Major security flaw found in Android phones

Ander computer/it/software/hardware nieuws.
Plaats reactie
theduvelking
Premium Member
Premium Member
Berichten: 602
Lid geworden op: 03 okt 2006, 01:22
Uitgedeelde bedankjes: 54 keer
Bedankt: 69 keer

NEW YORK (CNNMoney) -- A significant security hole has been discovered in Google's Android operating system for smartphones, which can allow attackers to gain access to users' personal information without their permission.
The flaw, which was discovered by three research assistants at Ulm University in the southern part of Germany, affects approximately 97% of Android users.


In a recent blog post, the researchers found that users of Android devices running versions 2.3.3 and below could be susceptible to attack when they are connected to unencrypted Wi-Fi networks. Anyone else on that network could gain access to, modify or delete Android users' calendars, photos and contacts.

"It is quite easy," the researchers wrote in a blog post. "The implications of this vulnerability reach from disclosure to loss of personal information."

A spokesman for Google (GOOG, Fortune 500) said the company is aware of this issue, and a fix is already in place for the calendar and contacts applications in the latest versions of Android, codenamed "Gingerbread" and "Honeycomb." A solution is also in the works for Google's Picasa photo sharing service, he said.

Only about 3% of Android users have the latest versions of the operating system, but Google said Android users running older versions will get a fix "in the next few days." Users don't need to take any action, and the patch will roll out globally.

The security flaw stems from Google making use of unencrypted login protocol for the affected services. By using HTTP, rather than the more secure HTTPS, "an adversary can easily sniff the [login information]," according to the blog post.

The kind of attack that can be performed on Android devices over unencrypted Wi-Fi networks is similar to so-called "Sidejacking" attacks on Facebook or Twitter. For instance, Firesheep, a free Firefox extension that collects data broadcast over an unprotected Wi-Fi network, allows users to gain access to other people's Facebook accounts.

Though the researchers found that any unsecured application making use of an Android user's photos, contacts or calendars could be compromised, the data an attacker can gain access to is limited to those three groups. The security bug does not, for example, allow intruders to view a user's e-mails.

Google was able to fix the problem on its end by requiring an HTTPS connection for calendar and contacts synchronization. By solving the problem on its own servers, Google was able to get around a notoriously slow Android update process: after Google updates the code, manufacturing partners and carriers then manipulate the code for each device.

As a result, the vast majority of Android users are still running "Froyo," which launched in May 2010. A quarter of users are still on "Eclair," which came out all the way back in January of last year.

That means a patch for the security hole could have been months or years away for many Android users had Google not found a workaround.

In addition to switching to HTTPS, the researchers also suggested Google prevent Android devices from automatically remembering and logging onto unencrypted Wi-Fi networks. Google did not say whether it had taken any of those steps. To top of page
Bron: http://money.cnn.com/2011/05/18/technol ... 1&iref=NS1

Zoals gewoonlijk zal dit weer niet wereldwijd in alle kranten komen te staan ... :bang:
Gebruikersavatar
meon
Administrator
Administrator
Berichten: 16609
Lid geworden op: 18 feb 2003, 22:02
Twitter: meon
Locatie: Bree
Uitgedeelde bedankjes: 564 keer
Bedankt: 759 keer
Contacteer:

Gebruikersavatar
selder
Moderator
Moderator
Berichten: 6305
Lid geworden op: 29 jun 2005, 20:25
Locatie: Tienen
Uitgedeelde bedankjes: 99 keer
Bedankt: 727 keer

theduvelking schreef: [...]

Zoals gewoonlijk zal dit weer niet wereldwijd in alle kranten komen te staan ... :bang:
Ha nee, natuurlijk niet, alleen als het over Steve Jobs zijn telefoons gaat hé :)
Ghost S1 • 8086K @5.2Ghz • Asus ROG Ryuo 240mm • Asus ROG STRIX Z390-I • Corsair Vengeance LPX 2x16GB 3200Mhz • Asus RTX2080Ti Turbo • Samsung 970 EVO 2TB • Asus ROG Swift PG258Q 240Hz • Logitech G Pro keyboard/mouse/headset
ubremoved_539
Deel van't meubilair
Deel van't meubilair
Berichten: 29849
Lid geworden op: 28 okt 2003, 09:17
Uitgedeelde bedankjes: 446 keer
Bedankt: 1985 keer

after Google updates the code, manufacturing partners and carriers then manipulate the code for each device.
Brrr... moest men verbieden zoiets... ik zie niet in wat de toegevoegde waarde is van een provider.
Gebruikersavatar
Ofloo
Elite Poster
Elite Poster
Berichten: 5263
Lid geworden op: 04 okt 2004, 07:36
Locatie: BALEN
Uitgedeelde bedankjes: 57 keer
Bedankt: 92 keer

Gaat weer iets van lange adem worden precies, ..
Lord Utopia
Erelid
Erelid
Berichten: 7819
Lid geworden op: 10 mei 2007, 16:33
Uitgedeelde bedankjes: 404 keer
Bedankt: 386 keer

r2504 schreef: Brrr... moest men verbieden zoiets... ik zie niet in wat de toegevoegde waarde is van een provider.
Is gewoon branding. Net zoals de logootjes van AT&T of Sprint op de Amerikaanse toestellen. 't Zijn gewoon de fabrikanten die sneller hun updates moeten doorgeven naar toestellen. Vooral Samsung is een krak in het uitstellen van updates.
Gebruikersavatar
Ofloo
Elite Poster
Elite Poster
Berichten: 5263
Lid geworden op: 04 okt 2004, 07:36
Locatie: BALEN
Uitgedeelde bedankjes: 57 keer
Bedankt: 92 keer

HTC is thans ook niet de snelste die er is ze, kan niet wachten tot er een nieuw root exploit so voor mijn dev dan kan ik er alternatieve soft op draaien dan upgrade ik die zo vaak als het nodig is.
Plaats reactie

Terug naar “Ander nieuws”