$bbtitle
Apple Stock: 252.17 ( 0.00 )
RSS RSS Twitter Twitter
Search:
AppleInsider.com Archives News Bytes Reviews Anonymous Mailer Submit Story AppleInsider Forums Mac Prices Polls Advertise on AppleInsider Contact AppleInsider
Hot Topics: Apple TV, iPod nano, iPod touch, iPod shuffle, iTunes 10, iOS 4.1, iOS 4.2
Save up to $300 on MacBook Pros, $180 on iMacs, and $150 on MacBooks: Mac Pricing Guide updated September 2nd (Find the best prices on Macs).
Share
Thursday, July 29, 2010

Millions of Android users hit by malicious data theft app (u)

By Daniel Eran Dilger

Published: 12:00 AM EST

An app distributed by Google's Android Market has collected private data from millions of users and forwarded it to servers China, validating Apple's uniquely strong stance on mobile security in the iPhone App Store.

The exploit, tied to an app that appeared to simply load free custom background wallpapers, was downloaded "anywhere from 1.1 million to 4.6 million times. The exact number isn’t known because the Android Market doesn’t offer precise data," according to a report by Dean Takahashi of VentureBeat.

The app "collects a user’s browsing history, text messages, your phone’s SIM card number, subscriber identification, and even your voice mail password. It sends the data to a web site, www.imnet.us. That site is evidently owned by someone in Shenzhen, China," the report noted (see the update by Lookout below).

The data upload was only discovered afterward, through forensics performed by mobile security firm named Lookout which sells virus and malware protection software for Android, Windows Mobile and BlackBerry devices. The problem was announced at the Black Hat security conference being held in Las Vegas.

(Update: Lookout has clarified in followup comments with AppleInsider that the intent of their "App Genome Project" research was to "identify security threats in the wild and provide insight into how applications are accessing personal data and other phone resources."

The group noted that the Android wallpaper app was "not proven to be malicious," but that the app does "ask the user for specific information around the phone details and that information is transferred to a server [in China]."

Correcting the original VentureBeat story, Lookout stated that "the apps from these developers send several pieces of sensitive data to a server, including a device’s phone number, subscriber identifier, and currently programmed voicemail number. The applications we analyzed did not access a device’s SMS messages, browsing history, or voicemail password (unless a user manually programmed the voicemail number on the device to include the voicemail password)."

Lookout also reiterated there is "no proof of malicious intent and in the past apps have been a bit overzealous in getting access to sensitive data with no ill intent." Lookout compared the Android wallpaper app copying local data to a Chinese server with a recent App Store title that purported to be a flashlight app while actually including a hidden SOCKS proxy that could be used for tethering.

Lookout added that it hasn't "yet" published a report detailing the Android wallpaper app, suggesting that it is continuing to look at the situation.)

Mobile data theft on the increase

The issue recalls a recent AT&T website leak that could hypothetically have enabled a malicious hacker to access 144 thousand of iPad 3G user's email addresses.

However, the Android app data theft was actually perpetrated by malicious hackers and not just demonstrated by researchers; it involves far more sensitive data; and affected far more victims--by more than an order of magnitude.

iOS vs Android in app security

Apps on any platform can access personal data and forward that data to an external server, but the Lookout research found that 47 percent of the selection of Android apps it looked at incorporated third party code (which may include malicious functions), while only 23 percent of analyzed iPhone apps did.

Apple also approves iOS apps through a strict vetting process before listing them in the App Store, while Google's Android Market app security involves simply warning the user that an app needs permissions to perform certain functions during the install.

Unlike other mobile platforms secured by Lookout, Apple's iOS platform doesn't have a live virus problem because third party iPhone apps can only be distributed through Apple's curated App Store, and apps are forced to run in a segregated sandbox environment where they can't infect the system. That doesn't necessarily mean iOS apps can't forward user data inappropriately however; Apple has discovered and pulled apps that have violated its privacy policies.

Apps must also be signed by a certificate created by Apple, which makes it much harder for malicious developers to anonymously distribute software designed to cause problems or steal data. Apple's security measures also make such efforts less attractive financially, despite the iOS platform's installed base being much larger than Android's.

