A bit about mobile electronics

A Google G1 Security Vulnerability Made Public by Charles A. Miller

 

 

android-300x300With the similarities between smartphones and Personal Computers, the sorts of security vulnerabilities that infect PCs are sure to create issues with handheld devices as well.  ‘Open source’ projects are especially vulnerable, using ‘free software’ to spread viruses and other malicious software.  T-Mobile’s Google G1 is nothing special to escape what threatens all computer systems, both stationary and mobile.

Charles A. Miller comes out to alert consumers of malicious software threats to smartphones after being one of the researchers to discover vulnerabilities to the Google G1 just days after the debut of Google’s G1 phone.  Mr. Miller is an expert researcher, being a former National Security Agency computer security specialist.

According to Miller, attackers could trick the G1 users into visiting a website that acts as a trap, exploiting the vulnerabilities of the G1.

The Web browser is the item to attack by making it possible, according to Miller, for software to be downloaded by G1 that would take snap shots of browsing habits and keys punched in.  This would allow secure data like passwords and account numbers to be copied and used.

Google execs pretty much shrugged off the threat by mentioning a key difference between the Google G1 and other smartphones.  The G1 creates compartments that make applications separate, thus limited the invasion to one application.

The folks at Google weren’t too happy with Miller, who had won $10,000 from a contest at a security conference by exploiting Apple’s Safari by directing a Mac laptop to a booby-trapped website, and mentioned that researchers should give companies time to fix vulnerability before going public.  Mr. Miller sided with consumers and decided to make it public before but withheld details of how the vulnerability can be exploited…sorry hackers.

Source:  New York Times

Leave a Reply

Secured for spam by MLW and Associates, LLP's Super CAPTCHASecured by Super-CAPTCHA © 2009-2010 MLW & Associates, LLP. All rights reserved.