Light Reading
BlackBerry preps security updates for Android and iOS devices as Lookout warns consumers their mobile apps could be vulnerable.

Mobile Apps Susceptible to Heartbleed, Too

Sarah Thomas
4/14/2014
50%
50%

It's not just Internet infrastructure that's susceptible to Heartbleed, one of the most pervasive OpenSSL security threats in some time. Mobile apps may also be at risk, and several firms are offering warnings and patches to safeguard consumer phones.

The Heartbleed bug is a software flaw discovered last week in the OpenSSL "Heartbeats" function that helps keep secure Internet connections alive. The bug could potentially let cyber criminals steal endless amounts of personal data.

While concern was initially for vulnerable websites, researchers are now warning that both Google (Nasdaq: GOOG) and Apple Inc. (Nasdaq: AAPL)'s mobile operating systems could be at risk as well. As such, BlackBerry said on Monday that it would release security updates for its messaging software on Android and iOS devices by the end of the week.

BlackBerry devices themselves don't use the at-risk software, but the company tells Reuters it needs to update its Secure Work Space corporate email and BBM messaging program that are in use on Android and iOS. The risk level may be relatively low, but the company says it could infect those who use the apps either on WiFi or over the cellular network.

Technically, any app that uses the OpenSSL code is susceptible to the Heartbleed bug. Mobile security provider Lookout has put out a Heartbleed Detector app that, when downloaded by a mobile phone user, can determine what version of OpenSSL the device is using and check to see if the vulnerable feature in Hearbeats is enabled. It can't do anything about it -- that's up to Google or the device maker -- but it does alert consumers to the potential for harm.

Since the bug was unearthed, there haven't been reports of widespread damage, but it could only be a matter of time. In the meantime, companies from operators to network equipment makers to software providers are working hard to develop patches and upgrades so consumers aren't affected. (See Cisco, Juniper Treating Gear Against Potential Heartbleed and Eurobites: Telenor Counters Heartbleed Threat.)

Lookout suggests that consumers should also change their passwords, but not until told to by their individual service providers, as the vulnerability pulls data from the active memory of the affected systems, so any attackers might still have access to a new password as well.

— Sarah Reedy, Senior Editor, Light Reading

(14)  | 
Comment  | 
Print  | 
Newest First  |  Oldest First  |  Threaded View
Page 1 / 2   >   >>
SarahReedy
50%
50%
SarahReedy,
User Rank: Blogger
4/18/2014 | 3:27:03 PM
Lookout Data

Lookout has new data out from the 10,000 people who downloaded its app and agreed to share their results:

-- "Devices running Android 4.1.1 are predominantly the ones that are vulnerable, but there are also a handful running 4.2.2

-- The Evo, HTC One S and HTC One X are the 3 most popular vulnerable smartphones

-- Regions of the world vary in their level of risk. 

Here you'll find a slideshare which includes full details and the next steps on what to do if your device is vulnerable."

SarahReedy
50%
50%
SarahReedy,
User Rank: Blogger
4/17/2014 | 12:42:43 PM
Wireless okay
More updates today from AT&T, SPrint, Verizon and T-Mobile suggest they have not been affected and are taking the necessary precautions, so rest easy (but not TOO easy). 
Mitch Wagner
50%
50%
Mitch Wagner,
User Rank: Lightning
4/16/2014 | 4:33:56 PM
Re: More malware
I know, right?! EVERYBODY PANIC!!

