Feeds

Skype plugs Android privacy flaw

Less paranoia

Next gen security for virtualised datacentres

Skype has plugged a privacy flaw in the Android version of its VoIP telephony software.

The update plugs a hole that created a possible mechanism for third-party apps to get access to private data (name, phone number, chat logs etc) held on the Skype directory on Android devices.

The security problem was discovered by independent software developer Justin Case and first reported on the Android Police smartphone security blog last weekend.

A rogue app could harvest a treasure trove of sensitive data, without root access or any special permissions, simply because Skype had made the mistake of storing personal data in a openly accessible and unencrypted files.

Skype’s chief information-security officer Adrian Asher acknowledged the flaw while stressing that the mobile telephony outfit has not come across any examples of its misuse by third-party malicious applications, though it would continue to monitor the situation. The firm advised users to download its software from the official Android Market or via Skype's web site, rather than unlicensed channels.

The updated smartphone software - released on Wednesday - also allows US users to piggyback onto 3G networks when making calls over Skype. Previously this facility, which users outside the US would take for granted, was only available from a select set of phones on the Verizon network, relegating other stateside users to Skype calling only when they accessed the service over Wi-Fi networks.

Skype-to-Skype calls and text are free, but there's a fee if you want to call landlines or mobiles outside the service. ®

Next gen security for virtualised datacentres

More from The Register

next story
UK fuzz want PINCODES on ALL mobile phones
Met Police calls for mandatory passwords on all new mobes
Don't call it throttling: Ericsson 'priority' tech gives users their own slice of spectrum
Actually it's a nifty trick - at least you'll pay for what you get
Three floats Jolla in Hong Kong: Says Sailfish is '3rd option'
Network throws hat into ring with Linux-powered handsets
Fifteen zero days found in hacker router comp romp
Four routers rooted in SOHOpelessly Broken challenge
Netflix swallows yet another bitter pill, inks peering deal with TWC
Net neutrality crusader once again pays up for priority access
New Sprint CEO says he will lower axe on staff – but prices come first
'Very disruptive' new rates to be revealed next week
US TV stations bowl sueball directly at FCC's spectrum mega-sale
Broadcasters upset about coverage and cost as they shift up and down the dials
Tech city types developing 'Google Glass for the blind' app
An app and service where other people 'see' for you
Canadian ISP Shaw falls over with 'routing' sickness
How sure are you of cloud computing now?
UK mobile coverage is BETTER than EVER, networks tell Ofcom
Regulator swallows this line and parrots it back out at us. What are they playing at?
prev story

Whitepapers

Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Top 10 endpoint backup mistakes
Avoid the ten endpoint backup mistakes to ensure that your critical corporate data is protected and end user productivity is improved.
Top 8 considerations to enable and simplify mobility
In this whitepaper learn how to successfully add mobile capabilities simply and cost effectively.
Rethinking backup and recovery in the modern data center
Combining intelligence, operational analytics, and automation to enable efficient, data-driven IT organizations using the HP ABR approach.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.