Hackers can pwn your Android in 10 seconds, if you use Bing App in Starbucks
blog.trustlook.com
blog.trustlook.com
thank god there is an app to protect... wait a minute... where have I seen these tactics used before...
DNS hijacking:
1. Quicker DNS response than router to pollute the Android's DNS
2. Rouge AP that pretend to be common free public wifi like "att", "starbucks", "cablewifi" or "Free Public WiFi"
3. De-authenticate valid AP connections and force user to try rouge WIFI
MITM attack: 1. ARP spoofing
This one uses Javascript Bridge vulnerability to execute high privilege code in your Android. The attack code is javascript to be interpreted to Java calls in Android.
You wouldn't be able to do that in iPhone though.
iOS doesn't bridge Javascript to _Java_ which is why this particular attack wouldn't work. But the JS<->Cocoa stuff is still pretty young, so wait and see ;)
Few people write insecure code on purpose. Of course the same is true of Safari or networking/parsing code. I still maintain certificate pinning is the answer here, to try and defend as much as possible against MITM in the first place.
I hate stories like that.
It flashes saying that the bing App got root permission. I think that's disabled unless the phone was jailbroken.
Google search is default, and for those looking for alternatives, there's also an excellent DuckDuckGo app.
(sorry, had to do it)