Security issues for Android smartphones

  • Replies:5
Kris Carlon
  • Forum posts: 1,110

Sep 27, 2013, 2:48:13 PM via Website

There's a lot of reasons Android-owners need to be careful with security: from excessive permissions, malware, ad networks, trojans, slow-downs and more. This forum is designed to help keep you on top of what problems people are suffering from and what you can do about it.

Follow Kris on Google+ and Twitter / Forum Rules - Recommended for new AndroidPIT members! / Important to all community members: please read before posting

Reply
Amy R.
  • Forum posts: 238

Sep 27, 2013, 9:59:24 PM via Website

I pretty much solved those general problems. Maybe you'll be able to pool some info regarding some security issues I've been facing.

1) Hey Kris, what about Cloud Encryption (I'm from the U.S., this is VERY important to me)?????????

2) Will there ever be an update to app center app to include app permissions before you hit the install button? The Android system does not state all the app permissions, only my Zoner Antivirus does.

3) Is there a way to "beef up the security" in my Android browser so it is as safe as my fully loaded Firefox (going out on a limb....)?

4) My current firewall only can block per app name. My device is not rooted and needs to remain this way for now. Is there an additional way to utilize my VPN Client in order to block certain host names or partial with subroutine (including a basic command set)? I can't find any useful information regarding stock VPN client for Jellybean 4.1.2 (really going out on a limb with this one....).

5) How on Earth am I supposed to get rid of this STUPID GOOGLE+ LINK on my profile page?!?! It was never there before then it suddenly appeared today! I already closed out of the Google+ portion of my Google account 3 times with their acknowledgement and they keep opening it up behind my back! I don't want them posting me in their social site! They act like a bunch of thick heads when I call their technical support. Christ, I don't even care if gmail can't sync without it, I just want it gone! I don't care if they "think" I'm lonely either!!! They are a security issue and I want it removed.****UPDATE: I believe I have corrected this problem, I hope****

Please Help Me :cold:

— modified on Sep 29, 2013, 7:23:07 AM

"You're Probably Wondering Why I'm Here & So Am I" - FZ

Reply
Kris Carlon
  • Forum posts: 1,110

Oct 10, 2013, 12:06:31 PM via Website

Hi Amy, great questions. I'll try to answer them as best I can

1) There's plenty of cloud encryption services out there. I use Boxcryptor for my Google Drive account, but you'll find plenty of others. The important thing to note is how secure the data is not only during transmission, but also on either computer. Most of the time when data is intercepted it is simply done on either end, not in the middle. It is also a good idea to keep it in the back of your head (even with encryption) that anything you post on the cloud can be intercepted, so perhaps storing financial information and sensitive personal information is not advised. Keep that stuff under the mattress.

2) I believe Caspar our Product Management guru answered this elsewhere. You can check permissions for paid apps in the App Center before installing (and paying, of course), but for free apps you first have to download them, then check permissions, then choose to install or not. Not very elegant, but functional enough.

3) I don't know much about secure browsers, but I use startpage.com as my default search engine - it uses Google search results but does not store any information about searches or users. You could check out secure browsers like Webroot, InBrowser and AirWatch but I don't have any personal experience with them. You can also keep an eye on cookies, cached items and the like too, which I expect you already do.

4) Way above my technical knowledge, sorry! Hopefully someone else reading this can advise you better?

5) I hope you have managed to correct the G+ link issue - I had a few problems with G+ links on Google accounts I didn't want G+ on too. But I got it sorted out eventually too. But not without headaches!

Follow Kris on Google+ and Twitter / Forum Rules - Recommended for new AndroidPIT members! / Important to all community members: please read before posting

Reply
Amy R.
  • Forum posts: 238

Oct 10, 2013, 4:23:19 PM via App

Kris Carlon
Hi Amy, great questions. I'll try to answer them as best I can

1) There's plenty of cloud encryption services out there. I use Boxcryptor for my Google Drive account, but you'll find plenty of others. The important thing to note is how secure the data is not only during transmission, but also on either computer. Most of the time when data is intercepted it is simply done on either end, not in the middle. It is also a good idea to keep it in the back of your head (even with encryption) that anything you post on the cloud can be intercepted, so perhaps storing financial information and sensitive personal information is not advised. Keep that stuff under the mattress.

2) I believe Caspar our Product Management guru answered this elsewhere. You can check permissions for paid apps in the App Center before installing (and paying, of course), but for free apps you first have to download them, then check permissions, then choose to install or not. Not very elegant, but functional enough.

3) I don't know much about secure browsers, but I use startpage.com as my default search engine - it uses Google search results but does not store any information about searches or users. You could check out secure browsers like Webroot, InBrowser and AirWatch but I don't have any personal experience with them. You can also keep an eye on cookies, cached items and the like too, which I expect you already do.

4) Way above my technical knowledge, sorry! Hopefully someone else reading this can advise you better?

5) I hope you have managed to correct the G+ link issue - I had a few problems with G+ links on Google accounts I didn't want G+ on too. But I got it sorted out eventually too. But not without headaches!

Thank you for answering (and trying to) answer my paranoid and technical questions. I'm very new when it comes to the internet in general and mostly had to rely on my own bad luck to teach me a lesson later.

-I figured the VPN question was a little beyond your technical knowledge. It appears the Android VPN is a lot more rigid then the ones I've used in Linux. There was little tricks I would use to utilize the vpn for secondary purposes. The list and statements in Android VPN don't appear familiar to the ones I used way back when.......

"You're Probably Wondering Why I'm Here & So Am I" - FZ

Reply
Kris Carlon
  • Forum posts: 1,110

Oct 11, 2013, 9:40:20 AM via Website

One thing I do know is that in all my NSA spook fan reading I know they have apparently cracked SSL and VPN a long time ago, so a new kind of security layer is required if you actually want to encrypt your data, rather than just make yourself feel better. Have you seen the ninja phone on indiegogo? Check it out, could be something interesting when it gets made (and despite flopping in indiegogo, it WILL be made, due to some unannounced backing).

Follow Kris on Google+ and Twitter / Forum Rules - Recommended for new AndroidPIT members! / Important to all community members: please read before posting

Reply
Amy R.
  • Forum posts: 238

Oct 11, 2013, 3:44:45 PM via App

Kris Carlon
One thing I do know is that in all my NSA spook fan reading I know they have apparently cracked SSL and VPN a long time ago, so a new kind of security layer is required if you actually want to encrypt your data, rather than just make yourself feel better. Have you seen the ninja phone on indiegogo? Check it out, could be something interesting when it gets made (and despite flopping in indiegogo, it WILL be made, due to some unannounced backing).

Just checked it out. Actually, it sounds pretty cool. Love to get sucked into that game :) !

In my programing days, I use to create crazy vpn subroutines that had nothing to do with security or create another vpn all together to implement those ideas. I mean, absolutely crazy secondary purposes. I kinda miss those days, but I don't miss the headaches it gave me.

"You're Probably Wondering Why I'm Here & So Am I" - FZ

Reply