The Macrosite for News, Analysis and Opinion about the Future of the Internet
David Harley

'Androidophobia' Hits the Web Again

Written by David Harley
2/1/2012 18 comments
no ratings
DISCUSS     Email This

George Santayana said a great deal more than “Those who cannot remember the past are condemned to repeat it,” but it’s probably the one quotation that nearly everyone in the security field will remember approximately verbatim.

For what (if anything) will I be remembered? Apparently, it’s likely to be a throwaway remark I made at the end of an interview with the UK journalist Steve Gold about a year ago, when the conversation turned to Android security. Apparently, I said something to the effect of “Android is terrifying.”

I don’t, in fact, have panic attacks in the presence of certain smartphones, but I guess the remark got more attention than “Security researcher anticipates increased volumes of Android malware in the next year or so” would have done. Frankly, that would probably have been seen as an insight with as much significance as “It will rain soon in Seattle” -- had not DroidDream, arguably the first major Android malware, hit the world’s radar just a day or two after.

Now the meme has resurfaced in the context of Symantec’s claim that there have been between 1 million and 5 million downloads of 13 apps infected with the malicious code called Android.Counterclank. In fact, the threat summary on Symantec’s own Website is considerably more restrained (1,000+ infections).

The trouble is that there’s a certain amount of debate as to whether the Android.Counterclank code is actually malicious. After all, it does actually ask during the installation process for permission to access some network and phone status data. The Android AV developer Lookout considers Counterclank to be “aggressive advertising,” rather than malware. And according to The H, Symantec is scaremongering.

The apparent difficulty lies in the definition of malware. Lookout has a (somewhat circular) definition that includes the phrase “designed to engage in malicious behaviour.” Well, yes, malware is a portmanteau word derived from MALicious softWARE. However, the company’s definition of malice is extraordinarily narrow -- “used to steal personal info... that could result in identity theft or financial fraud.”

There isn’t actually a universally accepted definition of malware, even in the AV industry -- heck, we never even came up with universal definitions for “virus” or “worm” or “Trojan” -- but as we use it in practical terms, it covers a lot more than that, including deliberate destruction of data or services, encryption for purposes of extortion, carrying a “joke” payload, and even doing nothing but replicating. (The last category includes most traditional viruses, as it happens.)

Symantec is, I imagine, concerned about the range of information that is silently accessed about the phone and its user, along with the very close similarity of some of the SDK code to pre-existing code found in earlier apps that are unequivocally considered to be malware. In fact, other vendors are detecting Counterclank using the same heuristic detections as Plankton/Tonclank, and they have been doing so for several months.

Lookout’s blog implies that, because the latest batch of programs do not use blatant backdoor and data-stealing functionality, the classification has changed from “malicious” to what many vendors call “possibly unwanted.” I remain unconvinced. Changing the browser’s home page might be considered “aggressive advertising,” but unless it’s specifically permitted by the user -- and Counterclank goes beyond the list of permissions requested, according to Symantec’s description -- it sounds very much like unauthorized modification to me, and that’s illegal in many jurisdictions (including here in the UK). In fact, while the underlying mechanism differs, misdirecting to a site that suits the software rather than the system user is uncomfortably close to the DNSchanger class of malware.

Google has removed some of the apps said to contain the Counterclank code from the market. However, five apps are still available, even though they were flagged by Symantec as containing the same “apperhand” code to which it has given the name Counterclank. It appears that Google considers these apps to meet their terms of service. Given the modifications that Counterclank is capable of making to the user’s system, this decision seems controversial, to say the least.

Related posts:

— David Harley has worked with ESET North America -- where he holds the position of Senior Research Fellow -- since 2006.

DISCUSS     Email This
Current display:       newest comments first       display in chronological order
Page 1 of 2   Next >
David.Harley
Rank: Cave Painter
Monday February 6, 2012 2:32:54 PM
no ratings

Bouncer is a good start, even though it comes with the customary "shoot the messenger" "we know better than the AV companies" messages. But it's a long way from an all-inclusive screening process. I think I need to find time for another blog on that...

