Your mobile phone may be bugging you, hackers warn
Thursday 12 August 2010
Latest in Business News
On Facebook
A British internet security company has demonstrated how to turn the Palm Pre into a secret bugging device, ideal for corporate espionage, and issued a warning that many other popular smartphones are also vulnerable to hackers.
In-house hackers at Basingstoke-based MWR InfoSecurity have created a bug hidden in an electronic business card, or vcard, which enabled them to use the Pre to record conversations and send the audio file back to them, whenever it is connected to a WiFi or 3G network – all without the user being aware anything at all is happening.
The company's 26-year-old principal security researcher – who gives his name only as Nils, and who was hired by MWR last year after having been a freelance hacker since his teens – demonstrated the security flaw in the Pre to journalists and IT specialists this week, saying the phone was "easy" to break into.
Hewlett-Packard acquired Palm two months ago, in part so it could use the Pre operating system on future smartphones.
Nils also revealed that MWR found a serious security flaw in Google's Android software, used as the operating system for a growing number of popular smartphones. The flaw allows a hacker to harvest all the usernames, passwords and browser history saved in an Android phone's web browser.
The vulnerabilities in the two operating systems took just two days for the determined hacker to discover, Nils told The Independent, and just three more to learn to exploit. "The Android phone does have some security built in, but the Palm system seems unprotected and extremely vulnerable," he said.
Hackers, both operating for their own amusement and for technology security firms, are engaged in an ongoing war to reveal vulnerabilities in the latest software and hardware – before unscrupulous hackers do the same.
MWR said that it had passed details of its discoveries on to Google and Palm, and would not publish them to the public until after they had been fixed. MWR said it would release the details later for educational purposes.
The MWR spokesman Alex Fidgen said that the Palm Pre vulnerabilities in particular raised serious concerns. "Whilst it is unusual for a genuine and accurate James Bond scenario to be uncovered during research, that is exactly what this represents. This calls into question fundamental assumptions about mobile phone security," he said.
"It asks some fundamental questions about whether security has really been considered in the rush to release new phones and operating systems."
- 1 Brazil rocked by abortion for 9-year-old rape victim
- 2 News in pictures
- 3 Four Britons face death by firing squad after 'smuggling cocaine into Bali'
- 4 Naked Miami man shot dead after being found eating another man's face
- 5 In pictures: The bewildering face of China
- 6 Principled Skinner rises above the fray
- 7 Thunderstorms and rain on the way as heatwave gives way
- 8 News International 'tried to blackmail select committee'
- 9 Postgraduate students are being used as 'slave labour'
- 10 Pope's butler: 'more arrests may follow'
- 1 Robert Fisk: Clinton's $33m raid on Pakistan shows that, in the end, hypocrisy will win
- 2 Brazil rocked by abortion for 9-year-old rape victim
- 3 It's not easy being Professor Green: The rapper, the heiress and a drama made in Chelsea...
- 4 Naked Miami man shot dead after being found eating another man's face
- 5 Principled Skinner rises above the fray
- 6 Fat? Really? Olympic hope laughs off official’s jibe – but others aren’t amused
- 7 'Hello mum, this is going to be hard for you to read ...'
- 8 Postgraduate students are being used as 'slave labour'
- 9 Coke reveals its secret: It may need to carry a cancer warning
- 10 French in uproar over oral sex anti-smoking posters
Experience the Heineken Hub
Get free wi-fi and exclusive i content while you enjoy a tasty pint of Heineken at participating pubs.
Can you imagine a career in teaching?
Be inspired to teach - let real teachers show you how rewarding the job can be.
Playing a game-changing role during the Games
Cisco is providing the solutions for London 2012's complex IT needs.
Enter the latest Independent competitions
Win anything from gadgets to five-star holidays on our competitions and offers page.
Business videos from commercial thought leaders
Watch the best in the business world give their insights into the world of business.
Career Services
Day In a Page



Comments