DATA DOCTORS

How to avoid falling victim to major Android security flaw

Jul 30, 2015, 4:08 PM | Updated: 4:10 pm

...

Q: I have an Android phone and just heard about the major security problem, so what do I do?

A number of newly-discovered vulnerabilities in a central Android software component called Stagefright, which is used to play, process or record multimedia files, is estimated to affect up to 95 percent of Android users.

According to the security researcher who discovered it, any Android device running version 2.2 through 5.1.1_r4 can potentially be exploited with a text message that contains a malicious multimedia file, better known as MMS messages.

Standard text messages that only contain text use the SMS (Short Message Service) and are not part of the problem. Only rigged MMS (Mutlimedia Messaging Service) messages are able to take advantage of this vulnerability.

If you open a malicious MMS message, you could provide complete access to your phone to a remote hacker. This could allow them to access anything they want on your phone or even wipe everything out, so be very careful with MMS messages, especially if you aren’t sure who sent it.

Google has been made aware of the problem and they have created a patch, but it’s probably going to be a while before your phone will get the fix.

The problem is that Google can’t directly send you the fix. They have to send it to all the different phone manufacturers (Samsung, LG, HTC, Sony, etc.) who then have to work with the various carriers (Verizon, AT&T, Sprint, T-Mobile, etc.) to finally deliver the fix to your phone. This process could take days, weeks or months, depending upon what type of handset you own and which carrier you use and, if you’re running really old versions that are no longer supported, there may never be a fix!

With this in mind, waiting for the phone manufacturers and carriers to deliver the fix will leave you vulnerable, so here are a few things that you should do to protect yourself in the meantime:

No. 1: Turn off the auto-download or auto-retrieval feature on your messaging app

The option is generally located in the Settings menu of whatever messaging apps you use, which can be accessed from within each app.  If you use more than one app, make sure you make the change.

No. 2: If you can’t find a setting to turn off MMS auto-download, stop using the app

The exploit occurs when your phone tries to process a rigged MMS message, so keeping them from ever getting on your phone is best way to protect yourself until a fix is installed.

If you can’t figure out how to stop the auto-downloads, switch to a different messaging app, such as Google Messenger.

No. 3 Manually download MMS messages only from people you know

Since any random hacker can target you simply by knowing your phone number, it’s extremely important that you pay attention as to who is sending you MMS messages.  If you don’t recognize the number, don’t let curiosity expose you!

No. 4 Stop using the Google Hangouts app on Android phones

The Google Hangouts app will automatically process media when it’s sent, which means you could potentially be exploited even if you don’t view the file.  Most people don’t use this app, but if you do, wait for Google to patch the app.

Data Doctors

Patrick Mahomes #15 and head coach Andy Reid of the Kansas City Chiefs are recorded on a phone as t...

Data Doctors

Handy tech tips all Valley residents should use to find lost phones in a snap

Q: My phone went missing, and I haven’t been able to locate it using the Find My service, so what should I do next?

5 days ago

(Pexels Photo)...

Ken Colburn, Data Doctors

Here are tips for freeing up Google storage space

Google provides a generous amount of free online storage but it can fill up quickly depending on how many of its resources you use.

12 days ago

Discover how to assess, estimate, and shop for the right battery pack with this concise guide. (Pex...

Data Doctors

Here is everything you need to know for testing and buying battery banks

Discover how to assess, estimate and shop for the right battery pack with this concise guide.

19 days ago

(Pexels Photo)...

Ken Colburn, Data Doctors

Here are the truly free smartphone video editing apps

The processing power on our smartphones has grown exponentially, allowing anyone to perform sophisticated video editing easily.

26 days ago

Google Maps app....

Data Doctors

How to rediscover places visited years ago on Google maps

Whether you're an Android or iOS user, or prefer accessing Google Maps on your computer, you'll find step-by-step instructions to unlock your travel memories effortlessly.

1 month ago

(Photo by Michael Bocchieri/Getty Images)...

Ken Colburn, Data Doctors

Here’s how to calculate your bandwidth needs

When searching for an alternative internet service provider, here are some tips on how to know how much bandwidth is needed.

1 month ago

Sponsored Articles

...

Condor Airlines

Condor Airlines can get you smoothly from Phoenix to Frankfurt on new A330-900neo airplane

Adventure Awaits! And there's no better way to experience the vacation of your dreams than traveling with Condor Airlines.

...

Collins Comfort Masters

Avoid a potential emergency and get your home’s heating and furnace safety checked

With the weather getting colder throughout the Valley, the best time to make sure your heating is all up to date is now. 

(KTAR News Graphic)...

Boys & Girls Clubs

KTAR launches online holiday auction benefitting Boys & Girls Clubs of the Valley

KTAR is teaming up with The Boys & Girls Clubs of the Valley for a holiday auction benefitting thousands of Valley kids.

How to avoid falling victim to major Android security flaw