The Register® — Biting the hand that feeds IT

Feeds

Samsung slaps swift patch over phone-wiping Galaxy S III vuln

Smartmobe owners can bonk without fear again

Regcast training : Hyper-V 3.0, VM high availability and disaster recovery

Samsung has whipped out a fix for an embarrassing flaw in its smartphones that allows miscreants to wipe victims' phones with a simple web link. The South Korean electronics giant is pushing out the patch right now.

The Galaxy S III has a firmware update available that closes the security hole, and it can be picked up from an over-the-air download - and it may already be installed on many handsets.

Fixes for other Samsung phones should be expected soon although the manufacturer is being uncharacteristically taciturn about the details. But a rapid fix is always a good thing, especially as knowledge of the flaw spreads.

The existence of the problem was revealed at the Ekoparty 2012 hacking event over the weekend, and enables mischievous colleagues and vandalistic hackers to hard reset Samsung handsets with ease, wiping all the data and returning the phone to its factory state.

The TouchWiz phone dialling application, it seems, was responsible. The software responds to phone numbers delivered in a URL in the same way as those entered manually, allowing special codes to be entered and executed from a web link picked up by wireless NFC, embedded in a web page or read off a QR code.

Given the nature of the problem the quick fix isn't a surprise: a minor tweak to the dialler was all that's needed although Samsung still deserves credit for getting the patch deployed so quickly.

Users wanting to know if their fix has been applied can drop by Android Central, which has a benign example available, while those who want to live dangerously can follow these instructions and bet their data that Samsung has fixed the problem. ®

Regcast training : Hyper-V 3.0, VM high availability and disaster recovery

Stop skinning Android

Just a suggestion, stop putting these shitty skins on Android phones. It's why I only buy the Nexus range - so I don't get all these stupid skins and un-removable apps.

I've seen HTC Sense regularly crash on a colleagues Desire HD, it's never happened to me on stock firmware.

7
1

Er, actually Samsung's patch was a while ago - hence why people aren't getting OTA notifications now.

5
1

Re: Not a (just) Touchwiz problem

"none of the others have Factory Reset USSD codes. hopefully."

You can hope, but in all likelihood this facility exists in all handsets.

Don't know why the reporters keep saying it is down to TouchWiz when the basic vuln has been shown to work on other phones. The only thing missing for other phones is the reset USSD code, security through obscurity is not security.

3
0

More from The Register

1,000 O2 staff chose redundancy over Capita
Betrayal, or just decent terms?
Google launches broadband balloons, radio astronomy frets
A careless Loon could blind the square kilometre array
 breaking news
Pttow! Ofcom kicks hams out of MoD bands
Geet off my land, you, you ... 'secondary user'
 breaking news
Now you can use your phone instead of your wallet at the ATM, too
Blimey, these little paper towels out of the vending machine are really expensive
 breaking news
UK.gov's £530m bumpkin broadband rollout: 'Train crash waiting to happen'
Whitehall whispers of damning watchdog report next month
 breaking news
MySpace zaps millions of teens' tearful rants, causes wave of angst
'Your crappy redesign SUCKS, I wanna read my blogs' screech users
 breaking news
Microsoft Office 365 on iPhone NOW: No, we're not making this up
Word, Excel, Powerpoint for your pocket-stroker
 breaking news
EU signs off on eCall emergency-phone-in-every-car plan
GPS and a mobe in every car - do you suppose the NSA would fancy that?