It has sparked an uproar over security involving the famous social
networking site Facebook, which in its users for mobile devices Android-OS and
IOS have a security flaw that would allow a user to copy a text file out of the
device giving any user input to our account, profile and content of the device.
The issue does not end there,
as TheNextWeb has chosen to go a little more there and delivered to the mobile
user know that Dropbox also suffer this vulnerability, which lie in the very
utility which stores the info in plain text format, instead of encrypting the
files so that 3rd party cannot enter it.
Facebook has responded with the
following statement:
Facebook utilities for IOS and
Android-OS have been designed exclusively for the use of the operating system
that the manufacturer provides and the input tokens are only vulnerable if it
has changed the mobile operating system (ie jailbreak for IOS or Root in
Android).
Although Mark Zuckerberg and company clearly want to wash their
hands with these statements, down to our hard disk responsibility to methods of
release or hacking of mobile devices, the same site that gives the news has
done extensive testing these utilities on devices without jailbreak, confirming
that this is entirely false.
The usefulness of Facebook in
IOS is quite vulnerable, as it is possible to enter the info using mac
application called iExplore, which has been used by Security researcher Gareth
Wright to make hack without the need for a device to be unlocked.
Therefore, all devices are
vulnerable to this defect, due to the way Facebook manages the file. Apparently Facebook is already aware of the
inconvenience and would already be working in an update to address this problem.
Drobpox hole would be very similar, as it exhibits the same fault
with the file.plist Jailbreak without the need for the device, empowering any
malicious application could exploit this flaw and take of personal info.
If you are a member of any of
these applications, you should not panic, you just have to stay away from the
charging stations and public computers until facebook and dropbox are made updates to their system. It is worth noting that until the moment there is no
evidence that anyone is using this method to gather information.
0 (mga) komento
Mag-post ng isang Komento