Light Reading Mobile – Telecom News, Analysis, Events, and Research

LR Mobile Column  

Smartphones: The New Hacker Frontier

September 03, 2010 | Denise Culver | Research Analyst |

In the first quarter of 2010, statistics show that global smartphone shipments topped 54 million – a 57 percent jump from the previous year. With such growth, it should come as little surprise that hackers are adapting their tested methods for infecting computers to attack Internet-enabled mobile and smartphones.

To date, the biggest smartphone breach occurred on Google Android phones. Users that downloaded certain wallpaper applications actually opened their phones up to hackers who harvested the phone and voice-mail numbers, as well as data used to disclose a user's physical location. The wallpapers were downloaded more than 1 million times, and information was transmitted to a Chinese Website. In one week, Google had to take down more than 80 such applications to protect its users.

Such attacks underscore the potential for hackers that are looking at Web browsing and application downloads as two fertile fields from which they can gain valuable information. And as hackers become more creative with their efforts, there is no doubt they will turn their attentions to hacking phones used by enterprises and organizations in order to glean even more nefarious treasure.

Enterprises and organizations should be taking strong measures to counter such attacks now, as discussed in the new Heavy Reading Mobile Networks Insider report, "Mobile Security: The Coming Boom in Authentication." Companies analyzed in this report include: ActivIdentity Corporation; Arcot Systems; Diversinet Corp.; Entrust Inc.; PhoneFactor Inc.; PortWise AB; SafeNet Inc.; and Vasco Data Security International Inc.

The number of smartphone attacks is small compared to that of PC attacks – there are about 40 million known malicious programs that target PCs, as opposed to about 600 for smartphones. But enterprise IT professionals and mobile authentication vendors agree that the next 12 months will see an astronomical increase in the number of attacks against smartphones.

Several factors will drive those attacks. Smartphone users are not smart when it comes to protecting their information, with most still relying on simple passwords as their only form of security. Also, enterprises and organizations – especially those in the financial services and healthcare industries – are increasingly introducing new applications for smartphone users, giving hackers access to banking, credit card, and other vital information.

Smartphone protection must be implemented at the enterprise level. Companies should already utilize two-factor authentication and other security afforded by mobile authentication vendors. Once enterprises force their employees to understand the importance of protecting mobile devices, there will be a trickle-down effect to the consumer market.

Meanwhile, mobile authentication vendors must remain diligent about making their solutions affordable and simple to use. As PC users have shown, the only types of security measures that succeed are those that do not infringe on speed and utility. As vendors continue to create and market such solutions, enterprises will have no choice but to face the reality that smartphones are the new hacker frontier.

— Denise Culver, Research Analyst, Heavy Reading Mobile Networks Insider


The report, Mobile Security: The Coming Boom in Authentication, is available as part of an annual single-user subscription (six issues) to Mobile Networks Insider, priced at $1,595. Individual reports are available for $900. To subscribe, please visit: www.heavyreading.com/mobile-networks.



Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

Network Computing encourages readers to engage in spirited, healthy debate, including taking us to task. However, Network Computing moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. Network Computing further reserves the right to disable the profile of any commenter participating in said activities.

 
Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
 
White Papers SPONSORED CONTENT
Featured
Docsis Provisioning of EPON (DPoE)
CableLabs spec that blends Docsis-style provisioning with EPON