Welcome, Guest: Register On Nairaland / LOGIN! / Trending / Recent / New
Stats: 3,152,942 members, 7,817,766 topics. Date: Saturday, 04 May 2024 at 06:58 PM

Your Password/personal Data Can Be Hacked Via Copy And Paste In Your Smartphone - Phones - Nairaland

Nairaland Forum / Science/Technology / Phones / Your Password/personal Data Can Be Hacked Via Copy And Paste In Your Smartphone (519 Views)

You Are Actually Giving Away Your Personal Data When You Copy And Paste It / How Much Data Can I Accumulate Per Night On The Airtel Night Plan / Beware Of Whatsapp Plus”, A Fake Malicious App That Steals Personal Data (2) (3) (4)

(1) (Reply)

Your Password/personal Data Can Be Hacked Via Copy And Paste In Your Smartphone by SmartDepot: 2:37pm On Oct 18, 2020

https://www.youtube.com/watch?v=Q2oYl0pMSjg

The video above is based on Android smartphone not for iOS, I am an Android App developer (Flutter certified), xda developers senior member (since 2014), degree in computer science, DBMS expert (My current day job), website and web applications developer, part-time YouTuber (Smart Depot NG) and lots more... I said this because I may use some technical term but will keep it as simple as I can. Secondly, before some will come and start arguing with me, have a little idea of who you are arguing with.
I'll answer questions in the comments (those who ask politely) as much as I can. You are free to bring your own contributions to the comments too just make sure that you researched what you are writing or know/have experience in the field.

The main reason for this video is to attack A POOR SECURITY HABIT - you may have done it for years without any repercussions but that doesn't change it from being bad approach to your personal (digital) security. This video is centered on Clipboard where items that are copied or cut are temporarily kept.

CLIPBOARD (DEFINITION) - a temporary storage area where material cut or copied from a file is kept for pasting into another File.
Clipboard itself is designed for information sharing between applications. Since Android is open source, apps (including third-party apps) can read the contents in the clipboard and the implications means another malicious app can read sensitive data or any data copied to the clipboard and this is the main reason why I say stop copying and pasting sensitive personal information (in the video I gave an alternative, use secured password managers).

ANDROID 10 PRIVACY CHANGES.
In Android 10, Google changed some privacy settings in Android that Removed background clipboard access from clipboard managers (app) or any other third-party app. While this is a privacy improvement, it did piss off alot of developers who either had to reworked their app or can't do anything to make their app run on Android 10. A good example is Clipper app (clipboard MANAGER - See images below). This move made a lot of developers start adding inbuilt clipboard management tools to their keyboard app. In the video, you'll see how alot of third-party apps are still trying to access clipboard (in Android 10) even though the access has been by new privacy implementation.
Some developers thought it would have been best for Google to create a clipboard access permission for apps instead of removing it, others feel it is a good thing while some are warry of the number of open GPL violations it could take Google to make an open source Android have a closed source clipboard - it's never going to be an easy decision anyway you look at it.

ANDROID 9 AND BELOW STILL VERY VULNERABLE.
Up to 91% of Android users use Android 9 and below. Clipboard managers like Clipper or even some malicious apps can add some features in it and gain background access to your clipboard even when you are using another app. So, there is a true vulnerability for Android version from Android 9 and below for data to be stolen from the clipboard so, it is important that you at least, do not copy and paste your sensitive personal information to the clipboard.

STOCK/THIRD-PARTY KEYBOARD APPS -
If you are on And 9 and below, even stock keyboard apps like AOSP keyboard or Google keyboard does not mean that you are not vulnerable even if it has its own clipboard manager, every copied information in the app also goes to the native Android clipboard. So, stock keyboards can give a security advantage if you are on Android 10 and above but there is still a potential vulnerabilities for clipboard.
THIRD-PARTY KEYBOARD apps are the most annoying part of all these security. Make use that you are using a third-party keyboard app from a trusted companies. Most Android third-party keyboard apps have their own inbuilt clipboard, which means that the app holds every single information you copy, can save it in its own cache and can do whatever it wants with such data.

