Skip the navigation
)
News

Google moves fast to plug Android Wi-Fi data leaks

'Impressive,' says mobile security expert on Google's quick move to fix flaw

May 18, 2011 04:12 PM ET

Computerworld - Google today confirmed that it's starting to roll out a server-side patch for a security vulnerability in most Android phones that could let hackers snatch important credentials at public Wi-Fi hotspots.

"Today we're starting to roll out a fix which addresses a potential security flaw that could, under certain circumstances, allow a third party access to data available in Calendar and Contacts," said a Google spokesman in an emailed statement. "This fix requires no action from users and will roll out globally over the next few days."

Computerworld blogger JR Raphael was the first to break the news of Google's move to fix the flaw.

Google will apparently apply a fix on its servers since it does not need to issue an over-the-air update to Android phones.

Experts applauded Google's fast reaction.

"It's impressive how quickly Google fixed this," said Kevin Mahaffey, chief technology officer and a co-founder of San Francisco-based mobile security firm Lookout. "Google's security team, especially on Android, is very, very quick to deal with issues."

Mike Paquette, the chief strategy officer for Hudson, Mass.-based Top Layer Security, agreed.

"The Google team talks about how they breathe security in and out, and this is a good example," said Paquette, who called the speed with which Google addressed the issue "pretty good."

Whatever Google is implementing will shut the security hole that three German researchers publicized last Friday.

According to the University of Ulm researchers, who tested another researcher's contention last February that Android phones sent authentication data in the clear, hackers could easily spoof a Wi-Fi hotspot -- in a public setting such as an airport or coffee shop -- then snatch information that users' phones transmitted during synchronization.

In Android 2.3.3 and earlier, the phone's Calendar and Contacts apps transmit information via unencrypted HTTP, then retrieve an authentication token from Google. Hackers could eavesdrop on the HTTP traffic at a public hotspot, lift authentication tokens and use them for up to two weeks to access users' Web-based calendars, their contacts and also the Picasa photo storage and sharing service.

Other applications that use Google's ClientLogin Protocol, including third-party Android apps as well as traditional desktop software like Mozilla's Thunderbird email program, were also vulnerable, the researchers said.

"The implications of this vulnerability reach from disclosure to loss of personal information for the Calendar data," said the three researchers, Bastian Koenings, Jens Nickels, and Florian Schaub. "For Contact information, private information of others is also affected, potentially including phone numbers, home addresses, and email addresses."

The trio estimated that 99% of Android users were affected because of the slow and fragmented updating that carriers conduct.

Koenings, Nickels and Schaub also outlined more devious damage that a cyber criminal could do. "An adversary could perform subtle changes without the user noticing," they said. "For example, an adversary could change the stored email address of the victim's boss or business partners hoping to receive sensitive or confidential material pertaining to their business."



What is Tech Briefcase?
TechBriefcase is a new, free service where IT Professionals can Search, Store and Share IT white papers and content like this. Learn more
Bookmark content
Speed up your research efforts with content across the web.
Search and Store
Find the white papers you need. Create folders for any topic.
View Anywhere
Open your briefcase on your iPhone, tablet or desktop. Share with colleagues.
Don't have an account yet?
Additional Resources
Security KnowledgeVault
WHITE PAPER
Security is not an option. This KnowledgeVault Series offers professional advice how to be proactive in the fight against cybercrimes and multi-layered security threats; how to adopt a holistic approach to protecting and managing data; and how to hire a qualified security assessor. Make security your Number 1 priority.

Read now.

Cut Communications Costs Once and for All
WHITE PAPER
New IP-based communications systems are being deployed by small and midsized businesses at a rapid rate. Learn how these organizations are enabling faster responsiveness, creating better customer experiences, speeding office or mobile interactions, and dramatically reducing existing communications costs.

Read now.

Security White Papers
Driving Secure Enterprise File Sharing and Syncing in the Enterprise
GroupLogic's new activEcho is the industry's only secure Enterprise File Sharing and Synching solution that balances the need for simplicity for the end...
The Enterprise File Sharing Option
Enterprises and IT departments need to address several critical security issues when considering file sharing and syncing products. Many of today's solutions do...
Security Strategies to Virtualizing Internet-Facing Applications
The IT organization at Intel has set a goal to transition their enterprise to a private cloud for their Office and Enterprise applications....
Cloud Security Planning Guide
Cloud security considerations span protecting hardware and platform technologies in the data center to enabling regulatory compliance and defending cloud access through different...
Cloud Security Vendor Round Table
This vendor round table guide will help you to evaluate different cloud technology vendors and service providers based on a series of questions...
All Security White Papers
Security Webcasts
Live Webcast
Data Privacy and Protection in Production Environments: New Research from Ponemon Institute
Date: Wednesday, June 13, 2012, 1:00 PM EDT / 10:00 AM PDT

In a recent study conducted by Ponemon Institute, fifty-five percent of respondents...
Data Privacy and Protection in Production Environments: New Research from Ponemon Institute
Date: Wednesday, June 13, 2012, 1:00 PM EDT / 10:00 AM PDT

In a recent study conducted by Ponemon Institute, fifty-five percent of respondents...
Security Certifications 101 - BlackBerry and all those acronyms what do they mean and why they matter?
FIPS, Common Criteria, CAPS, AISEP, NFC, NIST, Fraunhofer SIT, CESG, DSD - these are just some of the government and industry certifications which...
BlackBerry PlayBook OS 2.0 Security Overview
The presentation provides an overview of BlackBerry PlayBook OS 2.0 security capabilities and features, including: BlackBerry® Balance™ technology, BlackBerry® Bridge, data-at-rest protection, and...
BlackBerry NFC Security Overview
The presentation on NFC security will provide an overview of the security protections built into the BlackBerry platform to protect users, application developers...
Playing Defense: Staying on Top of Your Disaster Recovery Game
When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing...
All Security Webcasts
Newsletter Sign-Up

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all newsletters | Privacy Policy
IT Jobs