p>\n<p>In order to spur adoption these apps usually come pre-installed and may be turned on by default. Manufacturers may even replace Android\u2019s stock functionality with their own versions.<\/p>\n<p>Samsung has an entire \u201cS\u201d line of products, including both hardware and software \u2013 which S Suggest was part of.<\/p>\n<p>When they fail \u2013 as Samsung has with S Suggest \u2013 manufacturers are quick to abandon their software. They want to have their cake and eat it too \u2013 by pushing their proprietary software and then leaving the users with the risk of abandoned apps and unmaintained software.<\/p>\n<p>This is not the first time that Samsung has prioritized marketing new features over security. Their Tizen operating system \u2013 intended to compete with Android \u2013 was heavily criticized earlier this year for its poor programming. Researcher Amihai Neiderman said \u201c<a href=\"https:\/\/motherboard.vice.com\/en_us\/article\/samsung-tizen-operating-system-bugs-vulnerabilities\" rel=\"nofollow\">it may be the worst code [he\u2019s] ever seen<\/a>.\u201d<\/p>\n<p>Samsung is not the only company guilty of foisting unwanted software on its users or abandoning apps. The Android ecosystem is frequently criticized for \u201cbloatware\u201d &#8211; apps that come preinstalled on phones that are developed by the manufacturer or part of sponsorship deals \u2013 and for stopping critical OS updates only a few years after release.<\/p>\n<p>Samsung\u2019s S Suggest screw-up will only cost it a few days of bad press. But when manufacturers regularly <a href=\"https:\/\/www.extremetech.com\/mobile\/197346-google-throws-nearly-a-billion-android-users-under-the-bus-refuses-to-patch-os-vulnerability\" rel=\"nofollow\">abandon their software and devices<\/a> it\u2019s only a matter of time before a truly dangerous vulnerability occurs.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Abandoned Software is a Security Risk That Manufactures Must Take Responsibility For A researcher found that Samsung abandoned its \u201cS Suggest\u201d app which could have opened a security vulnerability for&#8230;<\/p>\n","protected":false},"author":2,"featured_media":4301,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":"","tve_updated_post":"","tve_custom_css":"","tve_user_custom_css":"","tve_globals":{},"tcb2_ready":0,"tcb_editor_enabled":0,"tve_landing_page":"","_tve_header":"","_tve_footer":""},"categories":[17],"tags":[3269,174],"class_list":["post-4296","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-industry-lowdown","tag-samsung","tag-vulnerabilities","post-with-tags"],"views":22585,"jetpack_featured_media_url":"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/06\/iStock-613763780.jpg","_links":{"self":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/4296","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/comments?post=4296"}],"version-history":[{"count":0,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/4296\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media\/4301"}],"wp:attachment":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media?parent=4296"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/categories?post=4296"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/tags?post=4296"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}