This has got to be the most embarrassing security holes I have ever heard of on a platform delivered by a major company. It is so wildly outrageous that it should serve as grounds to seriously consider whether or not one should trust the guys at Google who are working on the Android platform. There is simply no excuse for them to have a terminal open in the background on the phone, with all commands executed as root, and to have all input from the keyboard piped to it.
Not even Microsoft has been this bad.
Not even Microsoft has been this bad.
This has been fixed in the RC30 release last week which also blocks root access (jail breaking).
,Michael Martin
http://www.googleandblog.com/