Mercredi, 18 Mai 2011 01:37
User Login Vulnerability Found In 99% of Android Handsets
Research from multiple universities is now warning that almost all smartphones that are running Google’s Android software could be allowing third parties access to digital tokens that could allow access to services such as Google Calendar and Contacts. The issue seems to affect all devices running versions of Android prior to 2.3.3 and is related to handling of the authentication protocol ClientLogin. According to researchers at the German University of Ulm, once a user enters their credentials, the programming interface retrieves its token in clear text. The token is valid for 14 days and a window appears where attackers could use their new found access however they like. The whole process seems to be relatively easy to exploit according to the researchers. “We wanted to know if it is really possible to launch an impersonation attack against Google services and started our own analysis,” “The short answer is: Yes, it is possible, and it is quite easy to do so.” The results come after a professor at Rice University demonstrated a similar flaw affecting Facebook, Twitter, and once again Google Calendar. This time though, the hack could only be carried out on an unsecured Wi-Fi network. Google has patched that specific hole in Android 2.3.4 but failed to plug the whole when it comes to Picasa, which allows web albums to potentially transmit sensitive data in the clear. As of right now, Google claims to be working on a fix. Android’s fragmentaton issues cause potential security holes to be further exacerbated. The fragmentation causes phones to remain on older software long after patches have been released. With carriers and device manufacturers insisting on meddling with Google’s operating system, updates can take several months to get past their own software engineers, this results in a massive 99% o Android devices still being wide open to being hacked. Google recently mentioned that it will work more closely with carriers to try and reduce the time it takes for updates to be rolled out fully. As usual, stay tuned for more tech news and info by following us on Facebook, Twitter, and/or subscribing to our RSS feed. Read More Authors:
Read 4452 times
Published in
News Technologique-Tech News
More in this category:
« Sony’s “Welcome Back” Package Announced For PSN Users
Widgets For The iOS In Development »
Last WebBuzz
-
WebBuzz du 24/11/2017: Pérou décoller comme superman-Peru Reverse bungee aka Superman Jump
Read 46802 times
-
WebBuzz du 22/11/2017: Une Femme Saoudienne fait du surf dans les rues-Saudi girl Car Surfing after heavy rains and flood in Saudi Arabia
Read 45796 times
-
WebBuzz du 20/11/2017: Maxi crach au grand prix GT à Macau-Huge pile up Crash 2017 Macau Grand Prix FIA GT World Cup
Read 41482 times
-
WebBuzz du 17/11/2017: Boston Dynamics fait le cirque avec ses robots-BD prepare to build a circus with his robots
Read 43471 times
-
WebBuzz du 16/11/2017: Une illusion d'optique féminine-a feminine optical illusion
Read 42523 times
-
WebBuzz du 14/11/2017: Roumanie un bus de police évite un tram de justesse-Close call between a tram and police's bus
Read 38084 times
-
WebBuzz du 13/11/2017: Arrivée fracassante d'un bateau sur les docks de San Diego-Whale Watching Boat Crashing Into San Diego Dock
Read 36048 times
-
WebBuzz du 08/11/2017: Créer des flammes de toutes les couleurs-How to make colourful flames
Read 36990 times
-
WebBuzz du 07/11/2017: Echec test du système de détection des piètons de la Volvo S60-Volvo S60 Pedestrian Detection System Test failed
Read 38543 times
-
WebBuzz du 03/11/2017: Slacker dans la forêt-slackline in the forest
Read 41651 times
accident
Amazing
animal
animals
animaux
art
avec
baby
car
Cat
chat
chien
comment
Crazy
Cute
dans
Dog
droles
Echec
fail
fait
From
funny
how
jump
musique
nature
new
people
plus
pour
route
russia
russie
saut
sauvage
Sport
stupid
sur
Technique
The
usa
vehicules
video
video du jour
videos
voiture
webbuzz
wild
with