Discover
/
Article

Android handsets leak personal data

MAY 18, 2011
Physics Today
BBC : Nearly all phones that run Google’s Android operating system are leaking data used to access web-based services. Many applications installed on the phones interact with Google services by asking for an authentication token—a digital ID card for that application. Once issued, that token stays active and users aren’t prompted to log in again for a certain length of time. These tokens are sometimes sent over wireless networks in plain text, which makes them easy to find and steal for anyone eavesdropping on wi-fi traffic. The tokens aren’t bound to individual phones or times of use, so they could potentially be used to impersonate a handset anywhere. Bastian Konings of the University of Ulm and colleagues, made the discovery when they investigated how Android phones handle login credentials for web-based services. Google has not yet commented on the loophole uncovered by the team.
Related content
/
Article
/
Article
The availability of free translation software clinched the decision for the new policy. To some researchers, it’s anathema.
/
Article
The Nancy Grace Roman Space Telescope will survey the sky for vestiges of the universe’s expansion.

Get PT in your inbox

pt_newsletter_card_blue.png
PT The Week in Physics

A collection of PT's content from the previous week delivered every Monday.

pt_newsletter_card_darkblue.png
PT New Issue Alert

Be notified about the new issue with links to highlights and the full TOC.

pt_newsletter_card_pink.png
PT Webinars & White Papers

The latest webinars, white papers and other informational resources.

By signing up you agree to allow AIP to send you email newsletters. You further agree to our privacy policy and terms of service.