Great. There’s apparently a major security flaw in Android phones:
“The reality is, you’re carrying around a desktop computer in your pocket — but there’s no security like there is on computers,” explained Dave Aitel, president of security firm Immunity Inc. and a former computer scientist for the National Security Agency.
And no smartphone comes with antivirus software, experts noted.
Android-based smartphones use security tokens to grant access to only certain bits of information on the phone, Aitel explained, such as the Calendar or Google Reader. The token for Gmail is encrypted; all other tokens are unencrypted, he said — and they’re incredibly easy to steal.
“The tokens are essentially keys that only unlock part of the house,” Aitel told FoxNews.com. And because they’re passed to Google servers unencrypted, a cybersnoop could easily swipe one while a consumer is surfing the web in Starbucks.
My biggest concern about my Droid is the fact that it backs up to the cloud, and doesn’t offer a way to store data locally, as I did with my Palm device and Palm desktop. Google’s going to have to make a major effort to straighten this out, with Verizon and others.
[Update a few minutes later]
Apparently, they’ve already fixed this particular problem on the server side, but I suspect this will be an ongoing issue.