 dellsweigExtreme AerobaticsPremium,MVM join:2003-12-10 Campbell Hall, NY kudos:1 Reviews:
·Vonage
| something to be said for tight controls (itunes) One checkmark in the itunes model column......
»www.9to5mac.com/fraudulant-droid···aper-app
As noted - at least the flashlight/wifi router app did not steal personal information. -- Nothin' left to do but smile smile smile  |
|
 Reviews:
·Verizon FiOS
1 edit | really? You can tell that to all the people who got scammed out of money by a fraud a few months ago.
»www.macworld.com/article/152533/···aud.html
Please don't throw stones in glass houses. The App Store model is about as secure as "The Club" is on your car. |
|
 dellsweigExtreme AerobaticsPremium,MVM join:2003-12-10 Campbell Hall, NY kudos:1 Reviews:
·Vonage
| said by RiseAbove:really? You can tell that to all the people who got scammed out of money by a fraud a few months ago. » www.macworld.com/article/152533/···aud.htmlPlease don't throw stones in glass houses. The App Store model is about as secure as "The Club" is on your car. That was an issue with the App store as accessed from your PC - not an app installed on your phone access AND transmitting personal data to China -- Nothin' left to do but smile smile smile  |
|
|
|
 Reviews:
·Verizon FiOS
1 edit | said by dellsweig:said by RiseAbove:really? You can tell that to all the people who got scammed out of money by a fraud a few months ago. » www.macworld.com/article/152533/···aud.htmlPlease don't throw stones in glass houses. The App Store model is about as secure as "The Club" is on your car. That was an issue with the App store as accessed from your PC - not an app installed on your phone access AND transmitting personal data to China You can explain it all you want but in the end the Itunes store was cracked open, money was stolen and ripped off. Also if you look into it the developer of that scam he was in possibly a china or east asian location to.
You do realize in both cases personal data was stolen but in the Itunes one peoples credit cards were actually lifted and they were charged money. So the 2nd one seems a little bit more severe than the first don't you agree or is this" back Apple at all costs" day? Also have you actually thought things through? Wouldn't a large PC store hack and exploit be of a bigger issue since it tied directly to a credit card server instead of some random app just taking search history and what not? |
|
 NancymcaSecurity Goddess, retired.Premium join:2001-09-30 Voorheesville, NY | The Applestore app in question linked to an external website which acted as the conduit for theft. Thieves are not the most brilliant bunch....charging back to iTunes just made it all transparent. That's a bit different than theft which occurs directly through the app. Apple has increased their vigilance WRT in app weblinks so this is unlikely to happen again. That's an important consideration. AFAIK Google isn't vetting apps. Any action Google takes will be reactive going forward, not proactive like Apple is now doing.
One incident is a learning experience, it's the second that is going to be viewed *very* differently. -- Where's my flying car? It's 2010, they promised me there'd be flying cars. |
|
 dellsweigExtreme AerobaticsPremium,MVM join:2003-12-10 Campbell Hall, NY kudos:1 Reviews:
·Vonage
| said by Nancymca:The Applestore app in question linked to an external website which acted as the conduit for theft. Thieves are not the most brilliant bunch....charging back to iTunes just made it all transparent. That's a bit different than theft which occurs directly through the app. Apple has increased their vigilance WRT in app weblinks so this is unlikely to happen again. That's an important consideration. AFAIK Google isn't vetting apps. Any action Google takes will be reactive going forward, not proactive like Apple is now doing. One incident is a learning experience, it's the second that is going to be viewed *very* differently. You hit it right on the head!!!! -- Nothin' left to do but smile smile smile  |
|
 Reviews:
·Verizon FiOS
| reply to Nancymca said by Nancymca:The Applestore app in question linked to an external website which acted as the conduit for theft. Thieves are not the most brilliant bunch....charging back to iTunes just made it all transparent. That's a bit different than theft which occurs directly through the app. Apple has increased their vigilance WRT in app weblinks so this is unlikely to happen again. That's an important consideration. AFAIK Google isn't vetting apps. Any action Google takes will be reactive going forward, not proactive like Apple is now doing. One incident is a learning experience, it's the second that is going to be viewed *very* differently. I understand that and you make some good points but that doesn't take away from the idea of security in their respected app stores. Both suffered problems and both are probably making corrections.
