Google phone sports serious security flaw

Analysis
Oct 27, 20082 mins

The new Google/T-Mobile G1 phone hasn’t been out a week yet, but already it’s been hit with a security problem. The New York Times reports that security researchers have found a serious security flaw in the software of the new G1 that could trick users into surfing to booby-trapped Web sites and unwittingly downloading keyloggers and other nefarious programs.

The researchers notified the public of the flaw before Google had a chance to patch it, a fact Google took issue with, since the early public notice leaves hackers time to exploit the flaw before a fix is available.

One of the researchers, Charles Miller, says the group publicized the flaw to let G1 users know that their souped-up phone is just as vulnerable as a typical PC. Google acknowledged the issue, but said the design of Android and especially its “Chrome-lite” type browser would prevent too much harm (at least until a patch is delivered). This is because each site visited, and program run, is automatically placed in its own sandbox, so that any harmful coding cannot affect other programs or parts of the phone. As the NYT article states:

“We wanted to sandbox every single application because you can’t trust any of them,” said Rich Cannings, a Google security engineer. He said that the company had already fixed an open-source version of the software and was working with its partners, T-Mobile and HTC, to offer fixes for its current customers.

At least the researchers are withholding the technical details of the flaw until Google distributes a patch. Until then, G1 surfers beware.