According to that most reliable of sources, Some Guy On Reddit, iOS doesn't use OpenSSl and is therefore not susceptible, although apps might be susceptible. 
SarahReedy
50%
50%
SarahReedy,
User Rank: Blogger
4/15/2014 | 6:28:25 PM
Re: More malware
Of course, that makes sense, just like PR people latch on to events ilke this to pitch semi-related companies. I'd hope FireEye isn't making up viruses though...seems like new strands are found every day.
SarahReedy
50%
50%
SarahReedy,
User Rank: Blogger
4/15/2014 | 6:27:15 PM
Re: More malware
Thanks for the heads up, Malcom. I hope Apple issues that patch soon too.
SarahReedy
50%
50%
SarahReedy,
User Rank: Blogger
4/15/2014 | 6:26:10 PM
Re: More malware
Yikes, I guess it's starting then.
Mitch Wagner
50%
50%
Mitch Wagner,
User Rank: Lightning
4/15/2014 | 4:50:07 PM
Re: More malware
Attackers used Heartbleed to break into the Canada Revenue Agency.
Phil_Britt
50%
50%
Phil_Britt,
User Rank: Light Sabre
4/15/2014 | 2:48:01 PM
Re: More malware
To me the FireEye notification seems to be somewhat self-serving. McAfee also sent out notices, but also said that their software is not designed to protect against this type of vulnerability. It's good to get notices out, but I'm cautious any time the notice comes from someone seeking to sell a solution.
MalcolmTucker
50%
50%
MalcolmTucker,
User Rank: Light Beer
4/15/2014 | 2:39:12 PM
Re: More malware
I was performing some research into this.  Apparently, the APPLE "Airport Utility" which comes as standard software with all Mac Computers, uses the OpenSSL library. 

This is in the acknowledgements and licensing agreement feature within the Airport Utility itself.

Because the code hasn't been verified to be vulnerable, it may be best to take the Airport Utility (Located in the "Utilities" folder) and place it into the trashcan.  Apple's culture is one of secrecy and to not disclose issues until a patch is released.

Because Apple and everybody was blindsighted, it's probably best to place the Airport Utility into the trash.

Airport controls WiFi connections to Apple's own WiFi routers.  You should be able to connect to the internet, and configure your router if you use the Apple iPhone or iPad configuration app; then delete the app on your ipad until you need it again.
SarahReedy
50%
50%
SarahReedy,
User Rank: Blogger
4/15/2014 | 12:59:07 PM
Re: More malware
Yeah, it seems like most of the patches will be out in time, but we really don't know. I haven't gotten any notifications from service providers about actions to take. I was going to just change all my passwords, but sounds like that's not the wisest move, according to Lookout.
Page 1 / 2   >   >>
Flash Poll
From The Founder
It's clear to me that the communications industry is divided into two types of people, and only one is living in the real world.
LRTV Huawei Video Resource Center
Dr. Dong Sun Talks About Carriers' Digital Transformation & Huawei’s Telco OS

1|29|15   |   6:28   |   (0) comments


Dr. Dong Sun, Chief Architect of Digital Transformation Solutions at Huawei, discusses how telecom operators can become digital ecosystem enablers and deliver optimal user experiences that are in real-time, on-demand, all-online, DIY and social (ROADS).
LRTV Huawei Video Resource Center
Huawei's Chief Network Architect Talks about Network Experience & Operators’ Strategies

1|29|15   |   3:39   |   (0) comments


In the digital age, network experience has become the primary productivity especially for telecom operators. In this video, Wenshuan Dang, Huawei’s Chief Network Architect, discusses how carriers can tackle the challenge of infrastructure complexity in order to enhance business agility and improve user experience.
LRTV Documentaries
The Rise of Virtual CPE

1|27|15   |   01:38   |   (3) comments


As NFV strategies evolve from tests and trials to production telco networks, expect to hear a lot about virtual CPE (customer premises equipment) rollouts during 2015.
LRTV Documentaries
Optical Is Hot in 2015

1|23|15   |   01:56   |   (2) comments


Optical comms technology underpins the whole communications sector and there are some really hot trends set for 2015.
LRTV Custom TV
Policy Control in the Fast Lane

1|22|15   |   2:57   |   (0) comments


What's making policy control strategic in 2015 and beyond? Amdocs talks with Heavy Reading's Graham Finnie about the key factors driving change in the data services landscape. Find out what his policy management research reveals about the road ahead for policy control – and sign up for
LRTV Documentaries
Highlights From the 2020 Vision Executive Summit

