<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" 
      xmlns:thr="http://purl.org/syndication/thread/1.0">
  <link rel="alternate" type="text/html" href="http://blog.tmcnet.com/blog/tom-keating/skype/skype-responds-to-android-vulnerability.asp" />
  <link rel="self" type="application/atom+xml" href="http://blog.tmcnet.com/blog/tom-keating/atom.xml" />
  <id>tag:blog.tmcnet.com,2018:/blog/tom-keating//4/tag:blog.tmcnet.com,2011:/blog/tom-keating//4.46543-</id>
  <updated></updated>
  <title>Comments for Skype Responds to Android Vulnerability</title>
  <subtitle>VoIP &amp; Gadgets blog - Latest news in VoIP &amp; gadgets, wireless, mobile phones, reviews, &amp; opinions</subtitle>
  <generator uri="http://www.sixapart.com/movabletype/">Movable Type 4.38</generator>
  <entry>
    <id>tag:blog.tmcnet.com,2011:/blog/tom-keating//4.46543</id>
    <link rel="alternate" type="text/html" href="http://blog.tmcnet.com/blog/tom-keating/skype/skype-responds-to-android-vulnerability.asp" />
    <link rel="service.edit" type="application/atom+xml" href="http://blog.tmcnet.com/mt/mt-atom.cgi/weblog/blog_id=4/entry_id=46543" title="Skype Responds to Android Vulnerability" />
    <published>2011-04-15T15:55:09Z</published>
    <updated>2011-04-15T16:03:34Z</updated>
    <title>Skype Responds to Android Vulnerability</title>
    <summary>Skype&apos;s Chief Security Officer, Adrian Asher responded to Android Police&apos;s article on a vulnerability in the Skype for Android client. He writes: It has been brought to our attention that, were you to install a malicious third-party application onto your...</summary>
    <author>
      <name>Tom Keating</name>
      <uri>http://blog.tmcnet.com/blog/tom-keating/</uri>
    </author>
    
    <category term="Android" />
    
    <category term="Google" />
    
    <category term="Memory" />
    
    <category term="Skype" />
    
    <category term="TMCnet" />
    
    <category term="VoIP" />
    
    <content type="html" xml:lang="en" xml:base="http://blog.tmcnet.com/blog/tom-keating/">
      <![CDATA[<img class="mt-image-right" style="float: right; margin: 0 0 20px 20px;" src="http://blog.tmcnet.com/blog/tom-keating/images/android-logo.jpg" alt="android-logo.jpg" width="250" height="232" />Skype's Chief Security Officer, <a href="http://blogs.skype.com/security/2011/04/privacy_vulnerability_in_skype.html">Adrian Asher responded</a> to Android Police's <a href="http://www.androidpolice.com/2011/04/14/exclusive-vulnerability-in-skype-for-android-is-exposing-your-name-phone-number-chat-logs-and-a-lot-more/">article</a> on a <a href="http://blog.tmcnet.com/blog/tom-keating/skype/skype-for-android-exposes-personal-info.asp">vulnerability in the Skype for Android client</a>. He writes:<br /><br />
<blockquote>
<p>It has been brought to our attention that, were you to install a  malicious third-party application onto your Android device, then it  could access the locally stored Skype for Android files.</p>
<p>These files include cached profile information and instant messages.  We take your privacy very seriously and are working quickly to protect  you from this vulnerability, including securing the file permissions on  the Skype for Android application.</p>
<p>To protect your personal information, we advise users to take care in  selecting which applications to download and install onto their device.</p>
</blockquote>
<br />He acknowledges the need for Skype to secure the file permissions, but also basically says to take care which apps you install. But how does one know which Androids apps might be stealing Skype personal info, especially now that this exploit is out in the open?]]>
      <![CDATA[Further, he doesn't address whether Skype will be encrypting the locally cached files. Why not encrypt them? I know <a href="http://code.google.com/p/android/issues/detail?id=191">SQLite supports encryption</a>, but alas, according to Google it's <strong>commercial code</strong>. Google explained back in 2008, "An encryption module for SQLite exists, but is commercial, and thus <strong>cannot be included in Android</strong>.  Implementing a custom solution is obviated by the Android security model, which is based on Linux processes and prevents applications from reading each others' data and memory.  In the final version, only 3 processes will be running as root, all of minimal scope.  Since on-device encryption only protects the data from other programs/processes, and since our security model will achieve that, and since there is no readily available open-source encryption module for SQLite anyway, we are not implementing this at this time.<br /> <br /> So Skype isn't necessarily at fault here, since if I read this  correctly, <strong>none</strong> of the Android SQLite databases are encrypted. If  anything, it sounds like this is the fault of the Android operating  system for not offering encrypted databases. However, Google explains  that their <em>security model negates the need for encryption</em> - assuming of  course the application sets proper permissions on the files, which in  this case, Skype failed to do. The Android is not alone in not encrypting databases. The iPhone also natively uses SQLite without encryption, though <a href="http://mobileorchard.com/tutorial-iphone-sqlite-encryption-with-sqlcipher/">there is a tutorial</a> how to enable encryption. Even though Android doesn't require  encryption to protect each application's database, I'm surprised Android  doesn't offer this option. Someone could steal someone's Android  device, "root" it, and then get access to the unencrypted SQLite  database directly.<br /> <br /> In any case, Skype muffed up on the file permissions, which would have  blocked access to the unencrypted database, but I can't fault them for  not encrypting the SQLite database. That apparently is a "feature" of the Android operating system. <img title="smiley-undecided" src="http://blog.tmcnet.com/mt-static/plugins/TinyMCE/lib/jscripts/tiny_mce/plugins/emotions/img/smiley-undecided.gif" border="0" alt="smiley-undecided" />]]>
    </content>
  </entry>

</feed>
