Questions tagged [security]

For more generic questions relating security issues. For specific issues having their own tags, please use those -- e.g. 'malware', 'antivirus', 'privacy', 'lost-phone'. Please see the full tag wiki for more. For more in-depth Android security issues, you might rather want to visit our sister-site at http://security.stackexchange.com/questions/tagged/android

Questions with this tag cover issues of system integrity; viruses, scamware, and other malware; information privacy; and other related issues.

For more in-depth Android security issues, you may find IT Security more appropriate.

Related tags

Recommended readings on our site

Further readings

1306 questions
53
votes
4 answers

Just how secure is a pattern lock?

I recently had a phone stolen. It's been replaced, I've changed my passwords, the phone company has shut down connectivity for the stolen one... I think I'm pretty much as safe as I can be. However, it did get me wondering. How secure is the pattern…
Questioner
  • 3,729
  • 23
  • 60
  • 88
36
votes
7 answers

Stagefright security issue: what can a regular user do to mitigate the issue without a patch?

There appears to be a giant security vulnerability with Android that seems to basically affect all phones. PC World wrote: The vast majority of Android phones can be hacked by sending them a specially crafted multimedia message (MMS), a security…
mattm
  • 4,231
  • 4
  • 31
  • 49
32
votes
2 answers

How does the Heartbleed security vulnerability affect my Android device?

The "Heartbleed" vulnerability in particular versions of OpenSSL is a serious security issue which allows malicious servers or clients to undetectably obtain unauthorized data from the other end of an SSL/TLS connection. My Android device has a copy…
Michael Hampton
  • 2,110
  • 17
  • 26
14
votes
5 answers

Can my Android device become - remotely and without my permission - a wiretap and get used as surveillance device?

I saw the following article: An article in the Financial Times last year said mobile providers can "remotely install a piece of software on to any handset, without the owner's knowledge, which will activate the microphone even when its owner…
Casebash
  • 2,405
  • 9
  • 31
  • 43
8
votes
1 answer

Unsafe certificate protection in Android?

Maybe I'm wrong. If so, please let me know. Here is my question. I've followed the instructions here and installed my personal certificate stored in a pfx file (PKCS#12) in my Google Nexus (ICS 4.0.4). A little problem here is that it is not listed…
Taka
  • 181
  • 2
8
votes
1 answer

What is this "Rowhammer" vulnerability in news said to affect millions of devices? Is my device affected?

Rowhammer vulnerability is making news and blogs/ websites claiming millions of Android devices could be affected? What is it? How does it work? How do I test if my device is affected? While this is is a self answered question, updates /…
beeshyams
  • 40,739
  • 30
  • 119
  • 269
7
votes
1 answer

Does the Secure Random bug affect apps besides Bitcoin?

The Bitcoin Project recently announced a bug in the SecureRandom implementation on Android, which caused Bitcoin wallet apps to generate weak private keys that leave bitcoins vulnerable to theft. The major wallet apps have released updates which…
Nate Eldredge
  • 211
  • 2
  • 4
6
votes
3 answers

How to find out stolen phone of android by using IMEI number?

I have already tried by finding findDeviceWebsite Is there any way to find device by IMEI number?
6
votes
0 answers

FBE - Why does each user get a separate DE key

I've been reading about how File-Based Encryption and Direct Boot work. There's one thing I don't understand. According to https://developer.android.com/training/articles/direct-boot Device encrypted (DE) storage contains data encrypted with a key…
catanman
  • 193
  • 1
  • 5
3
votes
1 answer

What is the attack vector of <= 4.3 web view vulnerability?

This is in reference to the vulnerability that Google is not patching, since the WebView in 4.3 and less is part of the OS and not a separate updateable component. Since some people will not have easy upgrade options from their phone manufacturer or…
AaronLS
  • 143
  • 5
3
votes
1 answer

Security Audit - how can I tell my Android Distribution is safe

I've just bought a Jiayu G4 and it came with android installed (rooted). My question is - how can I tell that nothing nasty has been installed on the phone? Or best practices to ensure that it's safe to use. I've had a look but I haven't seen any…
patrickdavey
  • 133
  • 3
3
votes
0 answers

Safely buy a used mobile

Is there any step I need to take after buying a used Android phone from a stranger? Is restoring the device to defaults enough? The hardware should be fine; I'm talking more about the OS itself and software issues (viruses and so on)
Betching1
  • 39
  • 1
3
votes
1 answer

Protecting phone from the FREAK bug

How can I protect my phone from the FREAK bug? Phone is a Samsung GT-S5830 running Gingerbread.
2
votes
1 answer

How can I secure my pictures, videos and other files stored on my phone?

I am looking for a way to protect every sort of data that is saved in my Android phone from being stolen. I have done some research on Google Play, the only app I found with all the features is Folder Lock. Other than this app, the majority of the…
user59002
  • 21
  • 1
2
votes
0 answers

How can I know that my Galaxy's camera and microphone is not being accessed without my knowledge?

A few months back I installed a few apps straight from the internet. One was an ability to run Ruby scripts on my phone, the other was Grooveshark. Both times, an Jellybean 4.2 flagged up a warning saying these programs have the potential to access…
Starkers
  • 267
  • 3
  • 5
  • 10
1
2 3 4 5 6