ie8 fix
madison

Networking

Steven J. Vaughan-Nichols

Google is patching the Android security hole

By | May 20, 2011, 10:48am PDT

Summary: Just don’t ask us how Google is repairing its Android Wi-Fi network security problem.

In the wake of the revelation that there’s a huge security hole in Android’s Wi-Fi communications with Google applications, Google told me and other journalists on May 18th that, “Today we’re starting to roll out a fix which addresses a potential security flaw that could, under certain circumstances, allow a third party access to data available in calendar and contacts. This fix requires no action from users and will roll out globally over the next few days.” Fair enough, but how?

Specifically, I asked Google, “Is this a server-side fix? A client-side fix that will be rolled out as an automatically applied patch? A change in the client settings to force the use of a secure connection? Some combination of all these? Will this ‘fix’ be deployed to other apps that use ClientLogin [the routine that has the security problem]? Is it a ‘fix’ to ClientLogin? Any details on how the fix will be deployed? In the U.S. first? Via the various carriers? OEMs?”

And Google answered, well, actually they never did answer. Darn it!

So, here’s what I think Google is doing. I believe it must be a server-side fix since that’s the one way Google can roll it out quickly and without getting the phone carriers and OEMs involved. The easiest way to do that is to simply disallow ClientLogin from working over any open, non-secured Wi-Fi connection. It’s a kludge, but it should work.

At least, unlike Apple with its growing Mac Defender malware problem, Google admits to the problem and is addressing it. Apple still isn’t even allowing its technical support staff to tell users how to rid themselves of malware.

If, as I suspect, Google is handling this on the server side, I believe the Android hole should be closed up within the week. I just wish I knew more about exactly how Google is going about this. Google? The ball is in your court now.

Related Stories:

Android has a gaping network security hole

The truth about the latest Google Android security scare (Updated)

99.7% of all Android smartphones vulnerable to serious data leakage

Most Android devices vulnerable to identity theft

Connect to a PPTP VPN from your Android phone

Kick off your day with ZDNet's daily e-mail newsletter. It's the freshest tech news and opinion, served hot. Get it.

Topics

Steven J. Vaughan-Nichols, aka sjvn, has been writing about technology and the business of technology since CP/M-80 was the cutting edge, PC operating system

Disclosure

Steven J. Vaughan-Nichols

Steven J. Vaughan-Nichols is a freelance writer. He does not own stocks or other investments in any technology company.

Biography

Steven J. Vaughan-Nichols

Steven J. Vaughan-Nichols, aka sjvn, has been writing about technology and the business of technology since CP/M-80 was the cutting edge, PC operating system; 300bps was a fast Internet connection; WordStar was the state of the art word processor; and we liked it.

His work has been published in everything from highly technical publications (IEEE Computer, ACM NetWorker, Byte) to business publications (eWEEK, InformationWeek, ZDNet) to popular technology (Computer Shopper, PC Magazine, PC World) to the mainstream press (Washington Post, San Francisco Chronicle, BusinessWeek).

20
Comments

Join the conversation!

Just In

RE: Google is patching the Android security hole
FAULKNE 13th Oct
Good day to confirm this comment I would appreciate T h e b e s t o f Z D N e t d e l i v e r e d your website very nice to everyone Yes, Oracle is the only one with shared-disk architecture, but that is there advantage. It means you can add or remove nodes and the database lives on. In a shared nothing architecture, if you lose a node, you lose the system. I'm sure Oracle appreciates EMC highlighting their advantage.I also desire to signal in your RSS feeds. Thank you as soon as once again and maintain up the great operate Awesome post! Thank you very much || thanks for nice content this is really benefit to me.
0 Votes
+ -
Kudos to Google for acknowledging the flaw
facebook@... 20th May 2011
The challenge for Google now is to effectively deliver the security update to its disparate customer base. How rapidly will we see machines being updated?
0 Votes
+ -
RE: Google is patching the Android security hole
LoverockDavidson 20th May 2011
@facebook@...
If they are Verizon customers then 4 - 6 months sounds about right.
@facebook@... ... malware totally misses, since it has nothing to do with Apple's software problems (there is no error in the software).
0 Votes
+ -
I disagree
facebook@... Updated - 20th May 2011
@denisrs

Google acknowledges the flaw, Apple pretends theirs does not exist.

When the Exxon Valdez damaged the Alaskan coast, Exxon did everything within its power to deflect blame and liability from themselves. When Tylenol had their issue with bottle tampering, Tylenol was front and center, doing everything within its power to mitigate the issue.

