• Most Popular
  • Most Shared

Mobile phones may face hacking threat

HELSINKI
Mon Jun 1, 2009 8:50am EDT
City workers make phone calls outside the London Stock Exchange in Paternoster Square in the City of London at lunchtime in this file photo from October 1, 2008.REUTERS/Toby Melville

HELSINKI (Reuters) - Accessing your bank account using your mobile phone might seem safe, but security experts say would-be hackers can access confidential information via a simple text message seemingly from your service provider.

People in the industry aware of the risk see it as extremely small, as only a few people use handsets to access their bank accounts, but it is growing as mobile Internet usage rises.

In April, the flaw -- which enables criminals to access a cellphone data connection, steal data or install or remove programmes -- gained wider attention at the BlackHat Europe security conference.

"The hacker does not have to be especially skilled to do this," said Jukka Tuomi, chief technology officer at Finnish software firm ErAce Security Solutions.

ErAce said that in some phones using Microsoft's Windows software, users cannot block the attack, while Symbian phone users can block malicious messages.

However, in practice, most users accept an installation of new settings if they seem to be from an operator.

So far, security problems on cellphones have been mostly limited to small outbreaks as operators have been able to screen the data traffic, but the new risk could be out of their reach in many countries where screening text messages is not allowed.

Consumers' increasing fears over computer viruses' ability to attack cellphones can put at risk the takeup of new mobile services, which are crucial for operators looking for growth in mature markets, where call prices are falling.

A REAL RISK

Also, installing security software on the phone is not always enough, as on some models criminals can wipe the programme from the phone.

"People think they are closing their door, but the windows and the back door are open," ErAce's Tuomi said.

When trying to enter a bank website on a mobile browser from an infected phone, the message on the phone says: "Opening a secure connection. Content cannot be seen by anyone else." In fact, the connection goes through criminals' servers.

"This is a real risk, but we have not seen this used in any real attacks in the field," said Mikko Hypponen, research director at Finnish security software firm F-Secure.

Jacob Greenblatt, from security software firm Discretix said: "While this is definitely serious, there are certain safeguards which can be built into mobile devices to eliminate the threat entirely or to limit its potential for harm."

Even if new phones are protected, this would still leave billions of phones on the market which are not shielded. (Reporting by Tarmo Virki; Editing by Rupert Winchester)



More from Reuters

Photo

Fox, Time Warner Cable ink temp deal to avoid blackout

NEW YORK (Reuters) - Time Warner Cable and News Corp's Fox Networks agreed to a brief extension of their current carriage contract on Thursday to avoid a blackout that would have prevented 13 million U.S. homes from seeing TV shows like "The Simpsons" and college and NFL football games.

A customer is served at a counter inside a foreign exchange store displaying a poster of various banknotes including the Chinese yuan or renminbi (RMB) in Hong Kong November 20, 2009. REUTERS/Bobby Yip
OUTLOOK 2010:

Be careful what you wish for

Pressure on China to loosen its grip on the yuan will continue but the U.S. should tread carefully. Here are five world market issues to watch.  Full Article 

Clients work out on machines at the Bally Total Fitness facility in Arvada, Colorado June 15, 2009.  REUTERS/Rick Wilking

Get real with resolutions

We make them and we break them: The secret to keeping them is to avoid the impossible dream.  Full Article