Slashdot Mirror


Android Hacked Via NFC On the Samsung Galaxy S 3

An anonymous reader writes with an item from The Next Web: "Security researchers participating in the Mobile Pwn2Own contest at the EuSecWest Conference in Amsterdam [Wednesday] demonstrated how to hack Android through a Near Field Communication (NFC) vulnerability. The 0day exploit was developed by four MWR Labs employees (two in South Africa and two in the UK) for a Samsung Galaxy S 3 phone running Android 4.0.4 (Ice Cream Sandwich). Two separate security holes were leveraged to completely take over the device, and download all the data from it."

14 of 198 comments (clear)

  1. So am I safe? by Anonymous Coward · · Score: 5, Funny

    This was hacked via NFC. But I live in Pittsburgh, and the Steelers are in the AFC.

    So I can assume I am safe?

    1. Re:So am I safe? by davester666 · · Score: 5, Funny

      No. Your defense is weak.

      --
      Sleep your way to a whiter smile...date a dentist!
  2. And... iOS6 by jkflying · · Score: 5, Informative

    At the same event, they also hacked iOS6. Just to give an unbiased view...

    --
    Help I am stuck in a signature factory!
    1. Re:And... iOS6 by Anonymous Coward · · Score: 5, Funny

      You must be new here.

    2. Re:And... iOS6 by jkflying · · Score: 4, Informative

      Read the link:
      http://thenextweb.com/apple/2012/09/19/dutch-security-researchers-hack-apple-iphone-4s-exploiting-safari/

      They did it via a malicious webpage, which IMO is even worse than via NFC.

      --
      Help I am stuck in a signature factory!
    3. Re:And... iOS6 by jkflying · · Score: 4, Insightful

      They did it via a malicious webpage. I said hack, not jailbreak.

      --
      Help I am stuck in a signature factory!
    4. Re:And... iOS6 by TeRanEX · · Score: 5, Funny

      At the same event, they also hacked iOS6. Just to give an unbiased view...

      So apple can now sue Samsung because they copied the 'security issues'-feature from the iphone into the Galaxy?

    5. Re:And... iOS6 by UnknowingFool · · Score: 4, Informative

      Also for unbiased view, Pwn2Own is turn based as far as I remember. So any gloating that X device was first to be pwned is meaningless. Teams register before the contest. Team order is chosen randomly (drawing straws, 12 sided dice, whatever). The first team decides which device to be hacked and is given a time period to do so. If they succeed, they get the device. If the first team fails, the second team gets their chance and choice of device. If the first team succeeds, the next team with an unhacked device goes. Some teams register for multiple devices to get a better chance to win something.

      So gloating that iOS or Androd was first to be pwned is useless. It doesn't tell anything about ease of hack or relative security of devices. What matters if they were pwned.

      --
      Well, there's spam egg sausage and spam, that's not got much spam in it.
  3. Is it really such a big deal? by pablo_max · · Score: 4, Informative

    I am not totally sure why these handset hacks are always such big news. What are the chances that this can happen to a normal person? One, you would need to have NFC enabled, which people may do, but at least I never do by default. Two, you need physical access to the handset.
    Has it not been the case for a very long time that if you lose your handset that someone can use it, NFC or no NFC? Oh, and they need to trigger the exploit 185 times before it worked. I think we are still reasonably safe.

    1. Re:Is it really such a big deal? by vawwyakr · · Score: 5, Insightful

      I think that is pretty key here, 185 times at the range of less than and inch or so is basically someone sitting there next to you pretty much touching you for 5 minutes. Obviously this is something that needs to be fixed but I'll hold off on my panic just yet. Even if it worked on the first try someone would have to first identify you as having a vulnerable phone, and where you have if (ie which pocket, etc) then get so close as to be practically touching you and then they have to hope that you have nfc enabled. This isn't some sort of thing you can do just casually walking down the street. It might be an issue for a particular person being targeted but not very likely for a random attack.

