NewsBytes
    Hindi Tamil Telugu
    More
    In the news
    Narendra Modi
    Amit Shah
    Box Office Collection
    Bharatiya Janata Party (BJP)
    OTT releases
    Hindi Tamil Telugu
    NewsBytes
    User Placeholder

    Hi,

    Logout

    India
    Business
    World
    Politics
    Sports
    Technology
    Entertainment
    Auto
    Lifestyle
    Inspirational
    Career
    Bengaluru
    Delhi
    Mumbai

    Download Android App

    Follow us on
    • Facebook
    • Twitter
    • Linkedin
    Home / News / Technology News / OnePlus phones caught downloading GPS data over unsafe channels
    Next Article
    OnePlus phones caught downloading GPS data over unsafe channels

    OnePlus phones caught downloading GPS data over unsafe channels

    By Shubham Sharma
    Mar 31, 2019
    11:33 am

    What's the story

    OnePlus phones have always been impressive, but a new report suggests the A-GPS system of the 'flagship killers' is plagued by a critical issue.

    PiunikaWeb reports that the system has been rigged to download position data over insecure channels.

    The issue, which can have some serious consequences, has been reported and will be fixed in a future update.

    Here are the details.

    Issue

    OnePlus engineers overrode AOSP policies

    After a recent investigation of OnePlus' OxygenOS, PiunikaWeb discovered that the engineers from the company have been overriding the standard policies of the Android Open Source Project.

    They have been shipping a debug build of gps.conf, a text-based configuration file, with the OS, enabling insecure XTRA data servers.

    This could pose a major risk to the security of OnePlus customers.

    Risk

    How this poses a threat to customers

    Normally, the XTRA system, developed by Qualcomm, enables GPS receivers to pull positioning data over the internet from Qualcomm-operated servers.

    It enables faster GPS access, but with this particular change, OnePlus phones could download positioning almanac data from insecure HTTP channels.

    This insecure data transmission could ultimately allow an attacker to carry out a man-in-the-middle attack and get hold or modify the data.

    Information

    How an attacker could harm you

    In a man-in-the-middle attack, a bad actor relays/alters the communication between two parties who believe they are directly communicating. Here, the attacker could modify positioning data being transmitted from the insecure server to lead you to a completely different location which can be dangerous.

    Report

    Problem reported to OnePlus

    Following the discovery, PiunkiaWeb verified the issue with LineageOS contributor Louis Popi and - after receiving a confirmation - filed a bug report on the OnePlus forum.

    In response, the company claimed that gps.conf isn't being utilized to download positioning data on the phones from the XTRA servers and that they're aware of the issue and will fix it "in the upcoming updates."

    Quote

    Here's what Jeff H. from OnePlus Bug Hunter team said

    "The device is reading the address in Modem NV config, which is going through HTTPS instead of HTTP, and gps.conf has been already ignored, so the XTRA config won't be working," Jeff said, noting that they "will synchronize the gps.conf to HTTPS."

    Continued use

    However, PiunikaWeb says gps.conf is still in use

    Though OnePlus says gps.conf is not being used, PiunikaWeb emphasized otherwise.

    They claimed the configuration file is still being utilized to execute data download over insecure channels and have submitted further evidence to the company.

    OnePlus has not responded yet but if the claims made are true, it should not take too much time to get an update out.

    Facebook
    Whatsapp
    Twitter
    Linkedin
    Related News
    Latest
    OnePlus
    OxygenOS

    Latest

    Arvind Swami's 'Major Srinivasan' unveiled in Anupam's 'Tanvi The Great' Anupam Kher
    'The Royals' review: Bhumi-Ishaan's lifeless, hollow series tests your patience Movie Review
    Indian companies advise remote work amid escalating tensions with Pakistan India
    Chandigarh bans hoarding of essential commodities amid India-Pakistan tensions Chandigarh

    OnePlus

    OnePlus partners with Reliance Digital to boost offline sales India
    OnePlus 6T spotted on Geekbench with Snapdragon 845, Android Pie OnePlus 6
    OnePlus 6T v/s OnePlus 6: What's same, and what's different? OnePlus 6
    OPPO just tested 5G internet on a smartphone: Details here Xiaomi

    OxygenOS

    You can now buy OnePlus 5 in gold variant! India
    OnePlus 6 receives selfie portrait mode with OxygenOS 5.1.6 update India
    OnePlus 6 receives Android P Beta 2: Details here Google
    OxygenOS 5.1.8: An important update for OnePlus 6 Indian users OnePlus
    Indian Premier League (IPL) Celebrity Hollywood Bollywood UEFA Champions League Tennis Football Smartphones Cryptocurrency Upcoming Movies Premier League Cricket News Latest automobiles Latest Cars Upcoming Cars Latest Bikes Upcoming Tablets
    About Us Privacy Policy Terms & Conditions Contact Us Ethical Conduct Grievance Redressal News News Archive Topics Archive Download DevBytes Find Cricket Statistics
    Follow us on
    Facebook Twitter Linkedin
    All rights reserved © NewsBytes 2025