Your smartphone: a new frontier for hackers

  • Aquino, Trillanes, Pimentel named Senators-elect

    Aquino, Trillanes, Pimentel named Senators-elect

    Yahoo! Southeast Asia Newsroom
    Aquino, Trillanes, Pimentel named Senators-elect

    Amid questions hurled against its early partial proclamation, the poll body on Friday named three more winning Senate candidates even before it completed its official count.

  • UNA to Brillantes: Don't quit

    UNA to Brillantes: Don't quit

    Yahoo! Southeast Asia Newsroom
    UNA to Brillantes: Don't quit

    The United Nationalist Alliance (UNA) does not want Commission on Elections (Comelec) chair Sixto Brillantes Jr. to quit.

  • Why Pimentel skipped his proclamation

    Why Pimentel skipped his proclamation

    Yahoo! Southeast Asia Newsroom
    Why Pimentel skipped his proclamation

    When the poll body proclaimed Aquilino Martin "Koko" Pimentel senator-elect Friday, he joined seven of his fellow bets in the administration slate.

  • Top 6 senators proclaimed

    Top 6 senators proclaimed

    Top 6 senators proclaimed

    Newly-elected Senators Grace Poe, Loren Legarda, Alan Peter Cayetano, Francis Escudero, Nancy Binay and Sonny Angara, with the Commission of Elections en banc—sitting as National Board of Canvassers, during their proclamation as the top six winning senators, at the NBOC canvassing center, Philippine International Convention Center (PICC), Pasay City, south of Manila, on 16 May 2013, four days after the 2013 midterm elections. (Mike Alquinto/NPPA Images)

  • Dynasties sweep polls in clannish Muslim Mindanao

    Tinig Ng Botante

    By VERA Files In the clannish provinces of Muslim Mindanao, the Ampatuans remain the political family to beat, with close to 20 members of the clan winning various local positions in Manguindanao in last Monday’s election, based on the Commission … Continue reading →

LAS VEGAS (AP) — Hackers are out to stymie your smartphone.

Last week, security researchers uncovered yet another strain of malicious software aimed at smartphones that run Google's popular Android operating system. The application not only logs details about incoming and outgoing phone calls, it also records those calls.

That came a month after researchers discovered a security hole in Apple Inc.'s iPhones, which prompted the German government to warn Apple about the urgency of the threat.

Security experts say attacks on smartphones are growing fast — and attackers are becoming smarter about developing new techniques.

"We're in the experimental stage of mobile malware where the bad guys are starting to develop their business models," said Kevin Mahaffey, co-founder of Lookout Inc., a San Francisco-based maker of mobile security software.

Wrong-doers have infected PCs with malicious software, or malware, for decades. Now, they are fast moving to smartphones as the devices become a vital part of everyday life.

Some 38 percent of American adults now own an iPhone, BlackBerry or other mobile phone that runs the Android, Windows or WebOS operating systems, according to data from Nielsen. That's up from just 6 percent who owned a smartphone in 2007 when the iPhone was released and catalyzed the industry. The smartphone's usefulness, allowing people to organize their digital lives with one device, is also its allure to criminals.

All at once, smartphones have become wallets, email lockboxes, photo albums and Rolodexes. And because owners are directly billed for services bought with smartphones, they open up new angles for financial attacks. The worst programs cause a phone to rack up unwanted service charges, record calls, intercept text messages and even dump emails, photos and other private content directly onto criminals' servers.

Evidence of this hacker invasion is starting to emerge.

— Lookout says it now detects thousands of attempted infections each day on mobile phones running its security software. In January, there were just a few hundred detections a day. The number of detections is nearly doubling every few months. As many as 1 million people were hit by mobile malware in the first half of 2011.

— Google Inc. has removed about 100 malicious applications from its Android Market app store. One particularly harmful app was downloaded more than 260,000 times before it was removed. Android is the world's most popular smartphone operating software with more than 135 million users worldwide.