    2. Re:Is it really such a big deal? by vawwyakr · · Score: 4, Insightful

      So that assumption here is what? Someone walks down the street bumping into random strangers repeatedly hoping that:

      1) The bump into the side where the strangers phone was being held.
      2) The two phones are perfectly at the same height (presumably in a pocket).
      3) The strangers phone is vulnerable.
      4) They have NFC enabled.
      5) They could hold the phones in contact for the about of time necessary to transfer both an overloaded filed (presumably exceeded a buffer limit) and THEN also transfer the app compromised app that allows the actual hack to work (over a connection with a maximum bandwidth of a few hundred kbits/s).
      6) Then after the hack succeeded they remained in contact long enough for the data from the strangers phone to be transferred back to the hackers phone.

      All with anyone noticing? That's all assuming they fix whatever issue was causing it to need to be run 185 times before it finally worked? Assuming those 185 times were the incremental transfers of all the data needed? Again I'm still not scared. And this is fixed in Jelly bean (which my S3 is running...doom on you close talking random guy on the street thinking you finally found someone with an S3 to stand uncomfortably close to!).

  4. Re:Not exactly practical by fuzzyfuzzyfungus · · Score: 5, Insightful

    The more worrisome thing is probably that NFC is built in in the hope that swiping it all over the place against untrusted devices will become a normal behavior(sort of the way that attacks against the USB charge/data port are wildly impractical, until random charging kiosks start popping up in airports and all over the place, at which point behavioral protection goes out the window, and a bunch of systems intended only to connect to your home PC start getting shoved into god-knows-what...). Sure, as an attack to execute against the phone in your pocket, it is only marginally more practical than making a stab for the USB port; but if the happy-magic-future-of-even-more-middlemen-and-fees comes to pass, you'll see anywhere between several and dozens of readers a day getting a chance to try whatever they want when you shove your phone onto the pad(plus, if ATMs and mag stripe skimming are any indication, it will be about 20 minutes before somebody comes out with a nice little stick-on thin-circuit-in-rugged-sticker NFC 'skimmer' that can be planted on top of legitimate NFC pads and will do its best to MitM legitimate conversations or attack devices while they converse with the genuine NFC pad and log the results).

  5. NFC Doesn't Work That Easily by Chibi+Merrow · · Score: 5, Informative

    With this Galaxy 3 NFC hack, a stranger could do it sitting next to you on the bus.

    No, they'd have to be sitting next to me on the bus AND physically touch my phone with another device long enough to trigger NFC AND I have to have NFC enabled AND keep the devices in physical contact long enough for the download to complete OR hope that I have an active data connection AND the right web browser set as my default so their specially crafted web page loads to root my device...
    Except that (since I have like six web browsers installed) it requires me to interact with the phone to pick the web browser to open the page... A lot more difficult to arrange than "sitting next to someone".

    Also, the ASLR implementation is known to be incomplete on ICS. It's apparently fully fixed on Jelly Bean, so this hack shouldn't be possible on the S3 in a couple months, when the update is rolled out. Likewise, all of the Nexus NFC devices have been updated to Jelly Bean, so they're secure.

    Yeah, it's sad that the hack was possible, but it was due to flaws in the OS, not due to problems with NFC, and only under a very contrived set of circumstances...

    --
    Maxim: People cannot follow directions.
    Increases in truth directly with the length of time spent explaining them
  6. Only on Slashdot by EGSonikku · · Score: 5, Insightful

    Someone discusses an NFC hack to root and steal data off Android and half the posts are "Apple isn't secure either!"

    Focus people! Slashdot is supposed to be the home of Linux and Open Source and über hacks! Why isn't anyone deceminating how this hack works and posting some kind of work-around that isn't just "Don't use NFC" (a feature which Apple gets derided for not having)?

    Remember, a fix isn't "Don't use NFC and switch to another browser." Let's assume a user *likes* NFC, and *likes* his web browser as it is. Lets *fix* the problem here. Any thoughts or conjecture?

    --
    - "Scientia non habet inimicum nisp ignorantem"