Friday, January 11, 2013

Android Security Exploits Pt.2

http://www.xda-developers.com/android/nfc-secure-beta-makes-standard-lock-screen-security-a-relic-of-the-past/
This app looks very interesting as it provides another layer of security that can only be unlocked with an NFC tag. I do however have some questions: could somebody copy the NFC key and use their version to unlock the phone? The application claims to be 100% secure, but that seems very unlikely. What did they use to secure their application? If an attacker gained root couldn't they simply look at the device over ADB? Does the app protect against this? It seems like a good idea, but their claims seem slightly over the top.

http://www.xda-developers.com/android/dangerous-exynos-4-security-hole-demoed-and-plugged-by-chainfire/
The XDA Forums member alephzain created an application that can plug the hole found on devices using certain Exynos processors. The application changes the permissions on the vulnerable device, but in doing so also breaks the camera. The fix is a trade off, but it seems to be the only one that works currently. I am surprised that with such a large hole Samsung (the creator of the Exynos line of chips) has not taken steps to fix the issue.

1 comment: