Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

HTC Gaping Security Hole

Thread Tools
 
Search this Thread
 
Old 03 October 2011, 08:22 PM
  #1  
JackClark
Scooby Senior
Thread Starter
 
JackClark's Avatar
 
Join Date: Dec 2000
Location: Overdosed on LCD
Posts: 20,852
Received 51 Likes on 34 Posts
Default HTC Gaping Security Hole

This is what happens when you trust your data to a company with very little software experience. Some devices mentioned in the article, more being found.

Exposed data includes
  • The list of user accounts, including email addresses
  • A log of recent GPS locations
  • Phone numbers taken from recent call logs
  • SMS data, including recent numbers and encoded messages

Encouraging news from HTC "We will provide an update as soon as we're able to determine the accuracy of the claim and what steps, if any, need to be taken." good luck getting the updates out.



http://www.bbc.co.uk/news/technology-15149588
Old 03 October 2011, 08:49 PM
  #2  
jsh1
Scooby Regular
iTrader: (1)
 
jsh1's Avatar
 
Join Date: Aug 2008
Location: Warwickshire
Posts: 280
Likes: 0
Received 0 Likes on 0 Posts
Default

I am not going down the whole Android vs iOS route again, but this does highlight a significant advantage of Apple's "closed" approach to Apps and approving every one before release.

The "open" Android approach does leave you somewhat exposed to potential security risks.

Jason
Old 03 October 2011, 09:01 PM
  #3  
jonc
Scooby Regular
 
jonc's Avatar
 
Join Date: Apr 2002
Posts: 7,635
Likes: 0
Received 18 Likes on 13 Posts
Default

Yes, good job Apple have everything covered
http://www.informationweek.com/news/...ties/231601766
Old 03 October 2011, 11:38 PM
  #4  
JackClark
Scooby Senior
Thread Starter
 
JackClark's Avatar
 
Join Date: Dec 2000
Location: Overdosed on LCD
Posts: 20,852
Received 51 Likes on 34 Posts
Default

Originally Posted by jonc
Yes, good job Apple have everything covered
http://www.informationweek.com/news/...ties/231601766
This isn't a security pissing contest Jon, we can all dig out past articles.
Old 04 October 2011, 12:21 AM
  #5  
bioforger
Scooby Regular
iTrader: (1)
 
bioforger's Avatar
 
Join Date: Jan 2002
Location: Pig Hill, Wiltsh1te
Posts: 16,995
Received 5 Likes on 5 Posts
Default

lol not a pissing contest and yet you post up anything -ve against droid as soon as it hits the media.
Old 04 October 2011, 07:40 AM
  #6  
Saint AAI
Scooby Regular
 
Saint AAI's Avatar
 
Join Date: Mar 2005
Posts: 964
Likes: 0
Received 0 Likes on 0 Posts
Default

As far as I'm aware there are no malicious apps that use that exploit currently and HTC have acknowledged the bug and are going to roll out updates to close the hole shortly. Nothing to be worried about, you can easily fix it yourself by removing the HTC logging app.
Old 04 October 2011, 09:27 AM
  #7  
JackClark
Scooby Senior
Thread Starter
 
JackClark's Avatar
 
Join Date: Dec 2000
Location: Overdosed on LCD
Posts: 20,852
Received 51 Likes on 34 Posts
Default

Just how do you "easily" fix it yourself? Run a dodgy program?

Best advice is to not even try fixing it yourself, just be very, very careful choosing apps to install and have a good think about ones that you've already installed. Wake up call for a clean out of unwanted apps.

Take the post how you want @bioforger, I certainly appreciate valid security alerts regarding my products, people pay good money for a service like that.

Trending Topics

Old 04 October 2011, 10:12 AM
  #8  
Saint AAI
Scooby Regular
 
Saint AAI's Avatar
 
Join Date: Mar 2005
Posts: 964
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by JackClark
Just how do you "easily" fix it yourself? Run a dodgy program?
Just uninstall the HTC logging app. You do need root access to do it though as it's a system app built into the HTC ROM. I use a custom ROM so it's not there anyway.
Old 04 October 2011, 10:41 AM
  #9  
Scooby Soon!
Scooby Regular
 
Scooby Soon!'s Avatar
 
Join Date: Sep 2002
Posts: 2,551
Likes: 0
Received 0 Likes on 0 Posts
Default

hopefully my galaxy s2 will be fine It seems all the phones with the possible problem are USA phones?

as always best advice is to avoid weird obscure apps and you will be fine.
Old 04 October 2011, 11:19 AM
  #10  
jonc
Scooby Regular
 
jonc's Avatar
 
Join Date: Apr 2002
Posts: 7,635
Likes: 0
Received 18 Likes on 13 Posts
Default

Originally Posted by JackClark
This isn't a security pissing contest Jon, we can all dig out past articles.
I know it isn't, but your opening post would suggest otherwise. Besides, the reality is we all know is that OSX is no more secure than the latest Windows OS. Having a smaller market share does not make OSX more secure. The article I posted is relatively current as I understand it and still remains unpatched.