1|21|15   |   4:33   |   (2) comments


In December 2014, Light Reading brought together telecom executives in Reykjavik, Iceland to discuss their vision for high-capacity networks through the end of the decade. The intimate, interactive meeting was set against the backdrop of Iceland's spectacular natural beauty. As one of the event's founding sponsors, Cisco's Doug Webster shared his company's ...
LRTV Huawei Video Resource Center
Huawei Pay-TV Partner Harmonic, Helping Carriers Accelerate 4K Video Deployment with Huawei

1|20|15   |   5:42   |   (1) comment


At IBC, Peter Alexander, Senior Vice President & CMO at Harmonic, speaks about the growing interest in pay-TV service and its branching into multiple devices.
LRTV Huawei Video Resource Center
Sony Marketing Director Olivier Bovis Discusses the Outlook for 4K and Cooperation With Huawei at IBC 2014

1|20|15   |   6:50   |   (0) comments


At IBC, Olivier Bovis, Marketing Director of Sony, speaks about the coming of the 4K era.
LRTV Huawei Video Resource Center
Huawei Pay-TV Partner Envivio, Helping Carriers Accelerate 4K Video Deployment

1|20|15   |   2:57   |   (0) comments


At IBC, Olivier Bovis, Marketing Director of Sony, speaks about the coming of the 4K era.
LRTV Huawei Video Resource Center
Pay-TV's Networked Future

1|20|15   |   6:29   |   (0) comments


At IBC, Jeff Heynen, Principal Analyst at Infonetics, speaks about the future of the pay-TV industry and its transition.
LRTV Huawei Video Resource Center
Jeff Heynen: Distributed Access Will Help MSOs Compete in the Future

1|20|15   |   2:26   |   (0) comments


At IBC, Jeff Heynen, Principal Analyst at Infonetics, speaks about moving to distributed access and the future trend of cable business.
LRTV Interviews
Cisco Talks Transformation

1|20|15   |   13:02   |   (0) comments


In December 2014, Steve Saunders sat down with Cisco VP of Products & Solutions Marketing Doug Webster at Light Reading's 2020 Vision executive summit in Reykjavik, Iceland. They spoke about Cisco's approach to network virtualization as well as how service providers can begin to monetize high-capacity networks through the end of the decade.
Upcoming Live Events
February 5, 2015, Washington, DC
February 19, 2015, The Fairmont San Jose, San Jose, CA
March 17, 2015, The Cable Center, Denver, CO
April 14, 2015, The Westin Times Square, New York City, NY
May 12, 2015, Grand Hyatt, Denver, CO
May 13-14, 2015, The Westin Peachtree, Atlanta, GA
June 8, 2015, Chicago, IL
June 9-10, 2015, Chicago, IL
June 9, 2015, Chicago, IL
September 9-10, 2015, The Westin Galleria Dallas, Dallas, TX
September 29-30, 2015, The Westin Grand Müchen, Munich, Germany
November 11-12, 2015, The Westin Peachtree Plaza, Atlanta, GA
December 1, 2015, The Westin Times Square, New York City
December 2-3, 2015, The Westin Times Square, New York City
Infographics
Hot Topics
Google Continues Gigabit Expansion
Jason Meyers, Senior Editor, Gigabit Cities/IoT, 1/27/2015
BlackBerry Wants Net Neutrality Protection – That's Just Sad
Mitch Wagner, West Coast Bureau Chief, Light Reading, 1/22/2015
Cablevision's New WiFi Try – Freewheeling Enough?
Mari Silbey, Independent Technology Editor, 1/26/2015
Overture Builds on NFV Foundation
Mitch Wagner, West Coast Bureau Chief, Light Reading, 1/27/2015
LightSpeed Looks to Plug the Gigabit Gap
Jason Meyers, Senior Editor, Gigabit Cities/IoT, 1/23/2015
Like Us on Facebook
Twitter Feed
Webinar Archive
BETWEEN THE CEOs - Weekly Executive Interview
Join us live for Light Reading's interview with Jay Samit, the newly appointed CEO of publicly traded SeaChange International Inc. With a resume that includes Sony, EMI, Universal, Intel and Microsoft, Samit brings a reputation as an entrepreneur and a disruptor to his new role at the video solutions company. Hear what he has to say about the opportunities in video, as well as the outlook for cable, telco, OTT and mobile service providers.