Banking industry's m-commerce plans threatened by mobile malware
- 06 February, 2007 12:58
- Comments
Research and consulting firm TowerGroup predicts 2007 will be the year malicious code developed for identity fraud will target mobile banking via smartphones, PDAs and any other devices capable of running a connected Internet browser.
In a study titled "Fraud, Virus and ID Theft: Mobile Malware Stands to Create a New Beginning" TowerGroup chief analyst Bob Egan warns current m-commerce initiatives being developed by the financial services sector lack a justifiable focus on mobile malware.
Egan is calling for IT managers to upgrade malware and virus security packages to include mobile phones, based on what he believes are more than 200 mobile viruses in the wild. Egan said this figure doubles every six months.
"We're currently in the lull before the true storm," Egan said.
"To ensure that the mobile banking and payments channel will ultimately thrive, there is no time to waste in getting ahead of the malware challenge.
"The success of mobile banking and payments, as well as the concept of the mobile wallet, will be measured against the industry's ability to effectively contain the malware problems to a level that is at least on par with that of the existing Internet channel."
Gartner, too, have been very vocal in terms of the security procedures associated with Internet banking through handheld devices.
Last year analyst Graham Taylor released a paper titled "Banking on Mobile Platforms: Proceed with Caution" which advised banks to delay m-commerce plans as late as 2008. He said the delay in rolling out mobile banking initiatives is necessary to educate new users.
Most of the current mobile-phone specific malicious code acts either as a premium dialer (diverting calls to premium services numbers), "bluetoothing" contact lists to other bluetooth-enabled phones, or wiping out certain applications. No code exists yet with the potential to capture keystrokes or hijack banking sessions.
However, Neal Wise, director of security firm Assurance.com.au isn't too alarmed at this stage. Wise said most mobile phone viruses, so far, have been proof-of-concept and the idea they could act as keystroke loggers is a bit far fetched.
Wise cited the iPhone as one example, pointing out that with more functionality comes more risk.
"If you follow the money chances are someone is developing malicious code intended to hijack banking sessions or capture passwords," he said.
"As far as someone installing keystroke capturing software on a phone to hijack mobile commerce banking with a bank that is hard and far fetched and requires a sophisticated platform.
"The new Nokia 60 version 3 requires code to be signed by Nokia to do low level functions and so did the Blackberry so as long as the vendors have a model to only allow trustable code to be executed just like an operating system does to know something can be trusted.
"Phones are more focused computers now but many have Java which may allow malicious stuff to be executed but Java is supposed to ask the user if code to be executed exceeds the bounds of trust."
While Australia's major banks are planning m-commerce initiatives, Westpac, the Commonwealth Bank and the National Australia Bank, all confirmed there are no mobile banking services currently in use.
- Bookmark this page
- Share this article
- Got more on this story? Email Computerworld
- Follow Computerworld on twitter
- Six tips for choosing a unified threat management (UTM) solution
- Keeping up With Ever-Expanding Enterprise Data - 2010 IOUG Database Growth Survey
- Best practices for a Data Warehouse on Oracle Database 11g
- Email Encryption/Decryption and Signing integrated into a comprehensive content security solution
- Leverage Economic Advantages in Storage Management
- iPhone 5 rumour rollup for the week ending February 10
- 3D mapping revives underwater city
- Academic challenges Turnbull over NBN satellite criticism
- What are you saying: Telstra’s customer service slowly improving, SA minister urging Facebook to overturn its photo ban
- In pictures: Capgemini opens new Canberra office
-
Maingear's six-core laptop has 1.8TB of SSD storage
-
After Megaupload shuts, BTJunkie follows
-
Windows Event Viewer phishing scam remains active
-
NeuroSky MindWave: Fun with Brainwaves
-
20 popular Ubuntu Linux apps you may want to try
-
Computers for Seniors for Dummies, 2nd Edition
-
Windows 7 for Seniors for Dummies®
-
Windows 7 for Dummies® Dvd+book Bundle
-
Teach Yourself Visually Windows 7
-
Windows 7 for Dummies®
-
MYOB Software for Dummies 6E Australian Edition
-
Microsoft Office
-
Office 2007 for Dummies
-
Excel 2007 All-In-One Desk Reference for Dummies












Comments
Post new comment