{"id":169725,"date":"2015-07-31T19:30:49","date_gmt":"2015-07-31T19:30:49","guid":{"rendered":"http:\/\/rinf.com\/alt-news\/?p=169725"},"modified":"2015-07-31T23:05:23","modified_gmt":"2015-07-31T23:05:23","slug":"giant-security-flaw-makes-950-million-android-phones-vulnerable-texting-hack","status":"publish","type":"post","link":"http:\/\/rinf.com\/alt-news\/sicence-technology\/giant-security-flaw-makes-950-million-android-phones-vulnerable-texting-hack\/","title":{"rendered":"Giant security flaw makes 950 million Android phones vulnerable to texting hack"},"content":{"rendered":"<p>Android is by far the most dominant smartphone operating system in the world, and it has just been found to be vulnerable to a serious smartphone security flaw which allows devices to be hacked by simply sending them a text message.<\/p>\n<div>\n<p>About 80 percent of smartphones worldwide run Android, and just about all of those have a major vulnerability in their software, according to experts at <a href=\"https:\/\/www.zimperium.com\/company\">Zimperium<\/a>, a cybersecurity company specializing in mobile devices.<\/p>\n<p>What makes this problem a gaping security hole is that the victims don\u2019t even need to be tricked into downloading or opening a bad file \u2014 attackers only need to send them a text message for the malware to take hold.<\/p>\n<div class=\"rtcode\">\n<blockquote class=\"twitter-tweet\" lang=\"en\">\n<p dir=\"ltr\" lang=\"en\">So apparently Android phones are going to be easy to hack just by text message.<\/p>\n<p>\u2013 Savage Storm (@SavageArtStorm) <a href=\"https:\/\/twitter.com\/SavageArtStorm\/status\/625811949985492992\">July 27, 2015<\/a><\/p><\/blockquote>\n<\/div>\n<p>The issue stems from the way Android processes incoming text messages. Media playback software utilized by Android, called Stagefright, processes media files, such as images or video, sent to your device before you even open the message. Hackers can hide malware in those files, getting Stagefright to automatically unleash them onto your phone, thus giving attackers unfettered access to copy and delete data or use the camera, microphone, and GPS to track your every move.<\/p>\n<p><em>\u201cThis happens even before the sound that you\u2019ve received a message has even occurred,\u201d<\/em> Joshua Drake, a security researcher with Zimperium,\u00a0<a href=\"http:\/\/www.npr.org\/sections\/alltechconsidered\/2015\/07\/27\/426613020\/major-flaw-in-android-phones-would-let-hackers-in-with-just-a-text\">told<\/a> NPR. <em>\u201cThat\u2019s what makes it so dangerous. [It] could be absolutely silent. You may not even see anything.\u201d<\/em><\/p>\n<p>The issue affects any phone using Android software released in the last five years, according to Zimperium. That includes devices running Android\u2019s alphabetically-coded versions, Froyo through Lollipop, which together account for 95% of the operating systems being used on all android phones \u2014 or 950 million devices.<\/p>\n<div class=\"rtcode\">\n<blockquote class=\"twitter-tweet\" lang=\"en\">\n<p dir=\"ltr\" lang=\"en\">This whole Android hack thing makes me glad when I&#8217;m using Windows. It&#8217;s like I have the Battlestar Galactica &amp; I&#8217;m immune to a Cylon virus<\/p>\n<p>\u2013 Matt (@clappenings) <a href=\"https:\/\/twitter.com\/clappenings\/status\/625782786956333056\">July 27, 2015<\/a><\/p><\/blockquote>\n<\/div>\n<p>Zimperium said that it privately warned Google of the flaw on April 9, and even provided them with a fix. The company claims Google responded within 48 hours, saying that the bug would be patched in the near future.<\/p>\n<p>Companies are often given a 90-day grace period to issue a fix in situations like this. It\u2019s a guideline that Google itself abides by when it finds flaws in others\u2019 software,\u00a0<a href=\"http:\/\/money.cnn.com\/2015\/07\/27\/technology\/android-text-hack\/\">according<\/a> to CNNMoney.<\/p>\n<p>Zimperium went public with the news because the fix hadn\u2019t been made available 109 days later.<\/p>\n<p>This is likely due to the fact that Android isn\u2019t a single operating system like Apple\u2019s iOS, making it difficult to address problems for the myriad devices using the operating system in one fell swoop. Google also has to deal with third parties such as phone carriers like Verizon, T Mobile and AT&amp;T, as well as hardware manufacturers like Samsung and HTC.<\/p>\n<div class=\"rtcode\">\n<blockquote class=\"twitter-tweet\" lang=\"en\">\n<p dir=\"ltr\" lang=\"en\">Good luck waiting for Google &amp; Carrier updates | Most Android phones at risk from simple text hack, researcher says <a href=\"http:\/\/t.co\/rvv0dEzlW9\">http:\/\/t.co\/rvv0dEzlW9<\/a><\/p>\n<p>\u2013 Jason O&#8217;Donoghue (@i_Jason) <a href=\"https:\/\/twitter.com\/i_Jason\/status\/625774629035114497\">July 27, 2015<\/a><\/p><\/blockquote>\n<\/div>\n<p>Google told CNNMoney that it has already sent a fix to these partners, but it remains to be seen if they have in turn released it to users themselves.<\/p>\n<\/div>\n<p>Via <a href=\"http:\/\/www.rt.com\/usa\/310907-giant-security-flaw-android\/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=RSS\">RT<\/a>.\u00a0This piece was reprinted by <a href=\"http:\/\/rinf.com\">RINF Alternative News<\/a> with permission or license.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Android is by far the most dominant smartphone operating system in the world, and it has just been found to be vulnerable to a serious smartphone security flaw which allows devices to be hacked by simply sending them a text message. About 80 percent of smartphones worldwide run Android, and just about all of those [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":169726,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[487,13,18],"tags":[],"class_list":{"0":"post-169725","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-breaking-news","8":"category-sicence-technology","9":"category-latest-news"},"_links":{"self":[{"href":"http:\/\/rinf.com\/alt-news\/wp-json\/wp\/v2\/posts\/169725","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/rinf.com\/alt-news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/rinf.com\/alt-news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/rinf.com\/alt-news\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/rinf.com\/alt-news\/wp-json\/wp\/v2\/comments?post=169725"}],"version-history":[{"count":0,"href":"http:\/\/rinf.com\/alt-news\/wp-json\/wp\/v2\/posts\/169725\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/rinf.com\/alt-news\/wp-json\/wp\/v2\/media\/169726"}],"wp:attachment":[{"href":"http:\/\/rinf.com\/alt-news\/wp-json\/wp\/v2\/media?parent=169725"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/rinf.com\/alt-news\/wp-json\/wp\/v2\/categories?post=169725"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/rinf.com\/alt-news\/wp-json\/wp\/v2\/tags?post=169725"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}