Jump to content
Sign In to follow this  
A Nonny Moose

Android Apps "leak"

7 posts in this topic Last Reply

Highlighted Posts

Posted:
Last Online:  
 

"What one fool can do, another fool can do." - Sylvanus P. Thompson.

Seems there are some security issues. Some of this could be attributed to inexperienced programmers when it comes to apps. However, if Android itself is the culprit, shame on Google.


Beware: Emancipated user.  No Windoze for me.
The teacher opens the door but the student must enter himself. - Ancient Chinese Saying

Every minute of hate in which one indulges oneself is sixty seconds of happiness lost.
Music expresses that which cannot be put into words and that which cannot remain silent. -- Victor Hugo
If you always do what you've always done, you'll mostly get what you've always got.
JohnNewSig.gif
"We have met the enemy, and he is us" - Walt Kelly

Come join us at the Moose Factory

Share this post


Link to post
Share on other sites
Posted:
Last Online:  
 

Sounds like this is a vulnerability with the apps themselves, not the OS. So, that means it's on the app developers.

Of course, if they were doing it right, they would have named the apps they tested and which ones were found to have vulnerabilities. You don't do the public any service if you keep that secret!

This, as far as I am concerned, is also a great reason why handling banking from your phone is not wise. If I want to transfer funds or anything like that, I go in person to my local bank. Because as far as I am concerned, the single best way to keep someone from hacking into my online banking account is to simply not have one. The way I do it, I entirely use the banks infrastructure, so if something screws up, they're liable.


If you always take the same road, you will never see anything new.
If you can read this, you deserve a cookie.

Share this post


Link to post
Share on other sites
Posted:
Last Online:  
 

Sounds like this is a vulnerability with the apps themselves, not the OS. So, that means it's on the app developers.

Of course, if they were doing it right, they would have named the apps they tested and which ones were found to have vulnerabilities. You don't do the public any service if you keep that secret!

This, as far as I am concerned, is also a great reason why handling banking from your phone is not wise. If I want to transfer funds or anything like that, I go in person to my local bank. Because as far as I am concerned, the single best way to keep someone from hacking into my online banking account is to simply not have one. The way I do it, I entirely use the banks infrastructure, so if something screws up, they're liable.

thats a good idea.


Stupidity Should Always be Painful

 

the only thing that helps me maintain my slender grip on reality is the friendship I share with my collection of singing potatoes.

Share this post


Link to post
Share on other sites
  • Original Poster
  • Posted:
    Last Online:  
     

    Actually, I do on-line banking over the Internet. My bank is in another town something like 50 Km from here, so it is a kind of forced put. Their security is very good, and the activities are over an https encrypted link. No one in Canada has reported a problem with the banks being hacked.


    Beware: Emancipated user.  No Windoze for me.
    The teacher opens the door but the student must enter himself. - Ancient Chinese Saying

    Every minute of hate in which one indulges oneself is sixty seconds of happiness lost.
    Music expresses that which cannot be put into words and that which cannot remain silent. -- Victor Hugo
    If you always do what you've always done, you'll mostly get what you've always got.
    JohnNewSig.gif
    "We have met the enemy, and he is us" - Walt Kelly

    Come join us at the Moose Factory

    Share this post


    Link to post
    Share on other sites
    Posted:
    Last Online:  
     

    The issue isn't hacking on the bank's end, it's hacking on your end.

    You've brought up a vulnerability with Android apps that means someone can steal your usernames and passwords. And that is definitely not the only such vulnerability out there!


    If you always take the same road, you will never see anything new.
    If you can read this, you deserve a cookie.

    Share this post


    Link to post
    Share on other sites
    Posted:
    Last Online:  
     

    Yeah, sounds like a conjunction of App and User problems. I, personally, don't use any Wi-Fi network that I don't trust when I have the option (I will choose using the Hotspot on my phone over a free Wi-Fi connection) and that's where the Researchers were able to get in and intercept the data.

    It's not rocket science to do this yourself, all you need is a Wireless Access Point, an Internet Gateway and a PC with Wireshark installed relaying the connection in the middle.

    Once again it's the whole "not encrypting data before sending/storing it" and I'm getting rather sick of hearing of it. Not Salting (Or using an encryption method better than MD5, come on) sensitive data is just plain laziness on the behalf of the programmers and an insult to users.


      Edited by jdenm8  

    Share this post


    Link to post
    Share on other sites
  • Original Poster
  • Posted:
    Last Online:  
     

    Well, while not excusing them, you really can't blame the programmers too much. They've got to learn, somehow. Writing any program is not a piece of cake and QA is not a walk in the park either.


    Beware: Emancipated user.  No Windoze for me.
    The teacher opens the door but the student must enter himself. - Ancient Chinese Saying

    Every minute of hate in which one indulges oneself is sixty seconds of happiness lost.
    Music expresses that which cannot be put into words and that which cannot remain silent. -- Victor Hugo
    If you always do what you've always done, you'll mostly get what you've always got.
    JohnNewSig.gif
    "We have met the enemy, and he is us" - Walt Kelly

    Come join us at the Moose Factory

    Share this post


    Link to post
    Share on other sites

    Sign In or register to comment...

    To comment in reply, you must be a community member

    Sign In  

    Already have an account? Sign in here.

    Sign In Now

    Create an Account  

    Sign up to join our friendly community. It's easy!  

    Register a New Account

    Sign In to follow this  

    ×

    Thank You for the Continued Support!

    Simtropolis depends on donations to fund site maintenance costs.
    Without your support, we just would not be in our 24th year online!  You really help make this a great community. *:thumb:

    But we still need your support to stay online. If you're able to, please consider a donation to help us stay up and running. This helps sustain a platform where we can share our community creations for years to come.

    Make a Donation, Get a Gift!

    Expand your city with the best from the Simtropolis Exchange.
    Make a Donation and get one or all three discs today!

    STEX Collections

    By way of a "Thank You" gift, we'd like to send you our STEX Collector's DVD. It's some of the best buildings, lots, maps and mods collected for you over the years. Check out the STEX Collections for more info.

    Each donation helps keep Simtropolis online, open and free!

    Thank you for reading and enjoy the site!

    More About STEX Collections