— Symantec Corp., the world's biggest security software maker, is also seeing a jump. Last year, the company identified just five examples of malware unique to Android. So far this year, it's seen 19. Of course, that number pales compared with the hundreds of thousands of new strains targeting PCs every year, but experts say it's only a matter of time before criminals catch up.

"Bad guys go where the money is," said Charlie Miller, principal research consultant with the Accuvant Inc. security firm, and a prominent hacker of mobile devices. "As more and more people use phones and keep data on phones, and PCs aren't as relevant, the bad guys are going to follow that. The bad guys are smart. They know when it makes sense to switch."

When it comes to security, smartphones share a problem with PCs: Infections are typically the responsibility of the user to fix, if the problem is discovered at all.

The emergence in early July of a previously unknown security hole in Apple Inc.'s iPhones and iPads cast a spotlight on mobile security. Users downloaded a program that allowed them to run unauthorized programs on their devices. But the program could also be used to help criminals co-opt iPhones. Apple has since issued a fix.

It was the second time this year that the iPhone's security was called into question. In April the company changed its handling of location data after a privacy outcry that landed an executive in front of Congress. Researchers had discovered that iPhones stored the data for a year or more in unencrypted form, making them vulnerable to hacking. Apple CEO Steve Jobs emerged from medical leave to personally address the issue.

The iPhone gets outsize attention because it basically invented the consumer smartphone industry when it was introduced in 2007. But Apple doesn't license its software to other phone manufacturers. Google gives Android to phone makers for free. So, Android phones are growing faster. As a result, Google's Android Market is a crucial pathway for hacking attacks. The app store is a lightly curated online bazaar for applications that, unlike Apple's App Store, doesn't require that developers submit their programs for pre-approval.

Lookout says it has seen more unique strains of Android malware in the past month than it did in all of last year. One strain seen earlier this year, called DroidDream, was downloaded more than 260,000 times before Google removed it, though additional variants keep appearing.

Lookout says about 100 apps have been removed from the Android Market so far, a figure Google didn't dispute.

Malicious applications often masquerade as legitimate ones, such as games, calculators or pornographic photos and videos. They can appear in advertising links inside other applications. Their moneymaking schemes include new approaches that are impossible on PCs.

One recent malicious app secretly subscribed victims up to a service that sends quizzes via text message. The pay service was charged to the victims' phone bills, which is presumably how the criminals got paid. They may have created the service or been hired by the creator to sign people up. Since malware can intercept text messages, it's likely the victims never saw the messages — just the charges.

A different piece of malware logs a person's incoming text messages and replies to them with spam and malicious links. Most mobile malware, however, keep their intentions hidden. Some apps set up a connection between the phone and a server under a criminal's control, which is used to send instructions.

Google points out that Android security features are designed to limit the interaction between applications and a user's data, and developers can be blocked. Users also are guilty of blithely click through warnings about what personal information an application will access.

Malicious programs for the iPhone have been rare. In large part, that's because Apple requires that it examine each application before it goes online. Still, the recent security incidents underline the threat even to the most seemingly secure devices.

A pair of computer worms targeting the iPhone appeared in 2009. Both affected only iPhones that were modified, or "jailbroken," to run unauthorized programs.

And Apple has dealt with legitimate applications that overreached and collected more personal data than they should have, which led to the Cupertino, Calif.-based company demanding changes.

"Apple takes security very seriously," spokeswoman Natalie Kerris said in July. "We have a very thorough approval process and review every app. We also check the identities of every developer and if we ever find anything malicious, the developer will be removed from the iPhone Developer Program and their apps can be removed from the App Store."

A criminal doesn't even need to tailor his attacks to a mobile phone. Standard email-based "phishing" attacks — tricking people into visiting sites that look legitimate — work well on mobile users. In fact, mobile users can be more susceptible to phishing attacks than PC users.

The small screens make it hard to see the full Internet address of a site you're visiting, and websites and mobile applications working in tandem train users to perform the risky behavior of entering passwords after following links, new research from the University of California at Berkeley has found.