Mike Acker
Rank: Cyborg
Friday February 3, 2012 9:52:33 AM
no ratings

MJ="I'm with you on this, Mike."

thanks, Mary

  • is there any reason for anyone to expend resources making systems secure?

no: that is tacitly assigned to the user by our convention

but computer security is beyond our level of expertise for most of us

i don't like government intervention is most things but in this case it's probably going to be necessary

we need to divide computers into two major types

  • commercial
  • experimental

the commercial type should be locked down: no un-authroized software.

and customers should have a choice and they should be allowed to know the risk factors involved in that choice

this will need some rules from the FTC

Mary Jander
Thinkernetter
Friday February 3, 2012 9:44:49 AM
no ratings

I'm with you on this, Mike. What puzzles me is that Google claims the new Android scanning service, Bouncer, has been in service for months, even though no one noticed.

Excuse me?

Kicheko
IQ Crew
Friday February 3, 2012 7:39:46 AM
no ratings

I had asked myself how this would work too. It may be a great deal of work especially not being their core business, but maybe one of the ways it can be done is by outsourcing. In future if a company came up whose core business is to verify Apps, lots of app stores can outsource to them, including Android, Nokia etc.

Mike Acker
Rank: Cyborg
Friday February 3, 2012 7:17:44 AM
no ratings

in the news this morning Google is gonna clean up their Droid app store

geees o pete

 

and we get the admission this morning that Verisign has been ripped up by hackers since 2010

does anybody in this industry have any idea what they are doing?

Mary Jander
Thinkernetter
Thursday February 2, 2012 5:54:04 PM
no ratings

The security issue could improve, depending on app developers who add security, no?

David.Harley
Rank: Cave Painter
Thursday February 2, 2012 6:41:19 AM
no ratings

For Android to start pre-screening apps would need radical re-engineering of their marketing model, before even thinking of the technical issues. But it's way behind iOS in this respect at this moment.

Gigi
IQ Crew
Thursday February 2, 2012 2:32:46 AM
no ratings

David, when compare with other OS, android is not still in a full pledged way. It have some issues with security and I think hackers/ malwares are trying to make use of such loopholes.

Mary Jander
Thinkernetter
Wednesday February 1, 2012 5:30:25 PM
no ratings

Thankfully, our IT basically restricts any upgrades or installs not done by them alone.

On my personal computer, I am always deleting the dreaded "update now" screens.

Mike Acker
Rank: Cyborg
Wednesday February 1, 2012 2:33:00 PM
no ratings

=" Defining "malware" is an interesting challenge."

use the term "unauthorized programming" and you'll understand it more easily

remember: web pages are transient programming and as such the script must run sand boxed. when you close the page the transient program is gone.  a good sand box will not allow a transient program to access anything outsize that sand-box

which leaves the question: what do you do with a document you need to save or forward -- but which contains transient programming ?  that is one of the big issues that remains to be solved.

Google has the right idea: trash all the transient programming

the transient programmming, properly done, is just automated commands -- for things that you could do for yourself -- anyway

but when a document containing such transient programming is forwarded the authority and permissions of the user may change and that might open the lid on Pandora's famous box

Page 1 of 2   Next >
The ThinkerNet does not reflect the views of TechWeb. The ThinkerNet is an informal means of communication to members and visitors of the Internet Evolution site. Individual authors are chosen by Internet Evolution to blog. Neither Internet Evolution nor TechWeb assume responsibility for comments, claims, or opinions made by authors and ThinkerNet bloggers. They are no substitute for your own research and should not be relied upon for trading or any other purpose.
a moderated blogosphere of internet experts
Paul Korzeniowski
The smartphone market reached a significant milestone, a breakthrough that may cause vendors to celebrate but could strain the capabilities of IT service desks.
Maria Korolov
Maria Korolov   5/21/2013   7 comments
In the fall of 2011, around 160,000 students in 190 countries enrolled in a Stanford-sponsored online course about artificial intelligence. About 23,000 completed the course and got certificates, including 248 who got a perfect score. The university offered the same course the old-fashioned way to students sitting in Stanford classrooms. None of the those students got a perfect score.
Joe Stanganelli
As Mitch Wagner discussed today, Yahoo is acquiring Tumblr. The big Internet debate at the moment is whether Tumblr will be good or bad for Yahoo. Regardless of their stances on the future of Yahoo itself, many claim that Yahoo will somehow ruin Tumblr.
George Taylor
George Taylor   5/20/2013   9 comments
Has China stolen a march on the West, developing an Internet architecture that is not only based on IPv6, but is also inherently secure from both internal and external attack?
IETV: the thinkerNet on film
5
of
Kim Davis
Big-Data Can’t Always Sell Wine

