Feeds

Skype plugs Android privacy flaw

Less paranoia

The essential guide to IT transformation

Skype has plugged a privacy flaw in the Android version of its VoIP telephony software.

The update plugs a hole that created a possible mechanism for third-party apps to get access to private data (name, phone number, chat logs etc) held on the Skype directory on Android devices.

The security problem was discovered by independent software developer Justin Case and first reported on the Android Police smartphone security blog last weekend.

A rogue app could harvest a treasure trove of sensitive data, without root access or any special permissions, simply because Skype had made the mistake of storing personal data in a openly accessible and unencrypted files.

Skype’s chief information-security officer Adrian Asher acknowledged the flaw while stressing that the mobile telephony outfit has not come across any examples of its misuse by third-party malicious applications, though it would continue to monitor the situation. The firm advised users to download its software from the official Android Market or via Skype's web site, rather than unlicensed channels.

The updated smartphone software - released on Wednesday - also allows US users to piggyback onto 3G networks when making calls over Skype. Previously this facility, which users outside the US would take for granted, was only available from a select set of phones on the Verizon network, relegating other stateside users to Skype calling only when they accessed the service over Wi-Fi networks.

Skype-to-Skype calls and text are free, but there's a fee if you want to call landlines or mobiles outside the service. ®

The essential guide to IT transformation

More from The Register

next story
6 Obvious Reasons Why Facebook Will Ban This Article (Thank God)
Clampdown on clickbait ... and El Reg is OK with this
So, Apple won't sell cheap kit? Prepare the iOS garden wall WRECKING BALL
It can throw the low cost race if it looks to the cloud
EE accused of silencing customer gripes on social media pages
Hello. HELLO. Can EVERYTHING EVERYWHERE HEAR ME?!
Time Warner Cable customers SQUEAL as US network goes offline
A rude awakening: North Americans greeted with outage drama
Shoot-em-up: Sony Online Entertainment hit by 'large scale DDoS attack'
Games disrupted as firm struggles to control network
BT customers face broadband and landline price hikes
Poor punters won't be affected, telecoms giant claims
Broadband slow and expensive? Blame Telstra says CloudFlare
Won't peer, will gouge for Internet transit
prev story

Whitepapers

A new approach to endpoint data protection
What is the best way to ensure comprehensive visibility, management, and control of information on both company-owned and employee-owned devices?
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Maximize storage efficiency across the enterprise
The HP StoreOnce backup solution offers highly flexible, centrally managed, and highly efficient data protection for any enterprise.
How modern custom applications can spur business growth
Learn how to create, deploy and manage custom applications without consuming or expanding the need for scarce, expensive IT resources.
Next gen security for virtualised datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.