Although it is too soon to tell if Google will behave with the corporate responsibility that Tylenol had, in this case Apple is certainly Exxon.
0 Votes
+ -
@facebook: there is nothing Apple can do if users willfully want to install malware.
0 Votes
+ -
not a fix
IE9 Updated - 20th May 2011
Looks to me that they are only solving the issue for certain google services like mail and calender and that the vunerability will still exist for other apps, like it will still exist for Picasa
0 Votes
+ -
...to get things patched on their end (I think they'll be a bit more motivated than usual), but the server side fix is a start.
0 Votes
+ -
How?
tk_77 21st May 2011
The easiest way to do that is to simply disallow ClientLogin from working over any open, non-secured Wi-Fi connection. https).

This could explain why Picasa wont be fixed in this, if the code used to access the system on the client side doesn't support redirection (hard coded urls, not following redirect replies), or that it simply sends along its authorization information without even hitting the system first.
0 Votes
+ -
medical transc
Viralseoservices Updated - 22nd May 2011
security is an important issue now

posted : http://www.medicaltranscriptionservicecompany.com
0 Votes
+ -
Has their been any acknowledgement from Google on the coincidence that several Google/Android users are having trouble with gmail/calendars not syncing with their phones since this 5/21-22?
What a nightmare!
Okay.......2 months have passed. Anybody know the status of Google's "fix"????
I also desire to signal in your RSS feeds. Thank you as soon as once again and maintain up the great operate! nccma cooler
I used to be more than happy to seek out this internet-site.I wanted to thanks in your time for this glorious read!! I positively enjoying each little bit of it and I have you bookmarked to check out new stuff you weblog post. this thread is amazing i like your work and i appreciate you that you have share a useful stuff thanks for sharing the i shop abatwa
I used to be more than happy to seek out this internet-site.I wanted to thanks in your time for this glorious read!! I positively enjoying each little bit of it and I have you bookmarked to check out new stuff you weblog post.Bookmarking now thanks please consider a follow up post. power sa shop
I think the representation of this article is actually superb one. This is my first visit to your site. Thanks a lot and keep sharing the information. Keep updating the information for all of us. Thanks ZDNet Government was launched as the brand's first industry vertical, with a mission to cater to IT professionals in the public secto I agree with your post. However, do you have any sources I can cite for my paper wheel car com bury
Well welcome, hopefully you can become a vital member of the community and really help to push far ahead of google. Which Im sure the development team would love. This will of course earn you alot points too and get you on the leaders board. z d n e t t h a n k Im not sure i come to an agreement with you on every level, howevor it absolutely was a good posting, many thanks for taking the time to put up your ideas.
I like this kind mutual communication very much. I can learn much from that. The opinion that everyone gives also can be as useful information. Steel Pipe Supplier
Thanks nice info z d n e t I really liked your current article write more..let me add you to its favorite The articles you have on zdnet s i t e are always so enjoyable to read. Good work and I bookmarked it.
Fantastic news about the new release.I positively enjoying each little bit of it and I have you b o o k m a r k e d to check out new stuff you weblog post.Im not sure i come to an agreement with you on every level, howevor it absolutely was a good posting, many thanks for taking the time to put up your ideas
Good day to confirm this comment I would appreciate T h e b e s t o f Z D N e t d e l i v e r e d your website very nice to everyone Yes, Oracle is the only one with shared-disk architecture, but that is there advantage. It means you can add or remove nodes and the database lives on. In a shared nothing architecture, if you lose a node, you lose the system. I'm sure Oracle appreciates EMC highlighting their advantage.I also desire to signal in your RSS feeds. Thank you as soon as once again and maintain up the great operate Awesome post! Thank you very much || thanks for nice content this is really benefit to me.

Join the conversation!

Formatting +
BB Codes - Note: HTML is not supported in forums
  • [b] Bold [/b]
  • [i] Italic [/i]
  • [u] Underline [/u]
  • [s] Strikethrough [/s]
  • [q] "Quote" [/q]
  • [ol][*] 1. Ordered List [/ol]
  • [ul][*] · Unordered List [/ul]
  • [pre] Preformat [/pre]
  • [quote] "Blockquote" [/quote]
ie8 fix
Click Here
ie8 fix

The best of ZDNet, delivered

ZDNet Newsletters

Get the best of ZDNet delivered straight to your inbox

Facebook Activity

White Papers, Webcasts, & Resources
ie8 fix
ie8 fix