Tuesday | 7 October, 2008
Computerworld
Banking industry's m-commerce plans threatened by mobile malware
Keystroke code still unseen
Michael Crawford 06/02/2007 12:58:13

Computerworld Buyer's Guide - Vendors Matched to this Article
Related Features
  • +

    Ticked Off at Tick the Box Mentality 04/02/2008 13:01:15

    Does your executive search firm know the difference between an MIS manager and a CIO, and if it does, can it explain that difference to its corporate clients?
    Does your executive search firm know its MIS managers from its elbow? Does it even know the difference between an MIS manager and a CIO, and if it does, can it explain that difference to its corporate clients?
  • +

    Strategies for Dealing With IT Complexity 24/12/2007 10:30:47

    Every innovation, every business process improvement, comes with an IT complexity tax that must be paid by CIOs in time, money and sweat. Here are strategies to mitigate the increasing complexity of IT as it enables new business.
    Every innovation, every business process improvement, comes with an IT complexity tax that must be paid by CIOs in time, money and sweat. Here are strategies to mitigate the increasing complexity of IT as it enables new business.
Additional Resources
Executive Guides
Whitepapers
Zones
Zone logoZones provide focussed content from Computerworld and leading technology partners.

Newsletter Subscription

Sign up for our Computerworld newsletters!
Computerworld's twice-daily news service keeps you in touch with the latest, most important headlines from Australia and around the world.
Keep up with the latest virtualisation technologies, products, news and features.
RSS Feeds

Research and consulting firm TowerGroup predicts 2007 will be the year malicious code developed for identity fraud will target mobile banking via smartphones, PDAs and any other devices capable of running a connected Internet browser.

In a study titled "Fraud, Virus and ID Theft: Mobile Malware Stands to Create a New Beginning" TowerGroup chief analyst Bob Egan warns current m-commerce initiatives being developed by the financial services sector lack a justifiable focus on mobile malware.

Egan is calling for IT managers to upgrade malware and virus security packages to include mobile phones, based on what he believes are more than 200 mobile viruses in the wild. Egan said this figure doubles every six months.

"We're currently in the lull before the true storm," Egan said.

"To ensure that the mobile banking and payments channel will ultimately thrive, there is no time to waste in getting ahead of the malware challenge.

"The success of mobile banking and payments, as well as the concept of the mobile wallet, will be measured against the industry's ability to effectively contain the malware problems to a level that is at least on par with that of the existing Internet channel."

Gartner, too, have been very vocal in terms of the security procedures associated with Internet banking through handheld devices.

Last year analyst Graham Taylor released a paper titled "Banking on Mobile Platforms: Proceed with Caution" which advised banks to delay m-commerce plans as late as 2008. He said the delay in rolling out mobile banking initiatives is necessary to educate new users.

Most of the current mobile-phone specific malicious code acts either as a premium dialer (diverting calls to premium services numbers), "bluetoothing" contact lists to other bluetooth-enabled phones, or wiping out certain applications. No code exists yet with the potential to capture keystrokes or hijack banking sessions.

However, Neal Wise, director of security firm Assurance.com.au isn't too alarmed at this stage. Wise said most mobile phone viruses, so far, have been proof-of-concept and the idea they could act as keystroke loggers is a bit far fetched.

Wise cited the iPhone as one example, pointing out that with more functionality comes more risk.

"If you follow the money chances are someone is developing malicious code intended to hijack banking sessions or capture passwords," he said.

"As far as someone installing keystroke capturing software on a phone to hijack mobile commerce banking with a bank that is hard and far fetched and requires a sophisticated platform.

"The new Nokia 60 version 3 requires code to be signed by Nokia to do low level functions and so did the Blackberry so as long as the vendors have a model to only allow trustable code to be executed just like an operating system does to know something can be trusted.

"Phones are more focused computers now but many have Java which may allow malicious stuff to be executed but Java is supposed to ask the user if code to be executed exceeds the bounds of trust."

While Australia's major banks are planning m-commerce initiatives, Westpac, the Commonwealth Bank and the National Australia Bank, all confirmed there are no mobile banking services currently in use.

Computerworld Buyer's Guide - Vendors Matched to this Article
Market Place

Computerworld Member Login


 

Smart SOA World Tour

Discover how SOA can create smarter outcomes for your business.

Attend and learn:

  • How SOA is helping leading companies to become more agile
  • Where you should be applying SOA processes in your company
  • The top SOA implementation mistakes to avoid

Click here for more information.
Whitepaper

Did you GET the memo? Getting you from Web 1.0 to Web 2.0 Security

Enterprises have forged ahead with the rapid evolution from Web 1.0 to Web 2.0 without addressing the inherent security risks. It is imperative for organisations to continue to embrace new technologies to survive, but security must shift from being an after thought to a primary consideration. Read on to find out more.

Enterprise IT Buyer's Guide
Find Technology Vendors Fast
 
Find vendors by name | Find by category
Sponsored Links