ie8 fix

How to protect your Android on public Wi-Fi

Android phones and tablets running version 2.3.3 and earlier suffer from a Google app vulnerability on public Wi-Fi networks, according to a new report. However, there are some concrete steps you can take to protect yourself.

Update, Wednesday at 11:45 a.m. PT: Google has issued a fix that forces the affected Google apps to connect via the secure protocol HTTPS. As long as you update your apps when the fix is pushed out, this public Wi-Fi vulnerability won't affect you. Until then, it's best to use public Wi-Fi with extreme caution or follow the instructions below.

ConnectBot creates a secure tunnel using SSH to protect your data while it's in transit.

(Credit: Screenshot by Seth Rosenblatt/CNET)

Android phones and tablets running version 2.3.3 and earlier suffer from a calendar and contact information vulnerability on public Wi-Fi networks, according to a new report. However, there are some concrete steps you can take to protect yourself.

Here's how it works. The vulnerability is in the ClientLogin Protocol API, which streamlines how the Google app talks to Google's servers. Applications request access by sending an account name and password via secure connection, and the access is valid for up to two weeks. If the authentication is sent over unencrypted HTTP, an attacker could use network-sniffing software to steal it over a legitimate public network, or spoof the network entirely using a public network with a common name, such as "airport" or "library." While this won't work in Android 2.3.4 or above, including Honeycomb 3.0, that only covers 1 percent of in-use devices.

Of course, the safest solution is to avoid using public, unencrypted Wi-Fi networks by switching to mobile 3G and 4G networks whenever possible. But that's not always an option, especially for Wi-Fi-only tablet owners or those on tight data plans.

One legitimate if painstaking option is to disable syncing for the affected Google apps when connected via public Wi-Fi. The security risk affects apps that connect to the cloud by using a protocol called authToken, not HTTPS. The apps tested by the researchers who wrote the report revealing the vulnerability included Contacts, Calendar, and Picasa. Gmail is not vulnerable because it uses HTTPS.

However, this a cumbersome fix, as it requires going into each app before you connect and manually disabling syncing during the time you're on the particular public Wi-Fi network. A much easier solution is to use an app. One of the best apps for secure communication is SSH Tunnel (download), which was designed for Android users stuck behind the Great Firewall of China. SSH Tunnel has some limitations: you must root your phone to use it, and the makers strongly advise people not in China to look elsewhere for a secure tunneling app.

A better solution appears to be ConnectBot (download), which even offers a version from its Web site that supports pre-Cupcake versions of Android.

Users of third-party custom ROMs like CyanogenMod ought to check what security enhancements their installed ROM comes with. CyanogenMod, for example, has VPN support built in and turned off. Cyanogen users can access it from the Settings menu, tap Wireless and Network Settings, then tap VPN Settings.

Given the fragmentation on Android devices, this is a severe security risk that is mitigated only by its limitation to specific apps and public networks. The ideal solution is for Google to release app fixes or Android updates as soon as possible, although the company has given no indication of what steps it plans to take, or when. As always when using public Wi-Fi networks, proceed with caution.

Don't Miss

How to

Make your old iPhone run like new

Want to make your iPhone 4 run like an iPhone 5? Donald Bell has some easy tips.

Play Video

How to

Set up the ultimate home theater PC

From configuring your PC to choosing the right accessories, Sharon Vaknin shows you what you need to turn your PC into the ultimate TV companion.

Play Video

How to

Maximize your Galaxy S4's battery life

Stretch your S4's battery life with a few built-in features and lesser-known tricks that keep your phone from draining quickly. Sharon Vaknin shows you how.

Play Video

How to

Let guests DJ your party

CNET's Donald Bell shows you how to turn your iPhone into a shared jukebox that guests can access and control using a free app.

Play Video

How to

Take creative photos with the HTC One

The camera on the HTC One is capable of some pretty cool tricks. CNET's Donald Bell highlights some of this smartphone camera's slick features.

Play Video

 

Member Comments