TARGET FOR ATTACKS (ANDROID 10/11)
Removing background clipboard access from Android 10 and above while it solved some privacy concerns still means that malwares or hacking can now target keyboard apps to steal personal information so, it's best not to copy it at all. I am currently using Android 11 (pure AOSP rooted with Magisk) I like the improvements in the permissions and privacy, Keyboard apps can no longer manage the native clipboard even when they are the main input method, they can only pin or edit clipboard items inside their own app but there is no permission for clipboard access. Pinned/edited clipboard item from keyboard apps still shows up in the Android 11 native clipboard. That means that we'll have to wait for another year to see if Google can add that or improve clipboard security more. However, I like the new privacy implementation in Android 11 especially one time access and remove permissions when apps are not used for a while. Nevertheless, The best option for now when it comes to clipboard is still, don't copy and paste your sensitive personal data.

UNTRUSTED SOURCES AND MALICIOUS WEBSITES
We cannot talk vulnerabilities of copy and paste via clipboard with out talking about the main danger. For some of you that keep going to some dangerous sites that promise free movie downloads, get paid apps/games free, be careful because such sites and apps downloaded from such sites can steal sensitive personal data from your phone especially via clipboard or infecting your keyboard apps or even gain system access and that is very bad. I've had to format/wipe everything in an Android phone because of malicious attack and install everything - it's not a funny thing. So, be careful, the best and most important part of digital security is in the human factor - the proper habits, the apps you download and from where, the website you visit, the links you click, media/files you download etc

IF YOU MUST COPY AND PASTE - DO IT SECURELY! Yes, it is still paste passwords, I personally have over 300 saved passwords, you don't expect me to remember all of them by heart okay? So you have to use a password manager (there's already one in your phone by Google) you can also try other trusted passwords managers like Lastpass, Bit Warden etc. All you need to know is that main password to your password manager, secure it with 2FA too for more security and let it manage your password for you. I already done a video about that in my YouTube channel. Password managers are encrypted with the most morden 256 bit encryption can create secured passwords, and automatically fill in your passwords without using the native clipboard. You are also Warned to use passwords managers and auto fill passwords only IN TRUSTED WEBSITES AND APPS e get why - for your security.

SECURED PLATFORMS
Secure platforms due to this vulnerabilities in native clipboard are now disabling option to paste passwords and in most cases they also disable both virtual/hardware keyboard from accessing the password input section.
GTB online banking is a good example for this. They have their own secured keyboard (that scrambles the keypad every time the keyboard is called up) that inputs passwords and you are not allowed to paste passwords or use password managers auto fill. You have to know it by heart and type it in with their own keyboard app. That way they are ruling out potential vulnerabilities that comes from clipboard or copy and paste passwords. E get why these secured platforms are popping out in more apps and disabling paste passwords options and even disabling keyboards.

So, to wrap it up, if you can try updating or use Android 10 or above if you are using Android, use keyboards from trusted companies, always download and update apps from Google Play store, don't use apps that install other apps, avoid malicious websites and Apps, be careful be you click on any link (avoid shorten links as much as you can) and above all, DO NOT COPY AND PASTE YOUR SENSITIVE PERSONAL INFORMATION.

Feel free to ask me questions in the comments and come hang out with me on Twitter & IG on the same handle @smartdepotng

Stay safe!

#EndPoliceBrutality
#ENDSARS
#ReformNigieria

1 Share

(1) (Reply)

SOLD: Redmi 7 3/64gb / Guy Please Recommend Good Techno With Fast And Smart Browsing BTW 75k To 80k / Nexus 6p 3/32GB 45k Negotiable

(Go Up)

Sections: politics (1) business autos (1) jobs (1) career education (1) romance computers phones travel sports fashion health
religion celebs tv-movies music-radio literature webmasters programming techmarket

Links: (1) (2) (3) (4) (5) (6) (7) (8) (9) (10)

Nairaland - Copyright © 2005 - 2024 Oluwaseun Osewa. All rights reserved. See How To Advertise. 35
Disclaimer: Every Nairaland member is solely responsible for anything that he/she posts or uploads on Nairaland.