Why Google . . . WHY?!?
Why Google . . . WHY?!?
Author
Discussion

WeaselSandwicH

Original Poster:

19 posts

190 months

Wednesday 18th May 2011
quotequote all
So I was in a really good mood today until my girlfriend came home with the Metro and the front page reading "Android Phones 'all leak secrets'". It's a deeply disturbing article but more so to the point that thanks to google, I may have to get ANOTHER bank card cancelled because of there eagerness to compete in markets they should leave to the professionals. 99.7% of the android phones that are out on the market are susceptible to be openly accessed and things like contacts amended/deleted and temporary internet files accesssed for login details etc. I for one, am exceedingly pcensoredd off!

Famous Graham

26,553 posts

254 months

Wednesday 18th May 2011
quotequote all
In other news, sales of tinfoil have taken a remarkable upturn.

FourWheelDrift

92,257 posts

313 months

Wednesday 18th May 2011
quotequote all
Google are the Combined Harvester of the Tech world, they have to make their own products open slightly to allow their own information bots to collect your data to sell on. wink

Mr Happy

5,893 posts

249 months

Wednesday 18th May 2011
quotequote all
Do you know much about this hack or just what you've read in the paper? Serious question.

It's only a problem using wifi, and then - only unsecured wifi (so stuff like public access points/hotels etc where your initial contact is unsecured, then you purchase time and get a WPA password - at which point this defect is rendered null and void)

What has to happen is that someone just happens to be set up, with wireshark or some other packet stealing software on a laptop, and just happens to be waiting for Android users to sign onto the unsecured wifi and do enough stuff on it so that they can nab the 14 day lease secure token, then use that token to do whatever nefarious stuff they need to do.

In short, you'd be very unlucky for that set of circumstances to happen, you'd be even more unlucky if anything were to come of it.

So yeah - as long as you don't use unsecured wifi, nothing will happen.

For the TL;DR crowd - don't worry, nothing will happen.

Link here

WeaselSandwicH

Original Poster:

19 posts

190 months

Wednesday 18th May 2011
quotequote all
Surely though if they're just using a packet stealer then it wouldn't only need to be unsecure wifi locations? They must be able to do it on the other end as well, from what ever websites servers. Btw, just noticed that I totally posted this in the wrong forum part so I apologise.

crmcatee

5,803 posts

256 months

Wednesday 18th May 2011
quotequote all
Once people understand that Google's only product is Data the clearer the issues surrounding the leaking/providing of data will be.

Mr Happy

5,893 posts

249 months

Wednesday 18th May 2011
quotequote all
Erm, cos unsecured wifi is unsecured. Even if they're using only using WEP the packets are encrypted (weakly) which makes it not succeptible to a plain text attack such as this. Once the data packet is inside the router and off down the internet tubes, it's fine.

The packet sniffer works because on unsecured wifi everything is sent plain text (well, that's not strictly true but for the purposes of this discussion it is accurate enough) so it can just sniff the packets literally out of the air. If you use WEP/WPA/WPA2 etc, then it is encrypted from your device to the router, and as such no longer plaintext-viewable.

It's got nothing to do with websites or anything - it's literally just obtaining the authorisation token from whatever you log in to over an unsecured wifi network, and using that token to log in to whereever you went into and do dodgy things with it.

Seriously, you've got absolutely nothing to worry about with this. Certainly you don't have to go through the hassle of getting a new card etc.

I wish the media would report on some things with a foot a little more grounded in reality some days.

Edited by Mr Happy on Wednesday 18th May 19:18

DaGuv

451 posts

235 months

Wednesday 18th May 2011
quotequote all
OP, you're a TW*T!

Engineer1

10,486 posts

238 months

Wednesday 18th May 2011
quotequote all
If you are that paranoid do you change cards every time you make a card holder not present purchase over the phone? After all you have to tell them all the card details and they could write them down and use them till you twig.