Skip to main content

Nearly all Android phones ‘leak’ sensitive personal data, tests show

Google Android LogoGoogle’s privacy woes just got worse. According to a study by researchers at a German university, more than 99 percent of all smartphones that run Google‘s Android operating system can easily be infiltrated by mobile hackers. The attackers can then use the “leaked” data to impersonate the rightful user, and access online accounts, such as Google Calendar, Twitter and Facebook.

According to the University of Ulm researchers, Bastian Konings, Jens Nickels, and Florian Schaub, the Android vulnerability is due to an improper implementation of the ClientLogin protocol, which is used in Android versions 2.3.3 and earlier, reports The Register. Once a user submits his or her login information, ClientLogin receives an authentication token that is sent as a cleartext file. Because the authentication token (authToken) can be used repeatedly for up to 14 days, hackers can access the information stored in the file, and use it to do their nefarious bidding.

“We wanted to know if it is really possible to launch an impersonation attack against Google services and started our own analysis,” write the researchers on their blog. “The short answer is: Yes, it is possible, and it is quite easy to do so. Further, the attack is not limited to Google Calendar and Contacts, but is theoretically feasible with all Google services using the ClientLogin authentication protocol for access to its data APIs.”

As bad as this sounds — indeed, is — for Android users, this type of attack can only be waged when the Android device is using an unsecured network, like a Wi-Fi hotspot, to send data. The researchers say hackers could wage such an attack when a device is connected to a network that is under their control.

“To collect such authTokens on a large scale an adversary could setup a wifi access point with a common SSID (evil twin) of an unencrypted wireless network, e.g., T-Mobile, attwifi, starbucks,” write the researchers. “With default settings, Android phones automatically connect to a previously known network and many apps will attempt syncing immediately. While syncing would fail (unless the adversary forwards the requests), the adversary would capture authTokens for each service that attempted syncing.”

The researchers suggest a number of ways to fix the issue, for app developers, Google and Android users alike. Developers whose apps use ClientLogin “should immediately switch to https,” the researchers say. And Google should limit the life of the authentication token, and restrict automatic connects to protected networks only. Android users should update their devices to 2.3.4 as soon as possible, they say, as well as turn off automatic sync when connecting with Wi-Fi, or avoid unsecured Wi-Fi networks entirely.

Andrew Couts
Former Digital Trends Contributor
Features Editor for Digital Trends, Andrew Couts covers a wide swath of consumer technology topics, with particular focus on…
Samsung Galaxy S24 Ultra vs. S22 Ultra: Should you upgrade?
Samsung Galaxy S24 Ultra in Titanium Gray in hand.

The Samsung Galaxy S24 Ultra is one of the best Android smartphones on the market. But back in 2022, that honorable title went to the Samsung Galaxy S22 Ultra. Even though the latter came out over two years ago, it’s still an incredible mobile device that’s jam-packed with features, including an awesome camera system. How much better is the S24 Ultra though? Fortunately, we know a thing or two about both Samsung phones, so we thought we’d compare both models for you.

As you can probably guess, the S24 Ultra does come out on top in terms of the latest and greatest tech. When you start considering performance though, the S22 Ultra doesn’t really lag behind the newest Galaxy phone too much. Let’s break things down into multiple categories to get a better idea of the pros and cons. 
Galaxy S24 Ultra vs. S22 Ultra: specs

Read more
Samsung Galaxy Ring: news, rumored price, release date, and more
Three sizes of the Samsung Galaxy Ring, sitting on top of a white display case.

The smart ring market has been dominated by the Oura Ring so far, but that is about to change with the upcoming launch of the Samsung Galaxy Ring. The ring was teased at Samsung's Unpacked event in January and then again at Mobile World Congress (MWC) in February.

The Galaxy Ring is expected to come with various health sensors to help you track your physical fitness and daily activities — all with the backing of Samsung Health. It's one of the most highly anticipated releases of the year, and this is everything we know about it (so far).
Samsung Galaxy Ring: release date

Read more
Did you buy a Google Pixel 8a? These are the first 9 things you need to do
Google Pixel 8a in Aloe.

Ahead of Google I/O 2024, Google revealed the Google Pixel 8a, and it’s turning out to be one of the best phone values in a while. It boasts a beautiful OLED display that now sports a 120Hz refresh rate, the Tensor G3 chip, Gemini Nano, a larger battery, wireless charging, and a refreshed design with some fun new colors. In short, there's a lot to dig into.

There is definitely a lot to like about the Google Pixel 8a, and as such, we don't blame you if you aren't sure where to start. If you just picked one up, then make sure you do these things first!
Turn on Smooth Display

Read more