gyurisc

  • Random
  • Archive
  • RSS
  • Ask me anything

Cleartextben küldi az Android az Authentikációs tokeneket

A naptár és kontakt applikációk cleartextben küldik az authentikációs tokeneket. Ezek a tokenek 14 napig maradnak érvényben és a segítségével lehet olvasgatni mondjuk a naptárakat és a névjegyeket a google accountról! A cikk szerint 2.2től 2.3.4ig bezárólag érinti az összes Androidos telefont. Az enyém is ilyen sajnos :( Kiváncsi vagyok mennyi idő alatt jön ki a javítás. Addig is tartozkodni fogok a nyilvános wifizéstől a McDonaldsban!

To collect such authTokens on a large scale an adversary could setup a wifi access point with a common SSID (evil twin) of an unencrypted wireless network, e.g., T-Mobile, attwifi, starbucks. With default settings, Android phones automatically connect to a previously known network and many apps will attempt syncing immediately. While syncing would fail (unless the adversary forwards the requests), the adversary would capture authTokens for each service that attempted syncing. Due to the long lifetime of authTokens, the adversary can comfortably capture a large number of tokens and make use of them later on from a different location.

Nice!

via DaringFireball - Catching AuthTokens in the Wild The Insecurity of Google’s ClientLogin Protocol

    • #android
    • #security
    • #daringfireball
  • 1 year ago
  • Comments
  • Permalink
  • Tweet

Recent comments

Blog comments powered by Disqus
← Previous • Next →

About

Pages

  • Rólam

Me, Elsewhere

  • @gyurisc on Twitter
  • Facebook Profile
  • gyurisc on Youtube
  • gyurisc on github

Twitter

loading tweets…

I Dig These Posts

See more →
  • Photo via transittimes

    The TransitTimes+ for iOS storyboard, as at 22-May-2012

    Photo via transittimes
  • Photo via drkotasz
    Photo via drkotasz
  • Photo via builtwithbootstrap

    HNterest

    A Pinterest-like view for HackerNews stories

    Photo via builtwithbootstrap
  • Photo via lenardgabor

    dkitzinger:

    Reggelt!

    Photo via lenardgabor
  • Post via starsheep
    Rendszerváltók, takarodó!

    http://hirszerzo.hu/velemeny/2012/3/28/rendszervaltok_kiss_adam_I2M4V1

    Ideteszem, ez alá a smalladam-cikk alá a...

    Post via starsheep
  • RSS
  • Random
  • Archive
  • Ask me anything
  • Mobile

Effector Theme by Carlo Franco.

Powered by Tumblr