<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	
	>
<channel>
	<title>Comments on: Android malware hype</title>
	<atom:link href="http://javacard.vetilles.com/2010/06/28/android-malware-hype/feed/" rel="self" type="application/rss+xml" />
	<link>http://javacard.vetilles.com/2010/06/28/android-malware-hype/</link>
	<description>A weblog on Java Card, security, and other things personal</description>
	<lastBuildDate>Thu, 18 May 2017 07:26:32 +0000</lastBuildDate>
		<sy:updatePeriod>hourly</sy:updatePeriod>
		<sy:updateFrequency>1</sy:updateFrequency>
	<generator>https://wordpress.org/?v=4.0.32</generator>
	<item>
		<title>By: Erwan</title>
		<link>http://javacard.vetilles.com/2010/06/28/android-malware-hype/#comment-4204</link>
		<dc:creator><![CDATA[Erwan]]></dc:creator>
		<pubDate>Tue, 29 Jun 2010 19:55:41 +0000</pubDate>
		<guid isPermaLink="false">http://javacard.vetilles.com/?p=586#comment-4204</guid>
		<description><![CDATA[This reminds me the warning you get when installing some ports under FreeBSD:
the port foo installed /usr/local/libexec/barhelper and /usr/local/bin/bar whch can act as server and thus be a security breach...]]></description>
		<content:encoded><![CDATA[<p>This reminds me the warning you get when installing some ports under FreeBSD:<br />
the port foo installed /usr/local/libexec/barhelper and /usr/local/bin/bar whch can act as server and thus be a security breach&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Axelle</title>
		<link>http://javacard.vetilles.com/2010/06/28/android-malware-hype/#comment-4203</link>
		<dc:creator><![CDATA[Axelle]]></dc:creator>
		<pubDate>Tue, 29 Jun 2010 13:28:09 +0000</pubDate>
		<guid isPermaLink="false">http://javacard.vetilles.com/?p=586#comment-4203</guid>
		<description><![CDATA[Hi Eric,

I must add a comment on spyware. There are two different class of spyware: a) Trojan spyware, which are real malware and will for instance forward SMS without your being aware of it (I&#039;m sure you wouldn&#039;t like that) and b) border-line spyware, which do something potentially bad to your privacy but may be ok in some situations.
Sending SMS without user interaction *is* a dangerous feature. It ought to be limited.

Also, I do agree that Androids are not &#039;full of malware&#039; and that such reports may scare users.
But from what you quote of Smobile&#039;s report, I wouldn&#039;t disagree with them. And end-users are hardly ever aware that their phones are unsecure, so educating them can&#039;t be a bad thing. 

Finally, I disagree on this point:

&quot;Google is likely to turn on the kill switch before the bad guy can make any real money.&quot;

You have absolutely no proof about that. And my experience (not with Google though) is that they are unlikely to be aware and that the bad guy WILL make money before the tap is closed...]]></description>
		<content:encoded><![CDATA[<p>Hi Eric,</p>
<p>I must add a comment on spyware. There are two different class of spyware: a) Trojan spyware, which are real malware and will for instance forward SMS without your being aware of it (I&#8217;m sure you wouldn&#8217;t like that) and b) border-line spyware, which do something potentially bad to your privacy but may be ok in some situations.<br />
Sending SMS without user interaction *is* a dangerous feature. It ought to be limited.</p>
<p>Also, I do agree that Androids are not &#8216;full of malware&#8217; and that such reports may scare users.<br />
But from what you quote of Smobile&#8217;s report, I wouldn&#8217;t disagree with them. And end-users are hardly ever aware that their phones are unsecure, so educating them can&#8217;t be a bad thing. </p>
<p>Finally, I disagree on this point:</p>
<p>&#8220;Google is likely to turn on the kill switch before the bad guy can make any real money.&#8221;</p>
<p>You have absolutely no proof about that. And my experience (not with Google though) is that they are unlikely to be aware and that the bad guy WILL make money before the tap is closed&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Wadael</title>
		<link>http://javacard.vetilles.com/2010/06/28/android-malware-hype/#comment-4201</link>
		<dc:creator><![CDATA[Wadael]]></dc:creator>
		<pubDate>Tue, 29 Jun 2010 08:02:55 +0000</pubDate>
		<guid isPermaLink="false">http://javacard.vetilles.com/?p=586#comment-4201</guid>
		<description><![CDATA[Hi Eric,

You might have heard of the &#039;hole&#039; that would be apps allowed to execute native code which they would get somewhere on the net, sometime later than install.

I use free apps and many have asked for auth. I do not see why they need it.
However, it auth. them to use the apps. 

Somehow, it reminds me of the MS EULAs noone reads.

Is there a rule to recognize premium numbers ?

I don&#039;t know how to put nets around those apps without doing a constant survey.


Jerome]]></description>
		<content:encoded><![CDATA[<p>Hi Eric,</p>
<p>You might have heard of the &#8216;hole&#8217; that would be apps allowed to execute native code which they would get somewhere on the net, sometime later than install.</p>
<p>I use free apps and many have asked for auth. I do not see why they need it.<br />
However, it auth. them to use the apps. </p>
<p>Somehow, it reminds me of the MS EULAs noone reads.</p>
<p>Is there a rule to recognize premium numbers ?</p>
<p>I don&#8217;t know how to put nets around those apps without doing a constant survey.</p>
<p>Jerome</p>
]]></content:encoded>
	</item>
</channel>
</rss>
