The Register® — Biting the hand that feeds IT

Feeds

Google rolls out fix for Android security threat

Forecloses 'impersonation attacks' against users

Regcast training : Hyper-V 3.0, VM high availability and disaster recovery

Google has plugged a security hole that exposed the vast majority of Android phone users' calendars and contacts when they accessed those services over unsecured networks.

"Today we're starting to roll out a fix which addresses a potential security flaw that could, under certain circumstances, allow a third party access to data available in calendar and contacts," a company spokesman wrote in an email. "This fix requires no action from users and will roll out globally over the next few days."

The server-side fix addresses an implementation error in earlier versions of Android, which is used by more than 99 percent of those using the mobile operating system, according to Google figures. Versions 2.3.3 and earlier failed to transmit authentication tokens over an encrypted channels.

Attackers monitoring Wi-Fi hotspots and other open networks could exploit the weakness by copying the so-called authTokens and using them to gain unauthorized access to users' Google Calendars and Contacts.

The vulnerability could also cause devices synchronizing with Google Picasa web albums to transmit sensitive data through unencrypted channels, academic researchers from Germany's University of Ulm said.

The Google spokesman said the company's security team is still investigating those claims.

The fix forces Google servers to use an encrypted https connection when phones sync with Calendar and Contacts. ®

Agentless Backup is Not a Myth

You'd think they'd know better

You'd think that a company like Google would know better than letting identification go through unencrypted channels (even a one-time token). Especially on a mobile device, which is deemed to connect through non-secure or even hostile networks. Calendar and contact ar not banking-site-grade things but still can be used to build further attacks, notably social engineering ones. Potentially not good.

Good that they fixed that one, and from the server side too, no problem from laggard network operators failing to release the upgrade to their clients.

4
0

Good against providers doing DPI

This is very good news, especially since Vodafone and KPN in the Netherlands have admitted to doing Deep Packet Inspection, which means that they could have your authentication token even when connecting over 3G.

3
0

Learn to read

This is a server side fix so you'll get it immediately as it has nothing to do with O2, your phone or it's manufacturer.

2
0

More from The Register

 breaking news
Number of cops abusing Police National Computer access on the rise
Only a telegram from the Queen can get you off it
 breaking news
NSA PRISM snoop-gate: Won't someone think of the children, wails Apple
10,000 things probed, mostly about missing kids, Alzheimer patients, we're told
Flash flaw potentially makes every webcam or laptop a PEEPHOLE
But it's a Google problem - Chrome only, insists Adobe
Internet fraud still stings suckers
Australians twice as gullible as Americans
 breaking news
NSA PRISM-gate: Relax, GCHQ spooks 'keep us safe', says Cameron
Whatever they are up to, it's all above board, we're told
 breaking news
Yahoo! joins! rivals! in! PRISM! data! request! admission!
Keep calm and carry on using American tech firms, folks
PRISM snitch claims NSA hacked Chinese targets since 2009
Snowden suddenly looks safer in Hong Kong after revelations
 breaking news
US chief spook: Look, we only want to spy on 6.66 BEELLLION of you
Americans assured they are not in the NSA's sights
Speech-to-text drives motorists to distraction
Will talking to you mean I crash into that car up ahead, Siri?
DHS warns of vulns in hospital medical equipment
Has your doctor's anasthesia machine been hacked?