May
17
2011

Swiped Tokens Expose Android Devices To Data Theft

tsamsoniw writes “Researchers at the University of Ulm have found that eavesdroppers can intercept and use authentication tokens sent between Android apps and Google services via unsecured Wi-Fi. Those tokens, which aren’t tied to specific devices or sessions, can be used to peek at and tweak a user’s email, contacts, and calendar. Devices running Android 2.3.3 or earlier (which accounts for the vast majority of phones) are most vulnerable, but there are steps devs, Google, and users can take to reduce the risks.”

Read more of this story at Slashdot.


See the original article here:
Swiped Tokens Expose Android Devices To Data Theft

Written by Staff in: Slashdot | Tags:

No Comments

Comments are closed.

RSS feed for comments on this post. TrackBack URL


adsense

Cool-O-Rama: News for Geeks