Archive for December, 2009

Site Crashed

Wednesday, December 16th, 2009

Sorry for the downtime folks!

Apparently one of our plugins was causing some troubles.  We bought the plugin “Global Translator Pro” in hopes that we could have translations of our site available to a larger community but, the code is a bit buggy.

Hope to have the translations working again soon as well!

Android Security: Fail

Thursday, December 3rd, 2009

Over the last few years our lives have increasingly become integrated with technology. To many an Android or iPhone is the cornerstone to their life.  For lunch I fire up Google Latitude to see if a friend is nearby to grab a bite, I read my brother’s latest Twitter status as he trains in Florida for the Marines, at Walmart I scan laundry detergent barcodes through ShopSavvy to find a better deal. Only a few decades ago carrying a phone around with you wherever you went would be insane, why would you give everybody access to you at any time? To me, not having the internet with me at all times is equally ludicrous, how would I function!

This is a trade off. There is, of course, a willing breach of privacy but, what about your security. What information could your phone tell me if I hacked it? Are you running banking apps, email accounts, vpn, Facebook, etc.. . breaching the security of a phone is just as serious as hacking a computer.

Early this year oCERT pointed out two large vulnerabilities with Android’s security. Both of which use a denial of service attack to potentially access your phones information.

According to oCERT..

Affected version:

Malformed SMS DoS:

Android all 1.5 CRBxx versions (where xx are digits)
Dalvik API DoS:

Android <= 1.5

Fixed version:

Malformed SMS DoS:
Android 1.5 CBDxx, CRCxx and COCxx (where xx are digits)

Dalvik API DoS:
Android >= Donut DRC79

http://www.ocert.org/advisories/ocert-2009-014.html

In an age in which we rely so heavily on technology we must be vigilant and correct these problems quickly, as technology is double edged.

If you have a pre 1.6 Android phone make sure you get your software upgraded as soon as possible.