Nokia ‘Xpress’ browser faces privacy concerns

January 13, 2013 12:00 am | Updated January 30, 2013 08:57 pm IST - CHENNAI:

22mp Nokia Asha 303

22mp Nokia Asha 303

The fast-loading default browser used on most Nokia mobile handsets, including its ‘Asha’ range, appears to be a double-edged sword.

While the ‘Xpress’ browser is quick and used on resource-constrained devices that cannot run a full-fledged web browser, it appears that it decrypts data that flows through its ‘HTTPS’ connections – giving the company the ability to peep at connections set up for banking session, encrypted email and the like.

“From the tests that were performed, it is evident that Nokia is performing a ‘man in the middle attack’ for sensitive HTTPS traffic originating from their phone – and, hence, they have access to information which could include user credentials to various sites such as banking and social networking,” said Gaurav Pandya, a security analyst at Unisys Global Services India.

Nokia, in a statement, however has rejected claims that it might be spying on its user’s encrypted Internet traffic but admitted that it temporarily decrypts secure HTTPS connections for the benefit of customers.

“The compression that occurs within the browser means that users can get faster web browsing. When temporary decryption of HTTPS connections is required by our proxy servers, it is done in a secure manner. Claims that we would access complete unencrypted information are inaccurate,” a company spokesperson said.

0 / 0
Sign in to unlock member-only benefits!
  • Access 10 free stories every month
  • Save stories to read later
  • Access to comment on every story
  • Sign-up/manage your newsletter subscriptions with a single click
  • Get notified by email for early access to discounts & offers on our products
Sign in

Comments

Comments have to be in English, and in full sentences. They cannot be abusive or personal. Please abide by our community guidelines for posting your comments.

We have migrated to a new commenting platform. If you are already a registered user of The Hindu and logged in, you may continue to engage with our articles. If you do not have an account please register and login to post comments. Users can access their older comments by logging into their accounts on Vuukle.