Cellular3.11.2010

Warning! Smartphones the next big security vulnerability

Most PC users have learnt to protect their system from viruses and other malware and the plethora of free PC security tools available such as avast!, AVG, and Microsoft Security Essentials, means that there’s really no good excuse for a home user to leave their computer unprotected.

But cyber criminals are constantly trying to break through these security measures and now even the good ‘ol Mac, which prides itself on being more secure than Windows, is increasingly being targeted.

According to Toralv Dirro, a security strategist for Europe, the Middle East and Africa at McAfee Avert Labs, they are seeing more and more trojans for Mac OS X.

Dirro explained that this was likely because there are are now enough Mac OS X users out there for cyber criminals to make the effort to target the platform.

Cybercriminals targeting smartphones

Smartphones have been predicted to follow a similar trend, Dirro added, and with the growing popularity of these devices it is not unexpected to see cybercriminals focusing on this group.

South Africa would be an attractive market for cybercriminals targeting mobile phones. This is due to the high number of users that can access the Internet from a mobile device compared to a computer, Dirro said.

The total number of end users that access the Internet from a computer at home are much less than overseas, so it’s pretty pointless to attack computers in South Africa, added Dirro.

To illustrate the lack of urgency from handset manufacturers to address vulnerabilities, Dirro mentioned that it took phone vendors 18 months to get updates out for vulnerabilities identified in Bluetooth implementations.

Manufacturer-agnostic versus manufacturer-specific platforms

Platforms like Android might have a particular problem as fixes to vulnerabilities may not get pushed out to devices at all, Dirro said.

Unlike platforms such as BlackBerry and iPhone for example, Android runs on devices from many different manufacturers.

While Android is a product of the Open Handset Alliance (OHA), not all Android devices receive updates as they are released. The speed at which the devices receive an update, or whether they receive an update at all, is usually decided by the individual handset manufacturers and in some cases, mobile operators.

Dirro said that “rooting” your Android device, or gaining total control of it in order to load an updated version of the operating system, is only an option for a small percentage of Android users. This is due in part to the level of technical know-how required to achieve the task.

He also added that there is always a trade-off of security against usability. Forced updates from a handset/platform manufacturer might not always be desirable for companies (or individuals) reliant on custom apps that might break due to an update.

Apps a growing security problem

Another problem is the applications available to smartphones through the “app stores” of the various platforms.

One has to hope the developers of an application aren’t malicious and place backdoors with which they can obtain personal data or use your phone for their nefarious ends, Dirro explained.

Earlier this year researchers from HP’s TippingPoint Digital Vaccine Group demonstrated how they could take over around 8000 Android and jailbroken iPhone devices and build a botnet with a seemingly innocuous weather app.

McAfee’s own labs are also researching iPhone botnets.

Dirro says that he doesn’t think the openness of the app store is a major factor in getting a malicious app distributed through the official channels. He added that a skilled developer could probably write an app with a backdoor and get it through the screening processes of app stores.

But it is not only malicious developers who pose a risk. Well-meaning developers can also inadvertently introduce vulnerabilities in their apps, noted Dirro.

While it is always suggested that smart phone users employ the basic security measures, users should remain vigilant about which websites they visit and apps they install on their smartphones. If possible they should also keep their devices updated.

Whilst McAfee are not mincing their words when it comes to keeping safe online, it’s not all doom and gloom. Cybercrime, like any other industry, tries to exploit new opportunities but often a strong dose of common sense will take you far.

Warning! Smartphones the next big security vulnerability << Comments and views

Show comments

Latest news

More news

Trending news

Poll

Which online shop do you spend the most money with?

View Results

Loading ... Loading ...
Sign up to the MyBroadband newsletter