5|21|13   |   2:23   |   1 comment


Whole Foods Global Wine Purchaser Doug Bell told me about some of the constraints on using analytics in the US wine market.
Paul J. Fleuranges
Digital Signage Keeps NYC Subway Straphangers on Track

5|6|13   |   3:51   |   No comments


New York's Metropolitan Transit Authority is conducting a pilot test of digital kiosks to guide subway users to where they want to go more efficiently and at lower cost.
Kim Davis
Fast Forward to the Future

4|23|13   |   2:29   |   20 comments


A look back at tech writing in the 90s makes us wonder where enterprise IT will be 20 years from now.
Mitch Wagner
Google Launches Its Most Depressing Service Yet

4|15|13   |   2:59   |   10 comments


Google's new Inactive Account Manager lets you control how Google disposes of your accounts when you die.
Second Shooter
Argument Over Top-Level Domains Is 'Stupid'

4|11|13   |   2:07   |   3 comments


The whole Amazon.reader debate is a double-stupid. It's stupid to think that there's any e-book buyer who doesn't know Amazon's URL, and it was stupider to let ICANN launch the whole free-form TLD initiative to start with.
Kim Davis
Ladies, Your Tablet Awaits

3|21|13   |   2:22   |   37 comments


ePad Femme is the world’s first tablet “made exclusively for women.”
Wisdom of the Big Chair
NFC Moves Into the Mainstream

3|20|13   |   2:16   |   No comments


While NFC's original goal was to enhance mobile commerce applications, it is finding its way into a number of other uses, which is creating both opportunity as well as challenges for IT departments.
Wisdom of the Big Chair
Integrating Security Into Your Cloud Contract

3|19|13   |   3:35   |   No comments


Enterprises would like to move to cloud computing but are hesitant because they are concerned about providers’ ability to secure company data. Here are some tips that help to ensure that if breaches occur, the business is not left holding the bag.
Brian Baron
How Edmunds.com Collects Customer Information

3|18|13   |   1:15   |   No comments


Edmunds separates customers into segments based on the info it collects on its site and from partners, and uses that to push out custom content, said Brian Baron, director of business analytics for Edmunds.com, at Predictive Analytics Innovation Summit.
Brian Baron
How Edmunds.com Uses Analytics to Customize Site

3|14|13   |   0:47   |   No comments


The automotive website uses propensity modeling to target ads and customer registration forms, said Brian Baron, director of business analytics for Edmunds.com, at Predictive Analytics Innovation Summit.
an IBM information resource
sponsored content
big blue blog
Todd Watson
Todd Watson   5/21/2013   Post a comment
Sometimes business travel can be a royal pain in the you-know-what, and sometimes all things go well with the planes, trains, and automobiles.
an IBM information resource
sponsored content
Expert Integrated Systems: Changing the Experience & Economics of IT
In this e-book, we take an in-depth look at these expert integrated systems -- what they are, how they work, and how they have the potential to help CIOs achieve dramatic savings while restoring IT's role as business innovator.

READ THIS eBOOK
your weekly update of news, analysis, and
opinion from Internet Evolution - FREE!

REGISTER HERE
Wanted! Site Moderators
Internet Evolution is looking for a handful of readers to help moderate the message boards on our site – as well as engaging in high-IQ conversation with the industry mavens on our thinkerNet blogosphere. The job comes with various perks, bags of kudos, and GIANT bragging rights. Interested?

Please email: moderators@internetevolution.com
Internet Evolution – not for thickies
Keep Critical Data With a Knowledge Management System
Taimoor Zubair
Fortune 500 companies lose at least
$31.5 billion a year by failing to share knowledge. A Knowledge Management System (KMS) can help companies significantly reduce these costs.

CLICK FOR MORE
Yahoo Needs to Break Tumblr in Order to Fix It
Joe Stanganelli
As
Mitch Wagner discussed today, Yahoo is acquiring Tumblr. The big Internet debate at the moment is whether Tumblr will be good or bad for Yahoo. Regardless of their stances on the future of Yahoo itself, many claim that Yahoo will somehow ruin Tumblr.

CLICK FOR MORE