UPDATED: Google boosts privacy amidst Android leak worries
By Tom Brewster,
Google has added trust accreditation to Marketplace apps as it deals with claims that almost all Android phones leak user data.
Yesterday, Google announced a TRUSTe administered data privacy certification programme for its Apps, designed to give customers confidence in the security of software on the market.
“TRUSTe has created a certification program for installable Marketplace apps to verify that they clearly communicate their data handling and privacy practices,” said Scott McMullan, Google Apps partner lead, in a blog post.
“This programme, which is optional for vendors, displays a green TRUSTe logo on a certified app’s Marketplace listing page as well as search results pages.”
Customers who click on the logo will go through to a summary with more information about the app.
Android issues
Google has also moved to fix a vulnerability thought to affect the majority of Android phones.
German researchers Bastian Konings, Jens Nickels and Florian Schaub, from the University of Ulm, found login data to Google services could be leaked over unprotected Wi-Fi networks.
The problem stemmed from the way in which apps interact with Google services to request tokens. Tokens were seen being sent in plain text over open Wi-Fi networks, allowing eavesdroppers to pilfer them.
This could have allowed hackers to get hold of users’ calendar and contact data, or pictures via Picasa.
“This means that the adversary can view, modify or delete any contacts, calendar events, or private pictures. This is not limited to items currently being synced but affects all items of that user,” the researchers warned in a blog post.
They claimed 99.7 per cent of all Android smartphones were affected.
Google said it had fixed the issue in the latest versions of Android, including the current Gingerbread and Honeycomb OSs.
“We're aware of this issue, have already fixed it for calendar and contacts in the latest versions of Android, and we're working on fixing it in Picasa,” a Google spokesperson said.
Google Apps accounts were protected from the calendar and contacts vulnerability, however, as they send traffic over HTTPS.
UPDATE Google has sent over a new statement surrounding the Android flaw, saying an automatic fix would be rolled out soon.
"Today we're starting to roll out a fix which addresses a potential security flaw that could, under certain circumstances, allow a third party access to data available in calendar and contacts," a Google spokesperson said.
"This fix requires no action from users and will roll out globally over the next few days."
You may also like...
Sponsored Links
advertisement
You may also like...
Latest Security Analysis & Insight
What is your password worth?
Would you be tempted to sell off company passwords for a fee? If not, seems like you're in the minority, acccording to research.
- Macs under attack?
- Intel: security inside
- Are you spending too much on IT security?
- Does the government want to snoop on your data?
- Eurocrats versus the cyber criminals
- The truth about spam
- Google and privacy: What’s the problem?
- Q&A: Symantec’s CISO on the source code hack
- RSA: Back from the breach?
Latest Security Reviews
Check Point 2210 Appliance review
Rating: ![]()
advertisement
Most popular
- UK regulator shuts down Angry Birds scam
- Apple iPad 3 vs iPad 2 head-to-head review
- IBM bans use of Siri on iPhones
- Chromebooks: What's gone wrong?
- HP plans massive job cuts
- EMC World 2012: Tucci declares Documentum is here to stay
- Dell EqualLogic PS6100XS review
- Macs and Android under malware threat
- RIM loses its head of sales
- Local fibre broadband needs common standards
Latest News Videos in Security
IT PRO Podcast: Are UK data protection laws flawed?
We bring in two experts to talk about the problems with UK data protection law and the way it is managed.
Register for IT PRO
You'll get exclusive member benefits including free whitepapers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.






Lack of privacy from Google again!
We see another case of Google miss using people's online data. It is all very well the company apologising about breach of data however everyone's data is exposed forever. Opening it up to being spammed forever.
One way to avoid this risk is it use temporary email addresses. These can be disconnected to your inbox if the address is ever exposed. It is easier to use than you might think: http://www.spamratings.com/consumers/the-cleanzer-tour
By SpamRatings on Thursday May 19