Showing posts with label trojan horse. Show all posts
Showing posts with label trojan horse. Show all posts

Wednesday, 17 July 2013

Bluebox uncovers Android's Master Key

If you've kept in the loop at all with news on Android, you will have noticed a security company named Bluebox who discovered a vulnerability in Android that allows a hacker to modify the code of an APK file, i.e. an app, without changing the signature of the app. Essentially they could change the code and we, the end user would be none the wiser when we download this app as Android would not be able to tell that the app has been tampered with. Obviously this is a problem but do we need to panic?

How bad is it?
According to Bluebox, this vulnerability affects 900 million Android devices or 99 per cent of Android devices out in the wild. Any phone with Android 1.6 or above possesses this vulnerability so more or less anyone with an Android smartphone. These at first are pretty scary figures and you are more at risk if you install apps from a third-party source as they are generally less well regulated and more susceptible to being tampered with. If you like to try new apps and venture into apps made by individuals then that probably increases your risk even more, but we could go on and on about what increases your risks. 

Is there a fix?
A fix has been released by Google but it is up to manufacturers to implement it onto their devices and some have been slower to do so than others. Given the seriousness of this, most manufacturers have patched their devices but some have still not. It would be worth finding out if the manufacturer of your phone have taken steps to patch this vulnerability and if not, getting in touch and letting them know your concerns. Most companies nowadays take customer opinions much more seriously than they used to so it is a worthwhile method of making yourself heard.

Anything else to do?
Bluebox have since released an app that scans your device, checks to see if it is patched, and whether or not you have apps that have been tampered with. To download the app, follow this link. If your device is patched then your phone manufacturer has taken steps to prevent this vulnerability and if you do not have any apps that are infected then you're pretty safe. Otherwise, take the advised steps given by the app.

Conclusion
We can't underestimate the importance of vulnerabilities like this. To put it into perspective, your phone data could be available to a hacker if you install an app that has been tampered with. Even if you have nothing to hide, you will no doubt not want all your personal information and perhaps sensitive information being available to a total stranger who is up to no good!

Mo

Friday, 29 March 2013

Permissions and Warnings - should we pay more attention?

If you've ever installed an app on your phone (who hasn't?) then you'll have seen a list of permissions an app requests before being installed. You've probably also come across warnings on Android, but how much attention do we really pay to either of them? I think too many people blindly agree to a lot of things on their phone without fully understanding what they're asking for, similar to how we always click the little check-box asking if we agree to the T&Cs when we're signing up to stuff.

You have been warned

You rarely get warnings on Android but when you do, make sure you know what you're agreeing to before clicking to go ahead. I've picked the two below that I want to talk about, partly because I was quickly trying to find warnings to use as examples (it's harder than you think!), but mainly because I think they are very important to have a think about. The first is the location services using Google's database, it might seem innocent enough but have you ever had WiFi at your house and gone on Google Maps only to find your location given to a couple of feet without GPS? Chances are that it was your phone that transmitted your WiFi and its location to Google, who are now able to give you an accurate location by only using WiFi. This service constantly runs in the background when WiFi is on and you are not connected to any network. This happens because data is collected from all the networks your phone comes across. As it states, data can be sent back to Google even when there are no apps running, so when your phone is in your pocket this is likely to be happening too. 


Now I might make this seem really evil, but in fact it's not that bad. If you think about it, a database such as this is most effectively built by using thousands of phones to relay data back because of the nature of what's being collected. Basically because WiFi networks come and go quickly, it would never make sense for Google to independently collect this sort of data. Still, bearing in mind what it actually does, at least now you can make a better informed decision about whether you want this going on or not right?


The next warning I want to look at was the input method whereby it warns you about any application potentially being able to collect sensitive data you input onto your phone. I think this one is more serious than the last as it depends more on the app that will handle your input. There are a lot of keyboards on the Play store, but how can you be totally sure that the one you're using right now isn't storing and sending your data to a server about what you've just written? I'm not saying that keyboards on the Play store are doing that, but I think people should take care when trusting apps with their sensitive details. As with all apps, if you're getting it from somewhere that's not the Play store then you should really be wary as apps are very easy to manipulate and what might seem like a legit copy of a keyboard app could be an altered version to record all your keystrokes. You just never really know.