When you put your personal data in the trust of a company that has vast experience in producing software designed specifically for their hardware, it's encouraging to know that there are still people out there who highlight the major vulnerabilities that exist in their software. You will of course appreciate the validity of this security vulnerability in OSX and this service comes free of charge and is not included in the premium you pay on Apple products

Last edited by jonc; 04 October 2011 at 11:22 AM.
Old 04 October 2011, 12:06 PM
  #11  
chris84
Scooby Regular
iTrader: (1)
 
chris84's Avatar
 
Join Date: Aug 2010
Location: W Yorkshire
Posts: 521
Likes: 0
Received 0 Likes on 0 Posts
Default

It's not fair to compare the different approaches used for the app stores of both Android and Apple in this instance.

The bug is within HTCs shipped ROM and not an application downloaded from the market. Most software is shipped with some kind of bugs hence updates. Neither Apple, Android or Windows are perfect.

I'm not giving examples, it's not a fight.

People who own and like the iphone will always have biased opinions. Just like I'm sure most on here would agree that an Impreza is better than an Evo
Old 04 October 2011, 12:16 PM
  #12  
GazTheHat
Scooby Regular
 
GazTheHat's Avatar
 
Join Date: Aug 2005
Location: 392/361 MY04 STi
Posts: 7,638
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by bioforger
lol not a pissing contest and yet you post up anything -ve against droid as soon as it hits the media.
So true.
Old 04 October 2011, 12:24 PM
  #13  
Tidgy
Scooby Regular
 
Tidgy's Avatar
 
Join Date: Sep 2004
Location: Notts
Posts: 23,118
Received 150 Likes on 115 Posts
Default

droid aint perfect, apple aint perfect, job done.

whats next?
Old 04 October 2011, 12:47 PM
  #14  
JackClark
Scooby Senior
Thread Starter
 
JackClark's Avatar
 
Join Date: Dec 2000
Location: Overdosed on LCD
Posts: 20,852
Received 51 Likes on 34 Posts
Default

Originally Posted by Saint AAI
Just uninstall the HTC logging app. You do need root access to do it though as it's a system app built into the HTC ROM. I use a custom ROM so it's not there anyway.
Gibberish.
Old 04 October 2011, 12:52 PM
  #15  
JackClark
Scooby Senior
Thread Starter
 
JackClark's Avatar
 
Join Date: Dec 2000
Location: Overdosed on LCD
Posts: 20,852
Received 51 Likes on 34 Posts
Default

Originally Posted by jonc
I know it isn't, but your opening post would suggest otherwise.
I'd change Gaping if I could. But it's still a valid post. Yours on the other hand is old tripe, gleaned from the blog of a publicity hungry security company. It's old news, yes people should know that you can reset passwords, have been able to since I can remember, no it's not a valid link to be posting on this particular thread.
Old 04 October 2011, 01:18 PM
  #16  
Saint AAI
Scooby Regular
 
Saint AAI's Avatar
 
Join Date: Mar 2005
Posts: 964
Likes: 0
Received 0 Likes on 0 Posts
Default

Not gibberish at all. People can wait for HTC to release the update which will be over the air so easy and painless, something iOS users will be able to do soon . For people who don't want to wait and are worried about a very minor security bug, they can sort it themselves. I say minor as there are no reports of anyone being a victim of this exploit and it is highly likely that no one will be.

Originally Posted by HTC
HTC takes claims related to the security of our products very seriously. In our ongoing investigation into this recent claim, we have concluded that while this HTC software itself does no harm to customers' data, there is a vulnerability that could potentially be exploited by a malicious third-party application. A third party malware app exploiting this or any other vulnerability would potentially be acting in violation of civil and criminal laws. So far, we have not learned of any customers being affected in this way and would like to prevent it by making sure all customers are aware of this potential vulnerability.

HTC is working very diligently to quickly release a security update that will resolve the issue on affected devices. Following a short testing period by our carrier partners, the patch will be sent over-the-air to customers, who will be notified to download and install it. We urge all users to install the update promptly. During this time, as always, we strongly urge customers to use caution when downloading, using, installing and updating applications from untrusted sources.
Source
Old 04 October 2011, 01:27 PM
  #17  
TonyBurns
Scooby Regular
iTrader: (3)
 
TonyBurns's Avatar
 
Join Date: Aug 2000
Location: 1600cc's of twin scroll fun :)
Posts: 25,565
Likes: 0
Received 2 Likes on 2 Posts
Default

Hey its Jack and apple do nothing wrong
Oh wasnt it quite recently that apple logged all your locations and you could do nothing about it, well as we see, no one is perfect and HTC acknowledge that.
So, unless you can really come up with something different Jack, I wouldnt post gibberish as you put it

Tony
Old 04 October 2011, 01:34 PM
  #18  
JackClark
Scooby Senior
Thread Starter
 
JackClark's Avatar
 
Join Date: Dec 2000
Location: Overdosed on LCD
Posts: 20,852
Received 51 Likes on 34 Posts
Default

