Oct 03 AT 10:45 AM Nick Gray 27 Comments

HTC security hole could put some of your personal information at risk


If you happen to own one of those fancy new HTC phones that have come out over the past few months, you might want to hold off on downloading any new apps from less-than-trustworthy developers.

The folks over at Android Police have discovered that the HTCLogger.apk included in newer HTC devices and system updates doesn’t secure any of the data that it collects. HTC Logger is intended to capture system logs, GPS location, user accounts and other data to help HTC monitor handset issues, which HTC should be using to push out fixes in a more timely fashion. The problem is that all the data captured by the app is stored on the handset and can easily be captured by any application that has permission to access the Internet (android.permission.INTERNET).

The security vulnerability caused by HTCLogger is certainly critical, but we do believe the whole situation has been blown out of proportion. By fully disclosing how to take advantage of the vulnerability, Android Police has given hackers and app developers with malicious intent everything they need to capture the information stored by HTCLogger. There’s currently no indication that any rogue apps are taking advantage of this vulnerability, but we suggest you think twice before downloading applications from developers you don’t know or trust until HTC can resolve the issue.

HTC is aware of the vulnerability and is looking into fixing the problem. But if you have root access and want to take matters into your own hands, you can uninstall the app from /system/app/HtcLoggers.apk and be done with this whole issue.

HTC takes our customers' security very seriously, and we are working to investigate this claim as quickly as possible. We will provide an update as soon as we're able to determine the accuracy of the claim and what steps, if any, need to be taken.HTC

Will any of you be waiting around for HTC to correct the issue? Or will you simply remove the HtcLoggers.apk and move on?

Source: Android Police

Nick is a tech enthusiast who has a soft spot for HTC and its devices. Nick joined the Android and Me family in the summer of 2010.

    seems like security holes are found in everything these days.. sometimes i think its intentional

  • Paul

    Well they gave HTC and a heads up and gave them 5 business days to respond and HTC completely ignored it. So I hope this ‘lights a fire’ under their proverbial buts and gets them to do something about it. Like with any vulnerability, manufacturers would love to ignore it and focus on more profitable things like the next phone or whatever, but if enough people know about it and get upset about it then they have no choice but to go back and patch their software and address the issue. I just don’t like that HTC ignored the bug fix and I hope that enough people can get them to actually do something about it.

    • http://www.nexsoftware.net Justin Shapcott

      Paul – It is not customary to provide source code to exploit a vulnerability in the wild when there is not a workaround for the vast majority of those who might be affected. That’s bad form. The original post was done under the guise of ‘responsible disclosure’, but in telling exactly how to exploit it, they stepped into the realm of ‘irresponsible disclosure’.

    • http://www.anthonydomanico.com Anthony Domanico

      Why do people think that the phone design team and the people who work on Sense/bugs are the same people?

      • http://htcsource.com Nick Gray

        I think people forget that there are hundreds if not thousands of people who are involved in handset development and maintenance.

        • http://www.nexsoftware.net Justin Shapcott

          I’m pretty sure that there are only like 5-10 people working at HTC. 15 tops.

          And, yes, I am kidding.

  • http://htcsource.com Nick Gray

    No one is denying that there’s an issue here, but the way the issue was disclosed is a big part of the issue as well. The right way to fix an issue is not by telling the world how to take advantage of the vulnerability.

    • R.S

      It is IF it gets the vulnerabilty fixed quicker than it would have had it remained a secret. Not only that, but I believe that people have a right to know that their information is at risk.

      Plus if Android Police found it, who is to say that someone else hadn’t already found it or wouldn’t have found it before it was fixed?

      Now that its been exposed, HTC has no choice but to quickly deal with the issue right now rather than “when we get to it”.

      • http://www.nexsoftware.net Justin Shapcott

        There is a difference between disclosing the existence of a vulnerability, and releasing source code which can be used to exploit said vulnerability.

  • R.S

    Yes, I am well aware that there is a difference between exposing or disclosing a vulnerability. They have a much different affect on issues like this one, which is my point.

    By exposing the vulnerability, HTC has no choice but to act quickly because like you wrote, the source code which can be used to exploit the vulnerability was released. This means there is an immediate threat.

    If the vulnerability had only been disclosed, HTC could have taken their sweet time, if they weren’t already doing so, dealing with the issue since it would have only been a possible threat.

    Immediate threats are usually dealt with in a more timely manner, and with greater importance, than possible threats. The vulnerability being exposed to the world made it go from a possible threat to an immediate threat.

  • Derek

    Wow…this site gets slower and slower with staying on top the Android news. So incompetent.

