We're aware that some users are experiencing technical issues which the team are working to resolve. See the Community Noticeboard for more info. Thank you for your patience.
📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

Massive Android data leak - how worried do we need to be?

Options
Be avidly reading about this massive android mobile data leak - front page of the Metro, BBC, Sky News etc. It sounds as bad, if not worse, than the one that Apple were rightly chastised for (the data tracking thing).

As someone considering buying an Android mobile when my current contract expires, and the apparent difficulty of patching the phones due to how many different versions exist - how worried do we, the consumer, need to be?

Comments

  • steve1980
    steve1980 Posts: 2,334 Forumite
    As long as you have the latest version 4.2.3 I think, you're fine.
    Estate Agent, Web Designer & All Round Geek!
  • 23n1th
    23n1th Posts: 1,523 Forumite
    It would appear that all you need to do to counteract this is to switch off the auto-sync (which I do to save battery power) and use secure networks when updating or syncing your apps.
  • kutsu119
    kutsu119 Posts: 163 Forumite
    It's pretty poor on Google's part though - especially as so many people took the moral high-ground after the Apple fiasco..
  • paddyrg
    paddyrg Posts: 13,543 Forumite
    I just use HSDPA/3G everywhere for everything, no worry about open networks that way. Yes, it is a security vulnerability and a severe one, but only in certain circumstances (promiscuous network activity is always going to be a risk though with any device)
  • Fifer
    Fifer Posts: 59,413 Forumite
    10,000 Posts Combo Breaker
    I accept there may be a vulnerability using an open wifi network, but with a properly secured home wifi network or 3G/mobile, is there really much of a vulnerability?

    PS I think there's a typo in Steve's post above. The version of Android with the fix is 2.3.4
    There's love in this world for everyone. Every rascal and son of a gun.
    It's for the many and not the few. Be sure it's out there looking for you.
    In every town, in every state. In every house and every gate.
    Wth every precious smile you make. And every act of kindness.
    Micheal Marra, 1952 - 2012
  • gaming_guy
    gaming_guy Posts: 6,128 Forumite
    1,000 Posts Combo Breaker
    edited 1 June 2012 at 3:26PM
    ...........
  • teffers
    teffers Posts: 698 Forumite
    Part of the Furniture 500 Posts
    Using 2.3.4 so I'm not worried at all :cool:
  • paddyrg
    paddyrg Posts: 13,543 Forumite
    Fix going in now... http://www.theregister.co.uk/2011/05/18/google_android_security_fix/

    From what I understand...
    Attackers monitoring Wi-Fi hotspots and other open networks could exploit the weakness by copying the so-called authTokens and using them to gain unauthorized access to users' Google Calendars and Contacts.
    The fix forces Google servers to use an encrypted https connection when phones sync with Calendar and Contacts
  • mr_fishbulb
    mr_fishbulb Posts: 5,224 Forumite
    Part of the Furniture Combo Breaker
    kutsu119 wrote: »
    Be avidly reading about this massive android mobile data leak
    Forgive me if I'm wrong, but there hasn't been a leak.

    This news is of a vulnerability in the way that Android devices authenticate themselves when synchronising. The authentication is done by a token ID (basically a piece of text) which is sent unencrypted and are not one-time authenticators. This is vulnerable to a replay attack where anyone who gets a copy of your token ID can impersonate with it.

    Basically a very similar to the vulnerability FireSheep highlighted to the masses where the of sending authentication cookies over http (unencrypted rather than https (encrypted) meant they could be captured and replayed.
  • 23n1th
    23n1th Posts: 1,523 Forumite
    I also can't see how this can be worse than apples recent "software bug" which was collecting lots of private data from users.
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 350.9K Banking & Borrowing
  • 253.1K Reduce Debt & Boost Income
  • 453.5K Spending & Discounts
  • 243.9K Work, Benefits & Business
  • 598.7K Mortgages, Homes & Bills
  • 176.9K Life & Family
  • 257.2K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.1K Discuss & Feedback
  • 37.6K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.