<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>VR World &#187; security flaws</title>
	<atom:link href="http://www.vrworld.com/tag/security-flaws/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.vrworld.com</link>
	<description></description>
	<lastBuildDate>Fri, 10 Apr 2015 04:26:13 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=4.1.1</generator>
	<item>
		<title>Bluebox Labs: Xiaomi Phones a Major Security Risk</title>
		<link>http://www.vrworld.com/2015/03/06/bluebox-labs-xiaomi-phones-major-security-risk/</link>
		<comments>http://www.vrworld.com/2015/03/06/bluebox-labs-xiaomi-phones-major-security-risk/#comments</comments>
		<pubDate>Fri, 06 Mar 2015 06:58:29 +0000</pubDate>
		<dc:creator><![CDATA[Sam Reynolds]]></dc:creator>
				<category><![CDATA[Android]]></category>
		<category><![CDATA[Mobile Computing]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Operating Systems]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Bluebox]]></category>
		<category><![CDATA[Bluebox Labs]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[security flaws]]></category>
		<category><![CDATA[Xiaomi]]></category>

		<guid isPermaLink="false">http://www.vrworld.com/?p=49208</guid>
		<description><![CDATA[<p>Xiaomi devices ship with a number of security flaws due to the use of a forked version of Android. </p>
<p>The post <a rel="nofollow" href="http://www.vrworld.com/2015/03/06/bluebox-labs-xiaomi-phones-major-security-risk/">Bluebox Labs: Xiaomi Phones a Major Security Risk</a> appeared first on <a rel="nofollow" href="http://www.vrworld.com">VR World</a>.</p>
]]></description>
				<content:encoded><![CDATA[<p><img width="3182" height="2273" src="http://cdn.vrworld.com/wp-content/uploads/2014/10/Xiaomi-logo.jpg" class="attachment-post-thumbnail wp-post-image" alt="Xiaomi logo" /></p><p>Xiaomi devices have taken Asia by storm, providing fierce competition to established players such as Samsung (<a href="http://www.google.com/finance?cid=151610035517112">KRX: 005930</a>). Recently Xiaomi has been under the microscope for security issues, as it has <a href="http://www.vrworld.com/2014/09/24/xiaomi-fire-taiwan-security-issues/">been alleged</a> that these devices serve as a conduit that allows Chinese intelligence services to siphon user&#8217;s data. However a <a href="https://bluebox.com/technical/popular-xiaomi-phone-could-put-data-at-risk/">new report</a> by security consultancy Bluebox Labs shows that the real threat might come from sloppy coding.</p>
<p>The device tested by Bluebox researchers was the Xiaomi Mi 4. Like many smartphones from Chinese vendors, it ships with a forked (non official) version of Android branded as MIUI. Forked versions of Android do not undergo the same security vetting procedures from Google (<a href="http://www.google.com/finance?cid=694653">NASDAQ: GOOGL</a>) as official versions do.</p>
<p>Being a forked version of Android means that Google services are not available on the device. For example, the phone ships with a Google Play alternative called Mi Market. However the researchers found that this version of Android appeared to be a combination of 4.4.4 and older versions. Doing a deep dive into the OS the researchers found some conflicts at the API level. The devices contains a mixture of API keys from Android 4.4 and Android 4.2 that are both test-keys (not for public use) and release-keys. As test-keys are not finalized they ship with more security bugs than their final counterparts. However the combination of both test and release keys could be incredibly problematic as bugs will no doubt arise just by combining the two.</p>
<p><a href="http://cdn.vrworld.com/wp-content/uploads/2015/03/xiaomi-mi-4-6.jpg" rel="lightbox-0"><img class="aligncenter size-medium wp-image-49209" src="http://cdn.vrworld.com/wp-content/uploads/2015/03/xiaomi-mi-4-6-600x338.jpg" alt="xiaomi-mi-4-6" width="600" height="338" /></a></p>
<p>Bluebox researchers did on the device was a scan for suspicious apps &#8212; malware, spyware or adware. They found three apps considered to be risky. The most problematic of which was an app called Yt Service as it disguises its developer package to make it look like it came from Google &#8212; which is not the case. Next up were apps called PhoneGuardService which was identified as a Trojan and AppStats which is classified as riskware.</p>
<p>Bluebox gives the device a low trustable score of 2.6. By virtue of the fact that it runs a forked version of Android, Xiaomi devices ship with security flaws that have been long ago patched by Google.</p>
<p>For its part Xiaomi has not responded to Bluebox’s attempts for responsible disclosure &#8212; approaching the vendor first before going public.</p>
<p>Bluebox told <i>VR World</i> that it did not accept outside funding for this study.</p>
<p><strong>Update 4:50 China Standard Time:</strong></p>
<p>Xiaomi sent in this response:</p>
<blockquote><p>&#8220;We are investigating this matter now. There are glaring inaccuracies in the Bluebox blog post, as official Xiaomi devices do not come rooted and do not have any malware pre-installed. It is likely that the Mi 4 that Bluebox obtained has been tampered with.&#8221;</p></blockquote>
<p>The post <a rel="nofollow" href="http://www.vrworld.com/2015/03/06/bluebox-labs-xiaomi-phones-major-security-risk/">Bluebox Labs: Xiaomi Phones a Major Security Risk</a> appeared first on <a rel="nofollow" href="http://www.vrworld.com">VR World</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.vrworld.com/2015/03/06/bluebox-labs-xiaomi-phones-major-security-risk/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Content Delivery Network via Amazon Web Services: CloudFront: cdn.vrworld.com

 Served from: www.vrworld.com @ 2015-04-10 15:23:44 by W3 Total Cache -->