Android and its password problems open doors for spies

http://www.h-online.com/security/news/item/Android-and-its-password-problems-open-doors-for-spies-1918596.html
Android password problems
The data stored on Google servers when the "Back up my data" option is selected on an Android device includes Wi-Fi passwords in plain text format. This is not in itself news, but businesses in particular may wish to reconsider its implications in the light of the latest surveillance scandal.

The backup function is, at least on Nexus devices, activated by default, with no password of any kind required for the service. In Google's favour, it has to be said that it does make it clear what users are letting themselves in for, with the description of this function stating "Back up ... Wi-Fi passwords ... to Google servers". Tests by The H's associates at heise Security showed that after resetting an Android phone to factory settings and then synchronising with a Google account, the device was immediately able to connect to a heise test network secured using WPA2. Anyone with access to a Google account therefore has access to its Wi-Fi passwords.

No comments:

Post a Comment