Showing posts with label Mobile. Show all posts
Showing posts with label Mobile. Show all posts

2015-07-02

Huge Samsung Galaxy security flaw

A bit late in blogging about this topic:
Samsung Galaxy S6, S5, S4 and S4 Mini phones have a massive flaw that allows an attacker to take over the device. It's in the keyboard code, of all places, thanks to a custom SwiftKey build. There are about 600 million of these things in circulation, it's thought.
The patch has been released now by Samsung.

2015-05-23

Android Factory Reset - Inefficient!

The default reset feature leaves behind traces of user's data, and password tokens for Google, Facebook, etc. Another very good reason to encrypt the devices!

2014-11-19

Whatsapp's Encryption

Update 19-Nov-14:
Whatsapp introduces end-to-end encryption for Android users. For iOS it is coming soon. This is one feat that is worthy of a standing ovation.

Update 08-Oct-2013:
A good article to explain how the popular IM, whatsapp encrypts the data, and why the algo is flawed. And how the client was disassembled.

2014-10-29

Android 5.0 Lollipop - Security!

Google has finally released the much awaited (at least by myself) Android L. Lets dive into the new security features, which seem very promising. A true attempt at better managing security with usability.

2014-08-12

PGP Inventor Announces Blackphone

An encrypted and hardened version of Android, by Phil Zimmerman!

A similar Boeing Blackphone launched.

Update 12-Aug-2014:  Gets rooted in less than 5 mins.

2014-08-11

Xiaomi Phones Sending User Data to Home Servers

Update 11-Aug-14:
Security Researchers from F-Secure Antivirus firm has shown that the Xiaomi phones (RedMi 1S handset) send quite a lot of personal and sensitive data to "api.account.xiaomi.com"  server located in China, including following information:
  • IMEI Number of your phone
  • IMSI Number (through MI Cloud)
  • Your contacts and their details
  • Text Messages
More details here and here.

Update 12-Aug-2014:
Xiaomi releases a statement

2014-05-28

Spotify hacked

Today, the popular Music streaming service Spotify said the company has suffered a Data breach and warned users of its Android app to upgrade it in the wake of a potential data breach in their servers.
Full Story 

Aussie Apple Fans Get Pawned

A mysterious new scam has emerged targeting Antipodean iPhone, iPad and iMac users by locking their devices via “Find My iPhone” technology and holding them to ransom.
Full Story  &  Troy Hunt's Analysis

2014-03-11

Sim card based end-to-end encryption

In collaboration with its security partner Giesecke & Devrient which is an international leader in mobile security solutions, Vodafone is offering an end-to-end encryption for mobile communication based on the phone SIM card.
Full Story

2014-02-10

Sochi Olympics hit the security news!

"The U.S. State Department has told Americans coming to Sochi that they should have 'no expectation of privacy,' 
For now, looks like USA is trying to make the Russians look bad, without any solid evidence

2014-01-25

Snapchat's security woes

First they lose 4.6 M accounts and now their new security feature gets broken in under 30 mins.

2014-01-16

Starbucks App stores password in cleartext - a 'known' feature

Unbelievable!
Two executives -- Starbucks CIO Curt Garner and Starbucks Chief Digital Officer Adam Brotman -- said in a telephone interview that they have known for an unspecified period of time that the credentials were being stored in clear text. "We were aware," Brotman said. "That was not something that was news to us."

2014-01-12

Hackers expose phone information of 4.6M Snapchat users

The original website of the hackers has been taken down, I paste their message below.
More info here and here.

You are downloading 4.6 million users' phone number information, along with their usernames. People tend to use the same username around the web so you can use this information to find phone number information associated with Facebook and Twitter accounts, or simply to figure out the phone numbers of people you wish to get in touch with. 
This database contains username and phone number pairs of a vast majority of the Snapchat users. This information was acquired through the recently patched Snapchat exploit and is being shared with the public to raise awareness on the issue. The company was too reluctant at patching the exploit until they knew it was too late and companies that we trust with our information should be more careful when dealing with it. 
For now, we have censored the last two digits of the phone numbers in order to minimize spam and abuse. Feel free to contact us to ask for the uncensored database. Under certain circumstances, we may agree to release it

2013-09-20

Google knows YOUR WiFi Password!

Google has access to clear-text wifi passwords. Now considering there are 900 Million+ android devices, and each device would have multiple wifi passwords stored on them - do the maths!
Meaning all the good folks at NSA need to do is but send a request to Google asking for the wifi password of anyone, so that they could snoop in on their computers

2013-07-22

Millions of mobile sim cards vulnerable!

Mobile sim cards, which are still on the old technology, with DES encryption are all vulnerable to an attack



2013-07-12

India VS RIM

I thought I had blogged about the Government of India and Blackberry's RIM debate. But, I can't find it now. Basically the government is pressurizing for something that does not exist.

Update: 06-Jan-13
RIM gives in and sets up a monitoring facility for the Govt of India.

Update: 12-Jul-13:
Looks like BB/RIM finally gave in to the demands of the Indian Govt. But, earlier didn't they say they do not have access to the encryption keys, so how does this magic happen now?!

2013-07-09

99% of Android Devices Vulnerable

Impact:  Every device sold since Android 1.6 (Donut); that is, nearly 900 million device
[Quote] The vulnerability is a code signing flaw. Developer's 'sign' their apps with a cryptographic signature. That way, only the app developer is able to update or modify an existing app, because only the developer has the signature. Bluebox has discovered a way to subvert this. "This vulnerability makes it possible to change an application’s code without affecting the cryptographic signature of the application
Blog from the Bluebox - a new player in the market

Update 17-Jul-13: 
A second similar master-key vulnerability has been discovered.

2013-05-27

Sky news apps defaced!

Update 27-May-2013
Hackers break into Android apps of a Sky News??!!! Looking for some more details here.

Update 28-May-2013
This explains the matter better.