Permission to do what?
Well permission to do a lot of things actually! Permissions are basically rights you give an app in terms of what it can and can't do on your phone. I've taken Viber as an example as it requests a long list of permissions but I think you should have a little flick through the permissions any app requires before installing it just in case you find something that doesn't quite add up. This isn't a witch hunt against Viber as it's an over-the-top service provider like Skype or Whatsapp so they require various permissions, whilst sometimes a permission might only be required for a small thing, such as verifying your phone number at the beginning. You might also notice the system tools permission, which might seem a bit scary at first and hard to work out why an app would need it but for something like Viber, if you receive a call then the app needs to be able to disable your lockscreen to allow you to answer.



These permissions are somewhat expected of a messaging and calling app, to be able to access your contacts and logs to extract and match who uses Viber on your phone. Nothing really that worrying here but again, it's always good to have a think about how an app would use these permissions and how they could potentially abuse them too. 


I don't mean to scare anyone or cause paranoia, but giving permissions a bit of thought before you blindly accept it on your phone might save you a headache or two further down the line, especially at a time when Android is becoming so popular that malware is being created specifically for it.

Mo



Saturday, 2 March 2013

Virus scanner for your phone? Hell no!

Are they being serious when they say you need to have a virus scanner for your Android phone? I never understood who 'they' were and why 'they' recommend this but no doubt a lot of people have virus scanners on their phone. Phones are becoming more like computers nowadays, but I'm still adamant that 'they' are giving the wrong advice to people about this topic.

The Play Store and Malware

Android is not Windows, it doesn't need a virus scanner unless you're really pushing the envelope in terms of dodgy activities on your phone. For the average user of an Android smartphone, downloading apps from the Play store, browsing the web, checking social networking and so on are all perfectly safe tasks that you can do without the worry of malware (malicious software; an umbrella term for viruses, worms, trojan horses and so on). Sure there have been reports of malicious apps making their way onto Google's Play Store but Google is constantly monitoring the apps that are published on there using Bouncer, an automated system checking all apps published. Google also remotely monitor apps that are installed on phones to prevent an app that is later flagged as a virus or one might have been downloaded from a third party source remaining on the end user's phone. This technique might seen invasive but think of it as someone doing the rounds on the apps you have installed rather than rifling through your personal details.

Safest way to download

There are many ways that users can prevent a virus or other types of malware making their way onto their phones. It takes just a little bit of vigilance which will save you a lot of headache. The easiest way is to download apps from the Play Store as opposed to other sources. This will dramatically reduce the chances of having malware on your phone as any app on the Play Store will have gone through Google's checks before being made available. After all, when you download an app you only see the file size and you unless you're a programmer, you don't even know what the app contains. You end up having to trust the source you downloaded the app from. There are literally thousands of apps on the Internet that you could potentially download that would fool you into thinking they are genuine when really, they are running background processes doing who knows what to your phone.

Permissions, permissions, permissions!

Always check the permissions of any app you download. This might seem a bit time consuming but it's definitely worth doing. Always think about the app you are about to download to see if you can justify why they need the permissions stated. Most developers avoid asking for permissions which aren't required by their app as it arouses suspicion. You should also be wary of an app that requires new permissions during an update. Developers usually justify the reason for new permissions but think about whether it's actually needed or not. If not, simply don't update the app and voice your concerns to the developer.

Play in my Sandbox?

Android has a sandboxing feature which basically separates each application so that it only acts within certain parameters, namely the permissions it has been granted by you. This means applications cannot interact with each other so if a malicious app tries to read your contacts, it will simply fail if it does not have the specific permission. This is a very handy feature to prevent any apps running rampant on your phone. This feature doesn't allow apps to completely corrupt the phone's memory either, like you might see with other operating systems. The memory for each app is sandboxed too so if an app attempts any such thing, it will just end up crashing itself and nothing else, very handy if you end up in that situation. This safety feature drastically limits the damage a rouge app can do but doesn't eradicate the problem completely as the app can still carry out tasks within its given permissions which is why it is vital to check the permissions an app is asking for before installing.

Still not convinced?

If you're still worried about malware then obviously I can't stop you downloading a virus scanner but just bear in mind the safety features and failsafes built into Android and the common sense that you, as a user, can apply when downloading apps. Then make sure you free yourself from battery draining virus scanners!

Mo