• Most Popular
  • Most Shared

Mobile phones face hacking threat, experts say

Mon Jun 1, 2009 8:15am EDT

Stocks

   

* New security flaw putting most cellphones at risk

* On some models, users can block criminals, on others not

By Tarmo Virki, European technology correspondent

HELSINKI, June 1 (Reuters) - Accessing your bank account using your mobile phone might seem safe, but security experts say would-be hackers can access confidential information via a simple text message seemingly from your service provider.

People in the industry aware of the risk see it as extremely small, as only a few people use handsets to access their bank accounts, but it is growing as mobile Internet usage rises.

In April, the flaw -- which enables criminals to access a cellphone data connection, steal data or install or remove programmes -- gained wider attention at the BlackHat Europe security conference.

"The hacker does not have to be especially skilled to do this," said Jukka Tuomi, chief technology officer at Finnish software firm ErAce Security Solutions.

ErAce said that in some phones using Microsoft's Windows software, users cannot block the attack, while Symbian phone users can block malicious messages.

However, in practice, most users accept an installation of new settings if they seem to be from an operator.

So far, security problems on cellphones have been mostly limited to small outbreaks as operators have been able to screen the data traffic, but the new risk could be out of their reach in many countries where screening text messages is not allowed.

Consumers' increasing fears over computer viruses' ability to attack cellphones can put at risk the takeup of new mobile services, which are crucial for operators looking for growth in mature markets, where call prices are falling.

A REAL RISK

Also, installing security software on the phone is not always enough, as on some models criminals can wipe the programme from the phone.

"People think they are closing their door, but the windows and the back door are open," ErAce's Tuomi said.

When trying to enter a bank website on a mobile browser from an infected phone, the message on the phone says: "Opening a secure connection. Content cannot be seen by anyone else." In fact, the connection goes through criminals' servers.

"This is a real risk, but we have not seen this used in any real attacks in the field," said Mikko Hypponen, research director at Finnish security software firm F-Secure (FSC1V.HE).

Jacob Greenblatt, from security software firm Discretix said: "While this is definitely serious, there are certain safeguards which can be built into mobile devices to eliminate the threat entirely or to limit its potential for harm."

Even if new phones are protected, this would still leave billions of phones on the market which are not shielded. (Reporting by Tarmo Virki; Editing by Rupert Winchester)



More from Reuters

Joint Terminal Attack Controller SSgt Clinton J. Herbison, a U.S. Airman from the 817 Expeditionary Air Support Operations Squadron (EASOS) takes a break during a night mission near Honaker Miracle camp at the Pesh valley of Kunar Province August 12, 2009. Credit: REUTERS/Carlos Barria

Pictures of the Year

A look at the best photos of 2009.  Slideshow 

    The Dalai Lama jokes with a nasal spray after being asked his opinion on the swine flu during a press conference after his first lecture in Lausanne, Switzerland, August 4, 2009. REUTERS/ Valentin Flauraud

    What a wacky year it's been...

    Um, what's up the Dalai Lama's nose? "Oddly Enough" editor Bob Basler rounds up the goofiest photos of the year.  Full Article 

    A caution sign is seen next to a stock board at the Australian Securities Exchange (ASX) in Sydney September 5, 2008. REUTERS/Daniel Munoz
    Political Risk in 2010:

    Don't say we didn't warn you

    With the financial crisis (mostly) in the past, U.S. investors are eying a fresh start to the coming year. Here's a look at what speedbumps lie ahead.  Full Article