New features, known security hole
Summary
In January 2011 ICQ 7.4 appeared with an improved chat history, better Facebook integration and notifications of new mail from Gmail, Yahoo and Mail.ru. Users could switch faster between chat, SMS, voice and video calls. However, the developers had not fixed a known security hole in the auto-update function.
Ideas
- Messengers bundled messages from many services in one place.
- New features came before known security problems were fixed.
- The auto-update function itself was an attack path.
- The update function could not be switched off.
Insights
- An insecure update mechanism endangers precisely the users who use it unsuspectingly.
- Feature releases without security fixes show the wrong priorities.
Facts
- The version appeared for Windows.
- The hole in the auto-update function was already known.
- As alternatives, Golem named multi-messengers such as Miranda, Pidgin and Trillian.
References
Critique
- The report does not explain how hijacking the update function works technically.
Recommendations
- Only use software whose updates are signed and distributed over secured connections.
- For messengers, rely on open protocols with end-to-end encryption.
Links to the original source and the Web Archive open in a new tab.