VPN Encryption Vulnerability On Android
An anonymous reader writes "Cyber security labs at Ben Gurion University have uncovered a network vulnerability on Android devices which has serious implications for users of VPNs. This vulnerability enables malicious apps to bypass active VPN configuration (no root permissions required) and redirect secure data communications to a different network address. These communications are captured in clear text (no encryption), leaving the information completely exposed. This redirection can take place while leaving the user completely oblivious, believing the data is encrypted and secure."
It's Google's OS from NSA country.
I am going to need to update our companies VPN black list to include all android devices. End of story. Problem solution.
TFA says that you need to run a malicious app that intentionally exploits that system. They tested multiple android devices (and I'm assuming different versions of the OS). Also, does this work with every VPN service (like Cisco AnyConnect), or only the native system?
Would it be possible to test if any existing Play store app accidentally/intentionally triggers this exploit? I (like many Android users) don't pirate apps (even though my phone is rooted), but if the popular Play store apps are compromised, that would be a big deal for me.
using POT (Personal Open Terminal) should not skew the results?
This isn't a vulnerability at all. Apps can choose to ignore the default routing. Same on many operating systems. Windows and Linux, for example.
const int one = 65536; (Silvermoon, Texture.cs)
SJW, n: "Someone I don't like, and by the way I'm a fuckwit" - AC
Did I get it right???
Good thing I don't use a VPN on my android phone! I might have been exposing my data!
Tic-Tac-Toe, Global Thermonuclear War, and relationships all have the same winning move.
and have google known about this for very long ?
And is grounds for termination on the spot. Circumvention of corporate resources is frowned upon.
Sure MDM isn't *perfect* ( same as "everything is vulnerable"... ) but it goes a long way to prevent people from doing wrong things, and goes even further to help catch them doing it.
Now, that out of the way, some vendor's MDM is far better than others, sounds like you have been involved with the 'not as better' group.
---- Booth was a patriot ----
This doesn't sound like vulnerability on the encryption at all but rather Android allow modification of routing table instead. This means any existing encryption stay in tact, just rather the data is going to be re-routed out of the VPN tunnel.
-=-=-=-=-=-=-=-=-=-=-=-=-=- If picture worth a thousand words, how many megapixels is it? -=-=-=-=-=-=-=-=-=-=-=-=-=-
Simple solution percent of the *BSD We''l be able to Core team. They OWN LUBE, BEVERAGe, to the transmission overly morbid and Kreskin And promotes our
Many devices can update to Cyanogenmod. Mine has Android 4.2.2 as Cyanogenmod 11,without Google apps, so maybe NSA & Google access to mine is minimal.
I am a fan of full disclosure and all that, but does it have to be done on a Friday afternoon? Could you not sit on the bug for just one weekend and disclose it on Monday morning, so there is a chance that the right engineers to fix it are available?
Finally! A year of moderation! Ready for 2019?
Your VPN is one network interface going this way but you still have other interfaces on different IP addresses going that way and applications are free to choose which they use.
http://michaelsmith.id.au
"Now the user runs the malicious app and clicks on the Exploit button which takes advantage of the vulnerability in the phone’s system"
All I see is, if you run an app on your own device then you can capture your own network traffic. If this ` malicious app ' can't get onto the device without user action then this isn't a vulnerability in Android.
When I worked at Accellion - as, ostensibly, their systems and networks architect - I was overruled on the smartphone question - they required everyone to purchase their own smartphone and they didn't want to hear anything from me about how hard it would be to secure all of those different devices - I obviously didn't know what I was talking about (despite thirty years of experience).
So much for being the architect. Apparently that's a new name for 'janitor'.
Accellion fired me after I discovered that the company was in serious violation of the Palo alto fire code (45 amps' worth of hardware plugged into a single 18-amp circuit, I will affirm this under oath) and refused to give a higher priority to rolling out the Director of IT's new VLANs (apparently the Director of IT aspired to be an architect, too - remember what I said about architects and janitors, above).
Based on information and belief, Accellion tried to cheat the recruiter whom had placed me out of her fee, too - there was a lawsuit, I told my recruiter's lawyer what had happened, and all of a sudden Accellion was interested in settling out of court.
I hear they and their VC backers have been doing their level best to blacklist me ever since.
What do you do when your employer actively punishes you for your giving them the full benefit of the very experience that they hired you to benefit from?
I have never worked for such an abusive employer as Accellion.
CAPTCHA: 'prejudge'
This means that the solution Samsung offered for the first vulnerability found in KNOX (reminder: the solution was use VPN) does not solve the problem.
Sounds like something they'd do for their buddies in the NSA.