Google Rolls Out Updates for Android Security Hole

May 19, 2011 -

Responding to reports that 99.7 percent of Android-based phones suffered from a security hole that made vital personal data vulnerable to hackers, Google has released an automatic fix to deal with the problem. Google is trying to assure users that no action is needed on their part.

"Today we're starting to roll out a fix which addresses a potential security flaw that could, under certain circumstances, allow a third party access to data available in calendar and contacts," said Google in a statement. "This fix requires no action from users and will roll out globally over the next few days."

The flaw was identified by Ulm University (Germany) researchers who who tested the security hole on a number of smart phones using the Android operating system. They also found that some phones sent unencrypted data, which clever hackers could "eavesdrop" on with the right tools.

"We wanted to know if it is really possible to launch an impersonation attack against Google services and started our own analysis," said researchers Bastian Könings and Jens Nickels.

"The short answer is: Yes, it is possible, and it is quite easy to do so. Further, the attack is not limited to Google Calendar and Contacts, but is theoretically feasible with all Google services using the ClientLogin authentication protocol for access to its data APIs."

Source: GameIndustry.biz


Comments

Re: Google Rolls Out Updates for Android Security Hole

Good, quick turnaround.  That's what I like to see.  Being able to rapidly fix security holes is as important a skill as preventing them in the first place -- because sooner or later, you're going to need to know how to do both.

 
Forgot your password?
Username :
Password :

Poll

Will Target Australia sell the next GTA game upon its release?:

Shout box

You're not permitted to post shouts.
Mattsworknameohh, gods that game is pretty, just not my style these days07/29/2015 - 11:49pm
Andrew EisenUbisoft's Child of Light.07/29/2015 - 11:45pm
MattsworknameEnjoy man, Im gonna be playing split second myself07/29/2015 - 11:45pm
Andrew EisenSorry. That just slipped out. Off to play.07/29/2015 - 11:43pm
Andrew EisenWords have meanings, people! Use the damn dictionary! They're online! They're free! Arrggghhhh!07/29/2015 - 11:42pm
Andrew EisenThis is just depressing. I'm gonna go play video games.07/29/2015 - 11:42pm
Mattsworknameproliferation of the whole "internet movment" thing, people dont debate, they try to attack and go after peole to shut them down, casue it's easier then trying to debate the issues07/29/2015 - 11:39pm
MattsworknameWhen you break it down, what it is is the shifting of the media lanscape and how it effects news sites and other groups. once upon a time, you could have run that same article and it would have created debate, not online campagns, now, cause of the07/29/2015 - 11:38pm
MattsworknameCall it waht you wil, but thats how its viewed, not just by me, but by just about EVERYONE right now. Media, new networks, they dont' want to call it what it is, soe they call it "accountability"07/29/2015 - 11:34pm
Andrew Eisen"Gamasutra... had to pay" Yes. That's EXACTLY what it was. "Accountability" is and always was horse poop.07/29/2015 - 11:29pm
MattsworknameSo to speak07/29/2015 - 11:28pm
MattsworknameThats why this happened, you get people who felt hurt, marginalize, bettrayd, or otherwise offended, and they don't actually look at teh facts, they just attack and try to get there Blood for Blood07/29/2015 - 11:28pm
Mattsworknamefalse. Weather you think the article was right or not, there was a large group who felt taht gamastura and the other media sites had to pay for there actions, weather they deserved it or not07/29/2015 - 11:27pm
Andrew EisenTrying to yank advertising over a single opinion piece on a site that I would bet money most of the offended (if you will) didn't read, is no more an attempt at accountability than the Brown shooting's subsequent riots.07/29/2015 - 11:27pm
MattsworknameMy point andrew is that it's not about them, its about the people responding to the situation. THe brown shooting was eventually shown to be completely justified, but the "Black lives matter" meme kept on rolling despite all it's intiall claims being07/29/2015 - 11:26pm
Andrew EisenDude, you're comparing an opinion piece with someone who was shot to death. Gamasutra and Alexander already were accountable for the opinion piece in question.07/29/2015 - 11:25pm
Mattsworknamekinds of events. nor has it stopped them from being asshats in my opinion, but in there view, they have to hold someone accountible for recent events, so they are doing what they think they must, even if it's based on falsehoods07/29/2015 - 11:22pm
MattsworknameAndrew: It's really a matter of context for the people involved. For example. The "Black lives matter" thing is based on an entirely false account of events in the brown shooting, but that hasnt' stopped it from triyng to hold Polititcians accountable for07/29/2015 - 11:22pm
Andrew EisenWouldn't surprise me. A lot of words' actual meanings escape many people on the internet.07/29/2015 - 11:17pm
Andrew EisenSo, "they must be held accountable" means "we must hurt them for publishing an opinion piece we don't like."07/29/2015 - 11:17pm
 

Be Heard - Contact Your Politician