Well, I don't think this is a surprise to anyone.
Per a report by Alcatel-Lucent's Kindsight Security Labs (you can read it HERE.), Android malware has increased 6 fold to over 120,000. The bulk of these are Trojans of various sorts (the report gives you a breakout of the top ones).
Yesh.
And, sadly, this also shows the weakness of application signing to weed out the malware. We've already seen issues with Google's Bouncer keeping out the bad stuff, as well as what BlueBox recently found. (see my prior posts on both of these matters).
Related, they also show an increase in infected home networks. Again, not a big surprise if you think about it. Most people who setup home networks have little or no IT (much less IT Security) background.
For a good overview article, read THIS from Ziff-Davis.
Again, what I see here could be addressed by a couple of things.
1. Obviously Bouncer needs to be improved. BUT people can't rely upon it solely.
2. People need to be encouraged to install anti-malware apps on their smartphones. Ideally, just as with most PC that come preinstalled with a commercial AV program (usually with a set period of free use), we need to start seeing smartphones come pre-installed with SOME kind of anti-malware app. AND those people writing and putting out books/magazines on smartphones need to include security apps as part of their recommended installs people should have on their smartphones.
Wednesday, July 24, 2013
Tuesday, July 16, 2013
Another "micro-PC"
Just learned about this compact, and inexpensive PC: the Utilite.
At this point its just announced, but the company has a prior product line called the "Trim-Slice", so they do have a track record.
For about a $100, you get a small (very small) case with a powerful CPU, 4G Ram, 128G storage, and plenty of connections (USB, Gigabit ethernet, etc). Can run Linux or Android.
So now yet another power small computer that could be used for some interesting activities. A possible competition for the Raspberry Pi or Beaglebone. (tho I don't think so, they are focused on different markets).
At this point its just announced, but the company has a prior product line called the "Trim-Slice", so they do have a track record.
For about a $100, you get a small (very small) case with a powerful CPU, 4G Ram, 128G storage, and plenty of connections (USB, Gigabit ethernet, etc). Can run Linux or Android.
So now yet another power small computer that could be used for some interesting activities. A possible competition for the Raspberry Pi or Beaglebone. (tho I don't think so, they are focused on different markets).
Wednesday, July 10, 2013
UPDATE: Android "Master Key" Security issue
Some updates on the Android "Master Key" issue brought up by Bluebox Security.
Per THIS article at TechCrunch, Google has patched the issue.
HOWEVER, before anyone starts to think this is over, keep in mind this means that Google has created a patch and given it to their partners. THEY then need to test this patch with their released versions of Android for their devices (and realize that this issue goes back to earlier versions of Android which most manufacturers are no longer patching). And THEN they will release the patch to the carriers so they can test it before its released. This isn't like Windows Update.
As noted, most of the manufacturers are only maintaining the newer versions of Android they've released (usually just Jelly Bean), so who knows what this means for those stuck at prior versions.
Also, Bluebox has created a scanner that will tell you if you Android device is vulnerable. I thought THIS article was a pretty good response to that news.
Per THIS article at TechCrunch, Google has patched the issue.
HOWEVER, before anyone starts to think this is over, keep in mind this means that Google has created a patch and given it to their partners. THEY then need to test this patch with their released versions of Android for their devices (and realize that this issue goes back to earlier versions of Android which most manufacturers are no longer patching). And THEN they will release the patch to the carriers so they can test it before its released. This isn't like Windows Update.
As noted, most of the manufacturers are only maintaining the newer versions of Android they've released (usually just Jelly Bean), so who knows what this means for those stuck at prior versions.
Also, Bluebox has created a scanner that will tell you if you Android device is vulnerable. I thought THIS article was a pretty good response to that news.
Tuesday, July 9, 2013
Mission Critical's Information Security Technology Showcase South Florida- Sept 19th
One of the local South Florida IT security resellers, Mission Critical Systems hosts several Technology Showcases each year. These showcases bring together several IT security vendors. Yes, there is the standard sales pitches from them in the Exhibit hall, but what is great is the series of presentations from each of the vendors that avoids being just a sales pitch. This puts the event on a different level, in my opinion.
Another ones of these is coming up in the South Florida area on September 19, 2013. Registration for the event is already open at their website HERE. This will be held at the Seminole Hard Rock Casino and Hotel in Davie, Florida.
Disclaimer: I am NOT connected in any way with Mission Critical. I don't work for them, I don't do business with them. I do know several of the people who work there, that's it. So I don't gain anything from promoting this event.
Another ones of these is coming up in the South Florida area on September 19, 2013. Registration for the event is already open at their website HERE. This will be held at the Seminole Hard Rock Casino and Hotel in Davie, Florida.
Disclaimer: I am NOT connected in any way with Mission Critical. I don't work for them, I don't do business with them. I do know several of the people who work there, that's it. So I don't gain anything from promoting this event.
Motorola Mobility Smartphone Security issue: "Motorola is listening"
I recently learned of an interesting article: "Motorola is listening". Certainly in this times of heightened attitudes about data privacy, I think its important that people be aware of these things.
In a nutshell, the author discovered that his Motorola smartphone (a Droid X2) was sending a LOT of information to Motorola, despite not having Motoblur.