Exploitable vulnerabilities in the iOS platform have been reported elsewhere, including the Safari browser, but crafting a malicious attack via the browser requires luring users to a malicious site rather than simply distributing a bad app that appears to be useful and genuine.

Lookout chief executive John Hering said in the report that "he believes both Google and Apple are on top of policing their app stores, particularly when there are known malware problems with apps," but the report noted it's "unclear what happens" when apps don't actually do what they represent.

Filed under : Software, iPhone 216 Comments ] 
Story topics: iOS, Android, Google, Apple, Windows Mobile, App Store, Security, apps, BlackBerry   Print ] [ Story Link ] 

Mac Connection End of Summer Sale
MBP Model
Price
Discount
MacBook Model
Price
Discount
2.40GHz 13" MBP $1,049.00 $150.00 2.4GHz 13" MacBook $849.00 $150.00
2.66GHz 13" MBP $1,299.00 $200.00
iMac Model
Price
Discount
2.40GHz 15" MBP $1,599.00 $200.00 3.06GHz 21.5" iMac $1,049.00 $150.00
2.53GHz 15" MBP $1,729.00 $270.00 3.20GHz 21.5" iMac $1,349.00 $150.00
2.66GHz 15" MBP $1,899.00 $300.00 3.20GHz 27.0" iMac $1,529.00 $170.00
2.53GHz 17" MBP $1,999.00 $300.00 2.80GHz 27.0" iMac $1,819.99 $180.00
RSS


AppleInsider Features
Hot Forum Topics

Recent Articles
Apple posts iPad iOS 4.2 "Coming Soon" page
Google planning music store to take on Apple
First look: Taking HDR photos with Apple's iOS 4.1
Apple issues fourth beta of Mac OS X 10.6.5 to developers
Google disputes Apple's indirect claims about Android activations
Apple's Jobs says 'onerous terms' kept Facebook ties out of Ping
Apple aiming to improve syncing, sorting of cloud-based content
Wall Street views new Apple TV as small step, not living room revolution
iTunes 10 now available for download
Amazon offers purchases of Fox and ABC shows for 99 cents
New Apple TV runs same custom A4 processor as iPhone 4, iPad
Apple's AirPlay to stream photos, video from iPhones to HDTVs
Apple's iOS 4.1 ships Sept. 8, will fix proximity sensor, add HDR photos [Ux2]
Apple's iPod classic survives another year, but sees no changes
Apple reveals new cloud-centric Apple TV for $99
Apple introduces iTunes 10 with Ping social music network
Apple unveils new iPod touch with Retina Display, forward-facing camera
Apple announces new iPod nano with multi-touch display
Apple adds buttons to new fourth-generation iPod shuffle
iOS 4.2 for iPad coming in November, adds wireless printing and Air Play
Live updates from Apple's September 1st Media Event
Apple posts live stream of special event keynote
New Apple TV, iPods to debut today, won't ship immediately - report
Intel CEO says he asked Steve Jobs' opinion on Infineon deal
Fox, ABC agree to give Apple 99-cent TV rentals
Videos emerge of possible iPod Touch, iPod Nano parts
Amazon working on streaming subscription video service
Apple to offer live video stream of Wednesday's keynote
New Apple TV with Netflix streaming to be unveiled Wednesday - report
Palm unveils webOS 2.0, SDK available to developers
Apple's new iPod nano to maintain price points, won't push out shuffle - sources
Mexico's Telcel claims iPhone 4 antenna hardware fix in the works
Patent suit challenges motion-based input with Apple's iPhone 4
Rupert Murdoch may be swing vote in Apple's 99 cent TV rental pitch
Mac OS X version of AutoCAD due out in October
iTunes survey asks about instant streaming video
Apple expected to boost iTunes song samples to 60 seconds
AMD reveals plans to retire ATI graphics brand
Owner of location-based advertising patent targets Apple's iAds
Antitrust review of Comcast-NBC deal considers effect on Apple's iTunes

Advertisements







AppleInsider RSS Feed
AppleInsider © 1997-2008
Please review our Privacy Policy.
Written/Edited/Compiled by the AppleInsider Staff.