Originally Posted by TonyBurns
Hey its Jack and apple do nothing wrong
Oh wasnt it quite recently that apple logged all your locations and you could do nothing about it, well as we see, no one is perfect and HTC acknowledge that.
So, unless you can really come up with something different Jack, I wouldnt post gibberish as you put it

Tony
Save your fingertips Tony, you're living in the past.
Old 04 October 2011, 01:37 PM
  #19  
bigsinky
Scooby Regular
 
bigsinky's Avatar
 
Join Date: Dec 2002
Location: Sunny BELFAST
Posts: 19,408
Likes: 0
Received 0 Likes on 0 Posts
Default

awwwwww Jack you make me smile.........
Old 04 October 2011, 02:00 PM
  #20  
Ant
Scooby Regular
 
Ant's Avatar
 
Join Date: Jun 2008
Location: Notts
Posts: 9,243
Likes: 0
Received 0 Likes on 0 Posts
Default

Reel em in jack , you got a big catch today
Old 04 October 2011, 02:43 PM
  #21  
jonc
Scooby Regular
 
jonc's Avatar
 
Join Date: Apr 2002
Posts: 7,635
Likes: 0
Received 18 Likes on 13 Posts
Default

Originally Posted by Ant
Reel em in jack , you got a big catch today
He's a great sport, I'll give him that!

Last edited by jonc; 04 October 2011 at 04:18 PM.
Old 04 October 2011, 03:01 PM
  #22  
TonyBurns
Scooby Regular
iTrader: (3)
 
TonyBurns's Avatar
 
Join Date: Aug 2000
Location: 1600cc's of twin scroll fun :)
Posts: 25,565
Likes: 0
Received 2 Likes on 2 Posts
Default

I just laugh at him all fan boy and cant take the stick back

Tony
Old 04 October 2011, 04:16 PM
  #23  
jonc
Scooby Regular
 
jonc's Avatar
 
Join Date: Apr 2002
Posts: 7,635
Likes: 0
Received 18 Likes on 13 Posts
Default

Originally Posted by JackClark
I'd change Gaping if I could. But it's still a valid post. Yours on the other hand is old tripe, gleaned from the blog of a publicity hungry security company. It's old news, yes people should know that you can reset passwords, have been able to since I can remember, no it's not a valid link to be posting on this particular thread.
If you took your iBlinkers off for a split second, you'll see that this "old tripe" is widely reported and still current after all this time as Apple still have not plugged this hole.

It's heartening to know that despite all the hype and mis-information spread about that Apple OSX being the most secure OS in the world, they can produce software specifically for their own hardware and yet can still get it so glaringly wrong, it means they are human afterall.
Old 04 October 2011, 05:10 PM
  #24  
JackClark
Scooby Senior
Thread Starter
 
JackClark's Avatar
 
Join Date: Dec 2000
Location: Overdosed on LCD
Posts: 20,852
Received 51 Likes on 34 Posts
Default

Do you think your Windows password is out of reach? And what has this thread got to do with Apple anyhow, why do you Fandroids always try to change the subject, it's childish.
Old 07 October 2011, 04:32 AM
  #25  
bgood
Scooby Regular
iTrader: (2)
 
bgood's Avatar
 
Join Date: Sep 2004
Location: If you rev it, they will come!
Posts: 2,025
Likes: 0
Received 0 Likes on 0 Posts
Default

Thanks for reminding me to add you to my ignore list Jack, been meaning to do that for a while
Old 07 October 2011, 04:40 AM
  #26  
chris84
Scooby Regular
iTrader: (1)
 
chris84's Avatar
 
Join Date: Aug 2010
Location: W Yorkshire
Posts: 521
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by bgood
Thanks for reminding me to add you to my ignore list Jack, been meaning to do that for a while
+1
Old 07 October 2011, 07:44 AM
  #27  
JackClark
Scooby Senior
Thread Starter
 
JackClark's Avatar
 
Join Date: Dec 2000
Location: Overdosed on LCD
Posts: 20,852
Received 51 Likes on 34 Posts
Default

You won't hear this, but good.
Old 07 October 2011, 10:36 AM
  #29  
P1Fanatic
Scooby Regular
 
P1Fanatic's Avatar
 
Join Date: Dec 2001
Location: Arborfield, Berkshire
Posts: 12,387
Likes: 0
Received 0 Likes on 0 Posts
Default

Id be more concerned at their appalling customer service. If you didnt see Watchdog last night it was rather worrying. Phones sent to get repaired and lost, phones sent with s/w issue and came back with scratches all over.
Old 07 October 2011, 12:14 PM
  #30  
TingTongPJ
Scooby Regular
iTrader: (24)
 
TingTongPJ's Avatar
 
Join Date: Jun 2008
Location: Flocksville
Posts: 2,513
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by P1Fanatic
Id be more concerned at their appalling customer service. If you didnt see Watchdog last night it was rather worrying. Phones sent to get repaired and lost, phones sent with s/w issue and came back with scratches all over.

don't forget the biscuit crumbs, and different handsets returned as well, what a shower


Quick Reply: HTC Gaping Security Hole



All times are GMT +1. The time now is 09:01 AM.