The study found that the links within applications could be convincingly imitated, according to the authors, Adrienne Porter Felt, a Ph.D. student, and David Wagner, a computer science professor.

They found that "attackers can spoof legitimate applications with high accuracy, suggesting that the risk of phishing attacks on mobile platforms is greater than has previously been appreciated."

A separate study released earlier this year by Trusteer, a Boston-based software and services firm focused on banking security, found that mobile users who visit phishing sites are three times more likely to submit their usernames and passwords than desktop PC users.

Mobile users are "always on" and respond to emails faster, in the first few hours before phishing sites are taken down, and email formats make it hard to tell who's sending a message, Trusteer found.

Still, mobile users have an inherent advantage over PC users: Mobile software is being written with the benefit of decades of perspective on the flaws that have made PCs insecure. But smartphone demand is exploding, with market research firm IDC predicting that some 472 million smartphones will be shipped this year, compared with 362 million PCs. As a result, the design deterrents aren't likely to be enough to keep crooks away from the trough.

"It's going to be a problem," Miller said. "Everywhere people have gone, bad guys have followed."

  • Filipino assaulted by 4 Taiwanese in Tainan

    Taipei (The China Post/ANN) - Police confirmed that a Philippine worker was attacked by four Taiwanese and beaten with iron sticks and baseball bats in Tainan City on May 16 following the recent heated dispute between Taiwan and the Philippines.

  • Villar, Ejercito, Honasan named last Senators-elect
    Villar, Ejercito, Honasan named last Senators-elect

    The Commission on Elections (Comelec) will proclaim more winners in the senatorial race Saturday night, amid criticisms of "premature" proclamations.

  • Why Honasan feels bittersweet at his proclamation
    Why Honasan feels bittersweet at his proclamation

    For newly-proclaimed Senator Gregorio “Gringo” Honasan, this could be his last six years as senator.

  • Church must help the poorest, not dissect theology, pope says
    Church must help the poorest, not dissect theology, pope says

    By Philip Pullella VATICAN CITY (Reuters) - Pope Francis shared personal moments with 200,000 people on Saturday, telling them he sometimes nods off while praying at the end of a long day and that it "breaks my heart" that the death of a homeless person is not news. Francis, who has made straight talk and simplicity a hallmark of his papacy, made his unscripted comments in answers to questions by four people at a huge international gathering of Catholic associations in St. Peter's Square. ...

  • Nancy Binay shows up at her proclamation
    Nancy Binay shows up at her proclamation

    Now, she's coming. The daughter of Vice President Jejomar Binay will show up at her first proclamation as an elected official at the Philippine International Convention Center (PICC) Forum in Pasay City Saturday.

Loading...

Editor’s note:Yahoo! Philippines encourages responsible comments that add dimension to the discussion. No bashing or hate speech, please. You can express your opinion without slamming others or making derogatory remarks.

Odd Stories

  • Winning ticket for $590.5 million Powerball lottery sold in Florida

    Winning ticket for $590.5 million Powerball lottery sold in Florida

    Reuters - 8 hours ago
    Winning ticket for $590.5 million Powerball lottery sold in Florida

    By Brendan O'Brien (Reuters) - A single winning ticket for a record Powerball lottery jackpot worth $590.5 million was sold in Florida, organizers said late on Saturday, but there was no immediate word about who won one of the largest jackpots in U.S. history. The winning numbers from Saturday night's drawing were: 10, 13, 14, 22 and 52, with a Powerball number of 11. The odds of winning were put at 1 in 175 million. The winning ticket was sold at a Publix supermarket in Zephyrhills, a suburb

  • Germans blame euro zone crisis for Eurovision debacle

    Germans blame euro zone crisis for Eurovision debacle

    Reuters - 9 hours ago
    Germans blame euro zone crisis for Eurovision debacle

    BERLIN (Reuters) - Germans lamented their unexpectedly poor showing at the Eurovision Song Contest, blaming Chancellor Angela Merkel's tough stance in the euro zone crisis for their failure to win any points from 34 of the 39 countries voting. Denmark's Emmelie de Forest won the event, watched by around 125 million people across Europe, with 281 points while German act Cascada was 21st out of 26 countries, getting just 18 points from Austria, Israel, Spain, Albania and Switzerland. ...

