Why Google . . . WHY?!?
Discussion
So I was in a really good mood today until my girlfriend came home with the Metro and the front page reading "Android Phones 'all leak secrets'". It's a deeply disturbing article but more so to the point that thanks to google, I may have to get ANOTHER bank card cancelled because of there eagerness to compete in markets they should leave to the professionals. 99.7% of the android phones that are out on the market are susceptible to be openly accessed and things like contacts amended/deleted and temporary internet files accesssed for login details etc. I for one, am exceedingly p
d off!
d off!Do you know much about this hack or just what you've read in the paper? Serious question.
It's only a problem using wifi, and then - only unsecured wifi (so stuff like public access points/hotels etc where your initial contact is unsecured, then you purchase time and get a WPA password - at which point this defect is rendered null and void)
What has to happen is that someone just happens to be set up, with wireshark or some other packet stealing software on a laptop, and just happens to be waiting for Android users to sign onto the unsecured wifi and do enough stuff on it so that they can nab the 14 day lease secure token, then use that token to do whatever nefarious stuff they need to do.
In short, you'd be very unlucky for that set of circumstances to happen, you'd be even more unlucky if anything were to come of it.
So yeah - as long as you don't use unsecured wifi, nothing will happen.
For the TL;DR crowd - don't worry, nothing will happen.
Link here
It's only a problem using wifi, and then - only unsecured wifi (so stuff like public access points/hotels etc where your initial contact is unsecured, then you purchase time and get a WPA password - at which point this defect is rendered null and void)
What has to happen is that someone just happens to be set up, with wireshark or some other packet stealing software on a laptop, and just happens to be waiting for Android users to sign onto the unsecured wifi and do enough stuff on it so that they can nab the 14 day lease secure token, then use that token to do whatever nefarious stuff they need to do.
In short, you'd be very unlucky for that set of circumstances to happen, you'd be even more unlucky if anything were to come of it.
So yeah - as long as you don't use unsecured wifi, nothing will happen.
For the TL;DR crowd - don't worry, nothing will happen.
Link here
Erm, cos unsecured wifi is unsecured. Even if they're using only using WEP the packets are encrypted (weakly) which makes it not succeptible to a plain text attack such as this. Once the data packet is inside the router and off down the internet tubes, it's fine.
The packet sniffer works because on unsecured wifi everything is sent plain text (well, that's not strictly true but for the purposes of this discussion it is accurate enough) so it can just sniff the packets literally out of the air. If you use WEP/WPA/WPA2 etc, then it is encrypted from your device to the router, and as such no longer plaintext-viewable.
It's got nothing to do with websites or anything - it's literally just obtaining the authorisation token from whatever you log in to over an unsecured wifi network, and using that token to log in to whereever you went into and do dodgy things with it.
Seriously, you've got absolutely nothing to worry about with this. Certainly you don't have to go through the hassle of getting a new card etc.
I wish the media would report on some things with a foot a little more grounded in reality some days.
The packet sniffer works because on unsecured wifi everything is sent plain text (well, that's not strictly true but for the purposes of this discussion it is accurate enough) so it can just sniff the packets literally out of the air. If you use WEP/WPA/WPA2 etc, then it is encrypted from your device to the router, and as such no longer plaintext-viewable.
It's got nothing to do with websites or anything - it's literally just obtaining the authorisation token from whatever you log in to over an unsecured wifi network, and using that token to log in to whereever you went into and do dodgy things with it.
Seriously, you've got absolutely nothing to worry about with this. Certainly you don't have to go through the hassle of getting a new card etc.
I wish the media would report on some things with a foot a little more grounded in reality some days.
Edited by Mr Happy on Wednesday 18th May 19:18
Gassing Station | Video Games | Top of Page | What's New | My Stuff




