Skip to main content

Samsung lets S Suggest domain expire, potentially leaving customers vulnerable

Samsung, being the world leader in the number of phones sold, has to maintain hundreds of web domains that are tied to its different applications and services. Recently, the company accidentally let the domain linked to the S Suggest app expire. According to a security researcher who purchased the domain, this could have led to malicious attacks on millions of devices…

Talking to Motherboard, chief technology officer of Anubis Labs, João Gouveia, has taken ownership of ssuggest.com. The S Suggest application, which Samsung discontinued back in 2014, is the only application that is affected by data sent from the expired domain.

According to Gouveia, if someone had picked up the domain and wanted to cause harm, they could have used S Suggest to install malicious software onto millions of Samsung devices. This is possible because the application has permission to remotely reboot and install other apps.

After the initial report had been published, Samsung released a statement that disputed Gouveia’s claim. According to Samsung, “control of the domain ‘does not allow you to install malicious apps, it does not allow you to take control of users’ phones.'”

In a 24 hour period, Gouveia reports that he monitored over 620 million individual connections to the domain from over 2.1 million devices. This shows there is still a significant number of phones from 2014 and before (such as the Galaxy S5, Note 4, and any other devices sold beforehand) that were left vulnerable by Samsung.

Thankfully, users shouldn’t be worried because Gouveia was the one to take ownership of the domain. Additionally, he has offered to give back the ssuggest.com domain to Samsung.


FTC: We use income earning auto affiliate links. More.

You’re reading 9to5Google — experts who break news about Google and its surrounding ecosystem, day after day. Be sure to check out our homepage for all the latest news, and follow 9to5Google on Twitter, Facebook, and LinkedIn to stay in the loop. Don’t know where to start? Check out our exclusive stories, reviews, how-tos, and subscribe to our YouTube channel

Comments

Author

Avatar for Justin Duino Justin Duino

I’m a writer for 9to5Google with a background in IT and Android development. Follow me on Twitter to read my ramblings about tech and email me at justin@jaduino.com. Tips are always welcome.