DATA DOCTORS

How to avoid falling victim to major Android security flaw

Jul 30, 2015, 4:08 PM | Updated: 4:10 pm

...

Q: I have an Android phone and just heard about the major security problem, so what do I do?

A number of newly-discovered vulnerabilities in a central Android software component called Stagefright, which is used to play, process or record multimedia files, is estimated to affect up to 95 percent of Android users.

According to the security researcher who discovered it, any Android device running version 2.2 through 5.1.1_r4 can potentially be exploited with a text message that contains a malicious multimedia file, better known as MMS messages.

Standard text messages that only contain text use the SMS (Short Message Service) and are not part of the problem. Only rigged MMS (Mutlimedia Messaging Service) messages are able to take advantage of this vulnerability.

If you open a malicious MMS message, you could provide complete access to your phone to a remote hacker. This could allow them to access anything they want on your phone or even wipe everything out, so be very careful with MMS messages, especially if you aren’t sure who sent it.

Google has been made aware of the problem and they have created a patch, but it’s probably going to be a while before your phone will get the fix.

The problem is that Google can’t directly send you the fix. They have to send it to all the different phone manufacturers (Samsung, LG, HTC, Sony, etc.) who then have to work with the various carriers (Verizon, AT&T, Sprint, T-Mobile, etc.) to finally deliver the fix to your phone. This process could take days, weeks or months, depending upon what type of handset you own and which carrier you use and, if you’re running really old versions that are no longer supported, there may never be a fix!

With this in mind, waiting for the phone manufacturers and carriers to deliver the fix will leave you vulnerable, so here are a few things that you should do to protect yourself in the meantime:

No. 1: Turn off the auto-download or auto-retrieval feature on your messaging app

The option is generally located in the Settings menu of whatever messaging apps you use, which can be accessed from within each app.  If you use more than one app, make sure you make the change.

No. 2: If you can’t find a setting to turn off MMS auto-download, stop using the app

The exploit occurs when your phone tries to process a rigged MMS message, so keeping them from ever getting on your phone is best way to protect yourself until a fix is installed.

If you can’t figure out how to stop the auto-downloads, switch to a different messaging app, such as Google Messenger.

No. 3 Manually download MMS messages only from people you know

Since any random hacker can target you simply by knowing your phone number, it’s extremely important that you pay attention as to who is sending you MMS messages.  If you don’t recognize the number, don’t let curiosity expose you!

No. 4 Stop using the Google Hangouts app on Android phones

The Google Hangouts app will automatically process media when it’s sent, which means you could potentially be exploited even if you don’t view the file.  Most people don’t use this app, but if you do, wait for Google to patch the app.

Data Doctors

Many of the fake videos you’ll encounter are likely to be viewed on your smartphone, which can ma...

Data Doctors

Here are all the tips we know regarding how to spot deep fake videos

Many of the fake videos you’ll encounter are likely to be viewed on your smartphone, which can make detection a bit more difficult.

3 days ago

Patrick Mahomes #15 and head coach Andy Reid of the Kansas City Chiefs are recorded on a phone as t...

Data Doctors

Handy tech tips all Valley residents should use to find lost phones in a snap

Q: My phone went missing, and I haven’t been able to locate it using the Find My service, so what should I do next?

10 days ago

(Pexels Photo)...

Ken Colburn, Data Doctors

Here are tips for freeing up Google storage space

Google provides a generous amount of free online storage but it can fill up quickly depending on how many of its resources you use.

17 days ago

Discover how to assess, estimate, and shop for the right battery pack with this concise guide. (Pex...

Data Doctors

Here is everything you need to know for testing and buying battery banks

Discover how to assess, estimate and shop for the right battery pack with this concise guide.

24 days ago

(Pexels Photo)...

Ken Colburn, Data Doctors

Here are the truly free smartphone video editing apps

The processing power on our smartphones has grown exponentially, allowing anyone to perform sophisticated video editing easily.

1 month ago

Google Maps app....

Data Doctors

How to rediscover places visited years ago on Google maps

Whether you're an Android or iOS user, or prefer accessing Google Maps on your computer, you'll find step-by-step instructions to unlock your travel memories effortlessly.

1 month ago

Sponsored Articles

...

DESERT INSTITUTE FOR SPINE CARE

Desert Institute for Spine Care is the place for weekend warriors to fix their back pain

Spring has sprung and nothing is better than March in Arizona. The temperatures are perfect and with the beautiful weather, Arizona has become a hotbed for hikers, runners, golfers, pickleball players and all types of weekend warriors.

...

Day & Night Air Conditioning, Heating and Plumbing

Day & Night is looking for the oldest AC in the Valley

Does your air conditioner make weird noises or a burning smell when it starts? If so, you may be due for an AC unit replacement.

...

Collins Comfort Masters

Avoid a potential emergency and get your home’s heating and furnace safety checked

With the weather getting colder throughout the Valley, the best time to make sure your heating is all up to date is now. 

How to avoid falling victim to major Android security flaw