A noted security researcher Monday warned users of T-Mobile's G1 smart phone that a critical vulnerability in Google's Android operating system could be used to hack their phones.
Led by Charlie Miller, a researcher who has rooted out high-profile bugs in Apple's Mac OS X and iPhone, a team from Independent Security Evaluators (ISE) identified the bug and reported it to Google last week. ISE is a Baltimore-based security consultancy where Miller works.
Miller, who declined to get specific about the vulnerability, said only that it is a buffer overflow bug that could be exploited by tricking G1 users into visiting malicious sites. "There's a chance that the attacker could execute malicious code remotely" with the same privileges as the user of the phone's browser, Miller said.
T-Mobile started shipping the G1 shortly before the Oct. 22 launch date; the phone is the first powered by Google's open-source mobile phone operating system, Android.
Miller said that after alerting Google, a security researcher from its Android team contacted him for more information, and to ask that he withhold information until a patch was in place. Miller refused to wait, but promised not to disclose any details or technical information that could be used by hackers.
"People should know that there's a problem with the G1 before they buy it," Miller said as he defended his actions. "I don't want to help the bad guys either, but people should have all the information before they make a decision to buy [the phone]. I think I'm totally in the right here."
Google did not respond to a request for comment, or to questions about the status of any patch for Android and the G1.
Miller also said that he and others at ISE had crafted a working exploit, but would not release it until a patch is in hand.
According to a more detailed warning on the ISE site, the flaw is within one of the more than 80 different open-source packages used by Google to assemble Android. Miller blamed the bug on Google's use of outdated code. "This particular security vulnerability that affects the G1 phone was known and fixed in the relevant software package, but Google used an older, still vulnerable version," said the ISE alert.
Miller declined to name the specific open-source package at fault.
Google has been caught in the same bind before. Because it used an older version of WebKit, the open-source rendering engine that also powers Apple's Safari, for the foundation of its own Chrome Web browser, users were at risk from attacks based on a months-old flaw that had been dubbed the "carpet bomb" bug.
Google patched the carpet bomb vulnerability in a development build of Chrome two weeks ago.
Miller is well known in the Mac and iPhone vulnerability research community, and was on the same three-man ISC team that spotted and reported the first bug in Apple's iPhone shortly after it launched in mid-2007. Several months before that, he walked off with a $10,000 prize in an inaugural hacking contest by cracking an Apple laptop running Mac OS X in less than two minutes.
"I like the iPhone," said Miller, "but the G1 actually has a lot better security. In Android, Google uses this compartmentalized security architecture, application sandboxing really, so that each app runs as its own user and can access only its own files. So even though I can exploit the browser, I can't read the person's e-mail."
But even though it boasts stronger security, the G1 is still dangerous, Miller said, blaming user naivete.
"People are trained to be careful when they're browsing from the desktop or laptop, but hand them a phone and all the rules seems to go out the window," Miller said. "They use [their smart phone] to do everything they do on the desktop, but they forget they can get into trouble browsing from their phone."
Latest on Mobile Phones
- Apple may patch serious SMS vulnerability on iPhone
- Symbian Foundation makes progress, but challenges remain
- Palm Pre hardware glitches hard to evaluate, analysts say
- More pornography sneaks onto the iPhone
- Apple admits iPhone overheating issues -- sort of
- Jailbroken iPhones leave users more vulnerable
- Users complain about poor Pre hardware
- Why the iPhone can't be 'killed'
- Nokia N97 debuts with widgets and Ovi store
- Report: Dell developing handheld Internet device
Mobile Essentials
- Businesses see smartphone use rising, survey shows
- Femtocell FAQ: Time for a 'personal mobile phone tower'?
- Mobile tech under Obama
- T-Mobile G1: A tour of Google Android
- Analysts: OS focus could boost Moto's prospects
- New Nokia device highlights cheap smart phone trend
- Mobile industry split over UMA versus femtocells
- Qualcomm claims first-ever 20 megabits-per-second data call
- Industry heavyweights line-up behind Sony's TransferJet
- Mobiles, SMS play a role in Afghanistan security
TechWorld Jobs (beta)
Recent Jobs
TechWorld Blogs
-

TalkingTech
The view from the top of IT with TechWorld Editor Rodney Gedda
-

Entrenched
Cooking up better code, IDG's developers reveal some of their secrets
-

Broadband Voice
Darren Pauli digs in from the front line of Australia's broadband battleground
Recent blog posts
- Nokia remains 'open' to Android amid Symbian renaissance
- KDE's Seigo gives sneak peek at version 4.3
- Was the iPhone 3G S worth queuing up for?
- Has Oracle started its mammoth technology consolidation?
- iPhone 3.0: the detail is the process, not the features
- TechWorld.com.au goes mobile
- Should Dell buy Palm? Stranger things have happened
- A big week for Linux: is user friendliness finally in sight?
- Apple, Android rain on Palm's Pre parade
- The clone attack is becoming unstoppable
Recent comments
- State your Prediction and
14 hours 18 min ago - Yes I have seen them.Actually
15 hours 11 min ago - PSP Nintendo
1 day 6 hours ago - Interesting report. You were
2 days 2 hours ago - Are you sure it is in Sydney?
2 days 13 hours ago - The mobile market has
2 days 21 hours ago - Great news.
Sms spam should
3 days 18 hours ago - now what am I gonna do with
3 days 21 hours ago - ozlotteries.com not ozlotto.cm
3 days 22 hours ago - OLAT Release
4 days 9 hours ago - and i was sure i would win...
4 days 13 hours ago - Hi SolidRadicle,
I am looking
4 days 13 hours ago - Not if I can help it
4 days 13 hours ago - Ozlotto Tips Scam
4 days 18 hours ago - Great post.
It's very
4 days 18 hours ago - Excellent review! I'm glad
6 days 15 hours ago - iTunes Helper
1 week 2 days ago - Update the link to OrangeHRM web site
1 week 2 days ago - Very informative article
1 week 3 days ago - Google Chrome is still being directed to bing instead of google
1 week 3 days ago










Comments
Post new comment