Skip to main content

Nearly all Android phones ‘leak’ sensitive personal data, tests show

Google Android LogoGoogle’s privacy woes just got worse. According to a study by researchers at a German university, more than 99 percent of all smartphones that run Google‘s Android operating system can easily be infiltrated by mobile hackers. The attackers can then use the “leaked” data to impersonate the rightful user, and access online accounts, such as Google Calendar, Twitter and Facebook.

According to the University of Ulm researchers, Bastian Konings, Jens Nickels, and Florian Schaub, the Android vulnerability is due to an improper implementation of the ClientLogin protocol, which is used in Android versions 2.3.3 and earlier, reports The Register. Once a user submits his or her login information, ClientLogin receives an authentication token that is sent as a cleartext file. Because the authentication token (authToken) can be used repeatedly for up to 14 days, hackers can access the information stored in the file, and use it to do their nefarious bidding.

Recommended Videos

“We wanted to know if it is really possible to launch an impersonation attack against Google services and started our own analysis,” write the researchers on their blog. “The short answer is: Yes, it is possible, and it is quite easy to do so. Further, the attack is not limited to Google Calendar and Contacts, but is theoretically feasible with all Google services using the ClientLogin authentication protocol for access to its data APIs.”

As bad as this sounds — indeed, is — for Android users, this type of attack can only be waged when the Android device is using an unsecured network, like a Wi-Fi hotspot, to send data. The researchers say hackers could wage such an attack when a device is connected to a network that is under their control.

“To collect such authTokens on a large scale an adversary could setup a wifi access point with a common SSID (evil twin) of an unencrypted wireless network, e.g., T-Mobile, attwifi, starbucks,” write the researchers. “With default settings, Android phones automatically connect to a previously known network and many apps will attempt syncing immediately. While syncing would fail (unless the adversary forwards the requests), the adversary would capture authTokens for each service that attempted syncing.”

The researchers suggest a number of ways to fix the issue, for app developers, Google and Android users alike. Developers whose apps use ClientLogin “should immediately switch to https,” the researchers say. And Google should limit the life of the authentication token, and restrict automatic connects to protected networks only. Android users should update their devices to 2.3.4 as soon as possible, they say, as well as turn off automatic sync when connecting with Wi-Fi, or avoid unsecured Wi-Fi networks entirely.

Andrew Couts
Former Digital Trends Contributor
Features Editor for Digital Trends, Andrew Couts covers a wide swath of consumer technology topics, with particular focus on…
An Apple insider says a new iPad is coming in spring 2025. Here’s what we know
Someone holding the iPad (2022) with the display turned on.

Apple did not release any new iPads in 2023. However, this year marked a significant change with the introduction of all-new versions of the iPad mini, iPad Air, and iPad Pro. Notably absent from this list is the standard iPad, which hasn't been updated in nearly three years. This is expected to change in the coming months. According to MacRumors, Apple plans to release an updated iPad alongside the iPhone SE 4 in spring 2025.

While limited information about the upcoming iPad is available, several details have emerged in recent months. According to Bloomberg’s Mark Gurman, the new tablet is expected to support Apple Intelligence, just like all iPads released in 2024 do. This support suggests that the 11th-generation iPad will likely have a newer A-series chip and at least 8GB of RAM.

Read more
MediaTek’s Dimensity 8400 is going to make 2025 phones faster and more efficient
MediaTek Dimensity 8400 SoC visualized on a phone.

MediaTek has just introduced its latest smartphone silicon, and this one promises some big changes for midrange smartphones. The latest offering from the Taiwanese company is the Dimensity 8400 chip, and it will take on Qualcomm’s excellent Snapdragon 7 series Gen 3 processors.

The new MediaTek chipset, however, enters the fray with more firepower than we have ever seen in this segment. That’s because the Dimensity 8400 goes all-in on big cores and ditches efficiency cores, just like its flagship sibling, the Dimensity 9400.

Read more
It sure looks like the Samsung Galaxy S25 is getting a price increase
The back of the yellow Samsung Galaxy S24 Ultra.

The Samsung Galaxy S25 is just around the corner. We expect it to be announced on January 22 at the Galaxy Unpacked event that's expected to be happening that day, and a new leak further corroborates that information while adding in a few more tidbits we didn't know before.

Tipster Jukanlosreve shared the news on X, citing a "very reliable" source that confirmed the Galaxy S25 will officially be on sale in Korea (and presumably the U.S.) on February 7. In addition, the leaker says the Slim model will also be shown at the Unpacked event.

Read more