My main point that I was showing the submitter was that the security isn't all that even on the App store nor is it letting someone have bragging rights. PC or Phone doesn't matter where it took place the security holes were there and should be acknowledged not explained away. |
|
 Reviews:
·CenturyLink
·Verizon Wireless..
·Mediacom
| reply to dellsweig Mobile security is the new frontier. Android is growing balls to the wall right now (last I heard around 5 mil installs/month) and these issues - inherent in an "open" ecosystem - will only get worse. Eventually you will see them be forced to implement some method of culling apps, well beyond simply removing an offending application after some period of time when a third-party investigative unit finds flaws and privacy concerns.
Apple isn't perfect, and they're not innocent. There have been a few cases of apps improperly gaining access to contact information, for example. Of course I'd much rather sacrifice my contact list on the phone rather than bank accounts and other far more critical data which we're storing more and more of on these devices. It's a huge security issue.
All in all I prefer the Apple model, despite various reservations and grumblings from time to time. Android just doesn't suit me; If it does you, that's great. But be careful! |
|
 dellsweigExtreme AerobaticsPremium,MVM join:2003-12-10 Campbell Hall, NY kudos:1 Reviews:
·Vonage
| Another take on this:
»www.tuaw.com/2010/07/29/why-appl···od-idea/ -- Nothin' left to do but smile smile smile  |
|
 Reviews:
·Verizon FiOS
| reply to dellsweig Here is Androidcentral's report on the program
»www.androidcentral.com/rogue-and···ity-firm
quote: Update: Lookout got back to us during the overnight to clarify a few things as reported in the Mobile Beat story. They're not going quite so far as to call the app "malicious," but questions remain. Read Lookout's e-mail to us after the break. We've e-mailed the apps' developer for further explanation.
Hi Jerry,
I wanted to reach out to you regarding the wallpaper app we recently discussed at Blackhat to clarify a few things.
Specifically, the wallpaper applications we analyzed proved to send several pieces of sensitive data to a server, including a device's phone number, subscriber identifier, and currently programmed voicemail number. The applications we analyzed did not access a device's SMS messages, browsing history, or voicemail password (unless a user manually programmed the voicemail number on the device to include the voicemail password).
Also, it's important to note that the applications were estimated by androidlib to have between 1 and 4 million downloads (not necessarily the same thing as 1-4 million users).
Finally, while the data the wallpaper apps are accessing are certainly suspicious coming from wallpaper apps, we're not saying that these applications are malicious. There have been cases in the past where applications are simply a little overzealous in their data gathering practices, but not because of any ill intent.
I'm happy to answer any more questions you have.
Thanks, Kevin
Kevin Mahaffey Founder, CTO Lookout, Inc.
|
|
 Reviews:
·Verizon FiOS
| Here is more of the story
»www.androidcentral.com/android-p···response
quote: The developer responds
We've been in contact with the wallpaper applications' developer today and asked exactly what information the apps collect, and why any information would be sent to a server. (That the server is in China likely is irrelevant.)
You can read the entire response below, much of which is rendered moot by Lookout's previous clarification that text message and browsing history indeed was not collected. As for what was collected, the developer told us the following: quote: I collected the screen size to return more suitable wallpaper for the phone. More and More users emailed me telling that they love my wallpaper apps so much, because that even Background cant well suited the phones screen. I also collected device id,phone number and subscriber id, it has no relationship with user data. There are few apps in Android market has the favorites feature. Many users suggest that I should provide the feature so I use the these to identify the device, so they can favorite the wallpapers more conveniently, and resume his favorites after system resetting or changing the phone.