  • Powerball jackpot could go higher than $600 million

    Powerball jackpot could go higher than $600 million

    Reuters - Sun, May 19, 2013
    Powerball jackpot could go higher than $600 million

    By Karen Brooks AUSTIN, Texas (Reuters) - The Powerball jackpot Saturday night could exceed the $600 million figure being advertised, possibly rivaling the largest lottery payoff in U.S. history, a Texas Lottery official said on Saturday. "Oftentimes, the advertised amount is lower than what the actual jackpot ends up being," said Kelly Cripe, a spokeswoman for the Texas Lottery. "It's entirely possible this $600 million jackpot will end up being a bigger jackpot. ...

  • Denmark favorite to win Eurovision Song Contest

    Denmark favorite to win Eurovision Song Contest

    AP - Sat, May 18, 2013
    Denmark favorite to win Eurovision Song Contest

    MALMO, Sweden (AP) — An ethno-inspired flute and drum tune from Denmark is the bookmakers' favorite to win this year's Eurovision Song Contest on Saturday, which also features a bizarre opera pop number from Romania and an Armenian rock song written by the guitarist of Black Sabbath.

  • Canadian astronaut wrestles with gravity after spaceflight

    Canadian astronaut wrestles with gravity after spaceflight

    Reuters - Fri, May 17, 2013
    Canadian astronaut wrestles with gravity after spaceflight

    By Irene Klotz CAPE CANAVERAL, Florida (Reuters) - Back on Earth, Canadian astronaut and cyberspace tweeter Chris Hadfield is getting a rough re-introduction to gravity after a five-month stint aboard the International Space Station, the former commander told reporters during a video webcast from Houston. Hadfield became a social media rock star with his zero-gravity version of David Bowie's "Space Oddity" and a continuous stream of commentary on Twitter about his life in orbit. But living

  • Basketball, brotherhood, and beating a bleeding disease VERA Files - The Inbox

    By Lean Carlo Macoto, VERA Files Like the vast majority of Filipino men, Raymund Nanos is a huge basketball fan. His favorite sport is basketball. His favorite pastime is watching basketball. Those who don’t know him would probably think he … Continue reading →

  • 25 years of feeding a city’s body and soul VERA Files - The Inbox

    Text and photos by Elizabeth Lolarga, VERA Files It is apropos that a café founded by artists, writers and other individuals who operate outside society’s margins should mark its 25th year as a now respected Baguio institution with music, poetry … Continue reading →

  • A festival to celebrate 133rd birthday of Sarung Banggi composer VERA Files - The Inbox

    By Pablo A. Tariman, VERA Files Bicol composer Potenciano Gregorio-- who penned the famous Bicol love song, “Sarung Banggi”-- turns 133 on Saturday (May 18) with a festival carrying the name of his composition. But his famous love song has … Continue reading →

  • Filipino workers paying the price for Malacañang’s bungling Ellen Tordesillas, Contributor - The Inbox

    Commentary By Ellen Tordesillas It took a week for President Aquino to realize that the killing of a Taiwanese fisherman by a member of the Philippine Coast Guard team in the disputed waters of South China Sea could lead to … Continue reading →

  • Hot water treatment produces sweet, juicy mangoes VERA Files - The Inbox

    By Leilanie G. Adriano, VERA Files At the warehouse of farmer Ricardo Tolentino in Laoag, Ilocos Norte are the sweetest and juiciest mangoes, courtesy of a hot water treatment developed at the Mariano Marcos State University (MMSU). The technology was … Continue reading →

POLL
Loading...
Poll Choice Options