HomeinetThe security of a smartphone starts with its owner

Smartphone security starts with its owner

Smartphone owner? There's no doubt that mobile devices (smartphones and tablets) have become the preferred target of cybercriminals in recent times. With billions of smartphones sold, finding and exploiting security vulnerabilities has become a top priority for fraudsters.smartphones smartphones smartphones smartphones

iOS systems are no longer 100% secure, as the number of malware and cyberattacks targeting Apple's mobile platform has been on the rise in recent years.

Since the first iOS worm (Ikee) was discovered in 2009, which simply changed the device's wallpaper to one of Rick Astley, the iOS platform has been the target of many malware attacks
.
iOS is no longer the safest choice in mobile technology.

A study by Arxan Technology showed that 87% of the top 100 (paid) iOS apps have been cloned for malicious purposes, and are distributed through unofficial channels.

Jailbroken devices are easier to hack and were the target of the Xsser remote access Trojan (RAT) in 2014. Security researchers from Lacoon Mobile Security found it being distributed via a Whatsapp message to Hong Kong protesters with the aim of stealing personal information such as contact lists, texts or call logs.

But even non-jailbroken devices are no longer a guarantee of security. In 2014, a malware called Wirelurker was discovered on a third-party Mac app store, which would attack computers and wait for an Apple device to connect. This allowed it to hack into it and steal personal information.

Last year, FireEye researchers discovered a vulnerability in iOS that allowed a malicious app signed with a company certificate to replace the identity packet used to verify app updates. The flaw was dubbed Wirelurker .

XAgent ,and geo-location information from targeted devices. It could also be used to initiate voice recording on the device.

Threats and attacks designed for the iOS platform may not be as widespread as those intended for Android, but they are certainly starting to increase in frequency.

Meghan Kelly from security firm Lookout says that “today, iOS malware looks a lot like Android malware in 2010” and that the threat landscape for Apple gadgets is much the same as that seen for Google’s mobile operating system five years ago.

Security researchers at Bluebox have tested a range of nine different Android tablets for children, and found that almost all of them had vulnerabilities of various types.

It is important to note that these devices must comply with privacy laws (Children's Online Privacy Protection Act – COPPA) that prevent tracking and data collection. In addition, they have special software to protect the child's account on the gadget so that it limits changes that have not been approved by the guardian-administrator.

The study showed that more than 50% of tablets had a backdoor that bypassed security mechanisms and allowed the device to be rooted, which allows complete control over it.

Except for two products, all had third-party stores pre-installed, increasing the risk of malware entering from the internet since these markets do not perform strict checks on the applications they offer.

Another risk discovered by the researchers was that all tablets were susceptible to at least three significant vulnerabilities (Futex, ObjectInputStream, and BroadAnywhere), which could be exploited by a malicious user.

However, the biggest risk in the case of Android, as Bluebox reports, was discovered in a smartphone manufactured by Xiaomi.

The researchers purchased the device from a retailer in China and tested its security. The results were so incredible that the researchers believed they had been sold a fake device. As it turned out, the phone was real, but the software had been tampered with by the distribution chain.

The result was a device that included adware and malware and ran a custom copy of Android vulnerable to Masterkey, FakeID, and Towelroot (Linux futex). In addition, the phone was rooted.

Xiaomi was of course quick to provide explanations when Bluebox published the investigation, stating that the device was likely tampered with by an unofficial retailer from their distribution chain.

Based on all of the above, it seems that users should also take action to protect their data on mobile devices

Everything has become more organized and malicious users seem to be constantly devising new attacks that are difficult for an average user to discover.

An alternative solution you have for a secure Android is to immediately replace the operating system with one that has been verified by an authorized and trusted source, such as the images provided by Google or CyanogenMod.

With iOS, in addition to avoiding jailbreaking, users should avoid suspicious links or downloading apps from unknown sources.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS