• Home
  • Reviews
  • Featured
  • Archives
  • Videos
  • Devices
  • Tegra
  • Send Tips
  • Contact
  • AndroidCommunity on Twitter AndroidCommunity on Facebook AndroidCommunity on Google+ AndroidCommunity RSS Feed

Android Community

    • MUST READ

      STORIES

    • Chrome Beta updated with Translation bar and fullscreen tablet support

      May 23, 2013

    • HTC One ‘Senseless Edition’ could arrive this summer

      May 23, 2013

    • HTC One sales are strong as it passes 5 million mark

      May 23, 2013

  • Trending Topics
  • Jelly Bean
  • NVIDIA
  • Galaxy S 4
  • HTC One
  • Nexus 7
  • Sell Your Used Phone

HTC software bug leaks WiFi passwords on some Android phones

2
  • By Michael Crider
  • on 2 Feb, 2012



The last few months have not been kind to HTC on the security and privacy front. First there was a bug in HTC’s Sense skin that allowed for remote file access on a handful of smartphones, then the whole Carrier IQ debacle, which was demonstrated mostly on HTC’s hardware. The latest snafu was uncovered by the United States Computer Emergency Readiness Team, which states that a considerable amount of HTC phones are running flawed software that allows third-party applications access to encrypted WiFi passwords. The US-CERT team published their findings on the Homeland Security website yesterday.

The flaw is a minor one, allowing any application access to stored SSID passwords by using the “android.permission.INTERNET” permission. Affected phones tested by the researchers include the Desire HD, Glacier (T-Mobile MyTouch 4G), Droid Incredible, Sensation 4G, ThunderBolt, Desire S, EVO 3D and EVO 4G. While US-CERT recommends visiting the HTC support website for update instructions, HTC has said nothing as of yet about the security hole. Based on their behavior with the last security alert, you can expect them to update the affected handsets within the next few weeks.

Users shouldn’t panic: there’s been no documented case of apps or malware taking advantage of this loophole as of yet, and it would take some doing for an unscropilous developer to take advantage of it for personal gain. That said, it might be best to delete stored WiFi SSDs until the update and rely on a 3G or 4G connection for data, especially if you access sensative networks at home or at work. US-CERT notes that the Nexus One and T-Mobile MyTouch 3G (HTC Hero), both of which run mostly unmodified Android code, do not suffer from this issue. That means that if you’re running a custom ROM built from Android’s open-source packages, you’re probably safe as well.

[via PhysOrg]
Share
  • Samsung Galaxy Note 3 with Android 4.3 spotted in benchmark results
  • Verizon HTC One running Android 4.2.2 could be coming soon
  • Verizon HTC One tipped for CTIA event unveiling

Tags: htcprivacysecurityWiFi

  • http://profile.yahoo.com/25CJAVVTXVFVDTA6ONAV3TJB3E sab1024

    Thanks for the tip. On other topic: remember to use spell check. Kind of diminishes your cred with these spelling errors.

  • Anonymous

    Wow they need to fix their issues. First they screw over Carrier IQ and now this…

  • Search

  • REVIEWS

    • AT&T LG Optimus G Pro ReviewAT&T LG Optimus G Pro Review
    • Iron Man 3 game Review: what you need to knowIron Man 3 game Review: what you need to know
    • Samsung GALAXY S 4 ReviewSamsung GALAXY S 4 Review
    • Samsung Galaxy Note 8.0 ReviewSamsung Galaxy Note 8.0 Review
    • Pebble review: Two weeks with a smartwatchPebble review: Two weeks with a smartwatch
  • HANDS-ON & QUICK LOOKS

    • Coolpad Quattro II 4G and 8920 hands-onCoolpad Quattro II 4G and 8920 hands-on
    • Kyocera Hydro XTRM and EDGE hands-onKyocera Hydro XTRM and EDGE hands-on
    • Opera for Android exits beta, we go hands onOpera for Android exits beta, we go hands on


  • T-Mobile G1 Accessories
  • RECENT COMMENTS

  • About
  • Contact
  • Terms of Use
  • Privacy Policy
  • Advertise

Copyright 2013 Android Community