Lions, tigers, mobile spyware. Oh my.
This time it's security-software-maker Veracode decrying the BlackBerry's weaknesses. More specifically, Tyler Shields, a senior researcher with Veracode Research Lab, has put together and publicly released some proof-of-concept spyware code, dubbed TSXBBSpy, that can reportedly wipe a BlackBerry clean, distribute on-board data via e-mail and monitor voice-mail messages in real-time.
Why would Shields release the source code for such an app? Well, to show the world "how easy it is to write" of course.
Sounds frightening, right? Well, yes and no. First of all, such malicious software really isn't new. We've seen similar "spyware" emerge over the past couple of years with the growing popularity of the BlackBerry platform among RIM's traditional enterprise customer-base and in the massive consumer ranks.
The most recent example that comes to mind is PhoneSnoop, which could "turn your BlackBerry into a remote listening device." This app could indeed record your phone calls and send them to a third-party, but you not only had to install the suspicious app, but also grant it permission to your phone activity. As my friend, colleague and security-pro Ariel Silverstone put it in his blog post on the subject:
"It took over ten years for such a 'hack' as the listening software to be available. And it is not even a hack. It is no more a hack than a user being asked, in bold letters, to perform five steps to install spyware software on their pc...If someone does all of [this] they should be reminded how to buckle their belts on every airliner they board, and they indeed do not deserve a berry."
Ariel's point: Sure, software exists that can "hack" into your BlackBerry and potentially perform all sort of nefarious deeds. But the security safeguards built into RIM's BlackBerry OS make it extremely difficult for miscreants to do so without the approval, and often assistance, of the BlackBerry user.
News 1 year ago

