jducoeur: (Default)
[personal profile] jducoeur
According to reports from our company's security officer (SKA TS Michael of York), the first true security exploits are starting to hit cellphones. Great.

The first one is a classic for-profit Trojan. Someone has hacked a popular cellphone game (Mosquito); the cracked version has an autodialer built into it, which secretly dials a 1-900 for-pay number. This is really a rather nice scam -- done properly, someone could make a lot of money, all the while protesting his innocence.

The second is a proper virus. It's just a proof-of-concept, but the leap from that to a working virus isn't huge. It affects Symbian phones running Bluetooth, and fortunately requires the victims to actively accept the payload, so it isn't completely automatic. Still, the history of the Internet suggests that it won't be long before someone creates a genuinely malicious mutant strain of this virus, and there has never been a shortage of people dumb enough to open attachments from unknown senders.

*Sigh*. I wish I could even be surprised by this, but I'm not at all. Everyone thinks their own product isn't going to be a malware vector, until the virii start to fly. (This is one of those moments when I really am glad to be working where I am -- all of our lead developers are both creative and paranoid about security. That doesn't make us immune to hacks, but we aren't going to make it easy...)

(no subject)

Date: 2004-08-10 05:09 pm (UTC)
From: [identity profile] metahacker.livejournal.com
Could bluejacking be used to spread the virus? If so, you've got an real autopropagator there...

Another reason I don't like "promiscuous" technology that I can't see the source of. Ah, well.

(no subject)

Date: 2004-08-10 05:59 pm (UTC)
From: [identity profile] goldsquare.livejournal.com
I believe these are both old news.... (In other news, my new company does cell software, and apparently our senior staff was visiting yours yesterday.... :-)

(no subject)

Date: 2004-08-11 01:22 pm (UTC)
From: [identity profile] goldsquare.livejournal.com
Perhaps you have seen the debunking articles on the Mosquito game on The Register? It was a failed copy-protection experiment that was removed in the real game version, but appears in the cracked versions freely available - and which is not a virus, as it requires real effort to install.

The Symbian one is more realistic - again, it is a proof of concept done by researchers, also requires active approval before installing.

Things aren't as bad as the first reports made them appear.

Profile

jducoeur: (Default)
jducoeur

October 2025

S M T W T F S
   12 34
567891011
12131415161718
19202122232425
262728293031 

Most Popular Tags

Style Credit

Expand Cut Tags

No cut tags