Now, a word about Motoblur. Motorola Mobility rolled out this program as an enhanced UI for their earlier Android phones. You initially couldn't use your phone without signing up with the Motoblur service. You were encouraged to enter all your username and passwords for the various services you used (email accounts, twitter, facebook, etc), and it would give you alerts. What I think most people didn't know was that this information was actually stored on Motorola's servers. It's was kind of a cloud service without you realizing it. I think this was done probably as you moved from phone to phone, you could just log back into your Motoblur account on your new phone and have all your settings there.
But people hated Motoblur, and later versions were less intrusive. AFAIK, in their most recent phones (the newest RAZR line), Motoblur is gone. But they still use Motoblur for some things. (When I was "dogfooding" new versions of Android on a RAZR M, the updates were sent to my phone via Motoblur). I had to deal with Motoblur on my original Atrix 4G. But I don't recall dealing with it on my Droid Bionic, and certainly didn't have it on my RAZR M.
The author's phone, AFAIK, doesn't have Motoblur, BUT it is interesting (and a bit scary) that Motorola Mobility still seems to be gathering information from his phone. He has asked people with different models of Motorola phones to test them (he provides the tool he used) and report back on their results. I recommend people take a look at this article for updates. He has already put up several based on feedback. Will be interesting to see where this goes.
And what about other companies? Are Apple, Samsung, HTC, etc doing something similar?
In a nutshell, the author discovered that his Motorola smartphone (a Droid X2) was sending a LOT of information to Motorola, despite not having Motoblur.
Now, a word about Motoblur. Motorola Mobility rolled out this program as an enhanced UI for their earlier Android phones. You initially couldn't use your phone without signing up with the Motoblur service. You were encouraged to enter all your username and passwords for the various services you used (email accounts, twitter, facebook, etc), and it would give you alerts. What I think most people didn't know was that this information was actually stored on Motorola's servers. It's was kind of a cloud service without you realizing it. I think this was done probably as you moved from phone to phone, you could just log back into your Motoblur account on your new phone and have all your settings there.
But people hated Motoblur, and later versions were less intrusive. AFAIK, in their most recent phones (the newest RAZR line), Motoblur is gone. But they still use Motoblur for some things. (When I was "dogfooding" new versions of Android on a RAZR M, the updates were sent to my phone via Motoblur). I had to deal with Motoblur on my original Atrix 4G. But I don't recall dealing with it on my Droid Bionic, and certainly didn't have it on my RAZR M.
The author's phone, AFAIK, doesn't have Motoblur, BUT it is interesting (and a bit scary) that Motorola Mobility still seems to be gathering information from his phone. He has asked people with different models of Motorola phones to test them (he provides the tool he used) and report back on their results. I recommend people take a look at this article for updates. He has already put up several based on feedback. Will be interesting to see where this goes.
And what about other companies? Are Apple, Samsung, HTC, etc doing something similar?
Friday, July 5, 2013
More on TOR
I recently posted on the Onion Pi, using a Raspberry Pi as a TOR (The Onion Router).
As noted, for those wanted to learn more about TOR, check out their site HERE.
If you are one of those people that think only "naughty people" will want to use this device, you should check out their site.
Or better yet, watch this recent video from reason.tv which talks about it and the reasons why some would want privacy on the Internet:
As noted, for those wanted to learn more about TOR, check out their site HERE.
If you are one of those people that think only "naughty people" will want to use this device, you should check out their site.
Or better yet, watch this recent video from reason.tv which talks about it and the reasons why some would want privacy on the Internet:
New Android Security hole
So am not the first to bring this to others attention. I've seen several articles on it over the last week on the Android "Master Key" vulnerability.
Basically, researchers at Bluebox Security have found this security hole that has been present in all version of Android since v1.6. The firm informed Google about this in February. The Samsung Galaxy S4 supposedly has been patched for it. No word on any other Android device.
More information on it will be forthcoming at the Black Hat Security Conference. But for right now, you can check out their blog posting HERE on it.
Now, a basic thing about this issue is that it is exploited by malicious apps. And malicious apps, despite tools like Bouncer in the Google Play Store, can still be put up there. Patching Android is always a tough thing, because the process has to include both the manufactors and the carriers. According to a recent item on CIO, Google has already updated Play Store to block apps that take advantage of the issue. But I hope people see that as only a stop gap to getting the Android OS itself patch.
For those interested, here are the articles I've see so far on this:
Bluebox Blog
Techcrunch
Android Central
CIO
Basically, researchers at Bluebox Security have found this security hole that has been present in all version of Android since v1.6. The firm informed Google about this in February. The Samsung Galaxy S4 supposedly has been patched for it. No word on any other Android device.
More information on it will be forthcoming at the Black Hat Security Conference. But for right now, you can check out their blog posting HERE on it.
Now, a basic thing about this issue is that it is exploited by malicious apps. And malicious apps, despite tools like Bouncer in the Google Play Store, can still be put up there. Patching Android is always a tough thing, because the process has to include both the manufactors and the carriers. According to a recent item on CIO, Google has already updated Play Store to block apps that take advantage of the issue. But I hope people see that as only a stop gap to getting the Android OS itself patch.
For those interested, here are the articles I've see so far on this:
Bluebox Blog
Techcrunch
Android Central
CIO
Subscribe to:
Posts (Atom)