LBSZone - Location and Privacy

Location Technology, Privacy, & Security

  • NEWS
    • Business
    • mobile mapping
    • fleet management
    • iOS
    • Android
    • Developer
    • infographics
  • Features
    • AroundtheWeb
  • Telematics
  • Drones
  • Events
  • Blog
  • CAREERS
  • About Us
    • Partners Sites
      • GISuser
      • GeoJobsBIZ
      • LiDAR news
      • Amerisurv
    • Advertise
    • LBSzone Online Media Kit
    • Event Media Partner
    • RSS
  • SHOP
You are here: Home / AroundtheWeb / Serious Android crypto key theft vulnerability affects 10% of devices

Serious Android crypto key theft vulnerability affects 10% of devices

June 30, 2014 By LBSzone

Researchers have warned of a vulnerability present on an estimated 10 percent of Android phones that may allow attackers to obtain highly sensitive credentials, including cryptographic keys for some banking services and virtual private networks, and PINs or patterns used to unlock vulnerable devices.The vulnerability resides in the Android KeyStore, a highly sensitive region of the Google-made operating system dedicated to storing cryptographic keys and similar credentials, according to an advisory published this week by IBM security researchers. By exploiting the bug, attackers can execute malicious code that leaks keys used by banking and other sensitive apps, virtual private network services, and the PIN or finger patterns used to unlock handsets. The advisory said Google has patched the stack-based buffer overflow only in version 4.4, aka KitKat, of Android. In an update, IBM said the vulnerability affected only version 4.3, which runs on about 10.3 percent of handsets.

Screen Shot 2014-06-30 at 10.59.40 AM

Read more via arstechnica.com






Related articles:

  • Apple’s ‘kill switch’ leads to a drop in phone thefts – now Google and Microsoft are going to copy itApple’s ‘kill switch’ leads to a drop in phone thefts – now Google and Microsoft are going to copy it
  • How to… Access Your Google Location HistoryHow to… Access Your Google Location History
  • How to Dial Up the Privacy on Your PhoneHow to Dial Up the Privacy on Your Phone
  • WhatsApp user chats on Android liable to theft due to file system flawWhatsApp user chats on Android liable to theft due to file system flaw
  • A Guide to Unlocking Your Twitter Location HistoryA Guide to Unlocking Your Twitter Location History
  • Blackphone goes for Blackberry’s throat in privacy rowBlackphone goes for Blackberry’s throat in privacy row

Filed Under: AroundtheWeb, Privacy

Recent Posts

What can VPN serve for?

How to make your business more welcoming to your visitors

5 Reasons Why SMS Marketing Works

Ways To Get Your Business Noticed Online

5 things you never knew about Clover Dating App


shop for geogeek swag

twitter

Location Tech News

5 things you never knew about Clover Dating App

All to know about OPPO Find X5 Pro

Toshiba to proceed with restructuring despite Tsunakawa’s exit

Why the rave over Canon’s EOS R3?

Ukraine: How tech giants are reacting to Russian invasion

Four Best Photo Editor Apps On Android Playstore

Three Popular Cloud Gaming Platforms For Android

More Posts from this Category

Copyright Spatial Media LLC 2003 - 2015