So, that's where we stand. And this isn't necessarily a new thing for Android. Apps can have access to parts of your phone they don't necessarily need, but with no malice intended. (That's where these recent "X percent of Android apps can get at your personal data!!!" stories have come from.) It's just a matter of coding and intent, right? That said, you do need to pay attention to the the warning you get every time you install an app. Our previous example rings true: If, say, a calculator said it needed to see my text messages, I'd worry. A lot. It's either a poorly coded app, or it's up to no good. Either way, I don't want it on my phone.
Is this all FUD? When a security company says we need to be wary, we're wary -- and the fact that a security company makes its money selling security software is not lost on us. But take your time and read MaHaffey's post again. And read the developer's response again below.
The moral of the story is mind what you download, read as much as you can, and keep on top of things. Lookout's MaHaffey says so as well, ending with "Overall, our goal is to help users and developers alike across all mobile platforms to be responsible and vigilant in ensuring a safe mobile experience."
Indeed.
|
|
 SnakeoilIgnore Button. The coward's feature.Premium join:2000-08-05 Mentor, OH kudos:1 | reply to dellsweig Sad thing is: Why buy wallpaper? There are plenty of free wallpapers on the net. And you can make your own as well. |
|
 NancymcaSecurity Goddess, retired.Premium join:2001-09-30 Voorheesville, NY | reply to RiseAbove said by RiseAbove:I understand that and you make some good points but that doesn't take away from the idea of security in their respected app stores. Both suffered problems and both are probably making corrections. Apple*is* intensifying its vetting WRT in app links. That proactive stand will serve to limit the number of rogue developers looking to use an iPhone app as a information gathering conduit. Google is relying on third parties to provide information about rogue apps in the name of "openness". Which model do you think will offer better security over the long term? -- Where's my flying car? It's 2010, they promised me there'd be flying cars. |
|
 HomunculusPipsquackPremium join:2000-12-14 Dar al-Harb | reply to dellsweig And when you do get your account on iTunes compromised, don't expect Apple to be of any assistance whatsoever. -- Religion is a hatecrime |
|
 Z80APremium join:2009-11-23 | And if someone users a stolen credit card to buy a TV at Best Buy...don't expect Best Buy to give you your money back. |
|
 56403739Less than 5 months leftPremium join:2006-03-08 Naples, FL kudos:2 | reply to Nancymca said by Nancymca:Which model do you think will offer better security over the long term? The model where the user takes responsibility for what they are doing and does not rely on Apple, Google or any other huge corporation to tell them what to do.
Seriously, if you think relying on iTunes to be secure and safe is a good idea then you should really not be using third-party apps on *anything*. |
|
 dellsweigExtreme AerobaticsPremium,MVM join:2003-12-10 Campbell Hall, NY kudos:1 Reviews:
·Vonage
| reply to dellsweig Something from the security forum to add to this discussion
»Lookout for android phones -- Nothin' left to do but smile smile smile  |
|
 HomunculusPipsquackPremium join:2000-12-14 Dar al-Harb | reply to Z80A said by Z80A:And if someone users a stolen credit card to buy a TV at Best Buy...don't expect Best Buy to give you your money back. Terrible analogy. Stop thinking Apple is perfect. They aren't. -- Religion is a hatecrime |
|
 Z80APremium join:2009-11-23 | Perfect analogy. Quit acting like Apple can do no right. |
|
 Reviews:
·Verizon FiOS
1 edit | said by Z80A:Perfect analogy. Quit acting like Apple can do no right. no it's not and I don't know who perpetuated this idea that the itunes hackings of accounts was done by someone being sent to another website. I know it was stated above earlier and I should of caught it when someone threw it out there but I would like to see the evidence that Thuat Nguyen perpetrated his fraud by sending people to another website because there is no proof, in fact no idea of how he found the hole has been revealed Apple just shuffled off after they fixed the glitch. |
|