Security

Why an unhackable mobile phone is a complete marketing myth

Comment

David Jevans

Contributor

David Jevans is vice president of mobile security at Proofpoint and chairman of the Anti-Phishing Working Group.

The mobile security market is taking flight due to high-profile hackings, but is there such a thing as an unhackable phone? Especially one that costs as much as $14,000?

Consider this: The smartphone in your pocket is 10 times more powerful than the fastest multi-million dollar supercomputers of just 20 years ago. There are tens of millions of lines of software in that phone of yours. There are hundreds of apps written by more than one million developers, some of whom are hackers, and some of whom are just incompetent at security. And then there are chips in your phone that run sophisticated software, from companies located in countries all around the world, all of which have security bugs.

The complexity is mind-boggling — and so are all the security vulnerabilities that exist and will be found in the future.

In short, anyone who claims to sell an “unhackable phone” is either ignorant or lying.

With cybercriminals increasingly targeting mobile devices (such as with malicious apps and phishing schemes), threatening both the consumer and enterprises, the market is rushing to provide solutions to mobile security threats. Gartner calls this Mobile Threat Defense.

Everyone — no matter which phone they own — needs to be vigilant before downloading apps. For example, hackers recently created versions of Pokémon Go that contained malicious spyware that was released to eager fans before its official release. Even the first version of the legitimate Pokémon Go app was spying on many of your activities, and the developer and app stores didn’t catch it.

Despite the marketing hype, it is impossible to detect all malicious app behavior through a one-time scan of an app before it’s published on an app store. Bad apps often exploit operating system vulnerabilities that have not been discovered or fixed by the mobile device vendor. Apps can have “sleeper cell” behavior, where they don’t exhibit malicious behavior when being analyzed for app store approval — they wait until being deployed in the real world. Cybercriminals can also easily sideload apps onto both Android and iOS platforms from illegitimate app stores.

In addition to bad apps, we are seeing an increase in the number of criminals, hackers and hostile governments willing to pay for zero-day mobile exploits. These silent and secretive threats can take over your mobile phone simply by sending you a text message or email with a link to a malicious website. Unfortunately, new security threats and hacks are typically found after successful attacks have been reported by victims, researched and a fix is created by programmers. A hack may affect thousands or even hundreds of thousands of people before it is detected and fixed.

It’s also important to consider that most phones claiming to be “secure” or “unhackable” come from companies that base their phone on the Android operating system. Android is a state-of-the-art mobile device operating system, but more than 100 new security bugs are regularly discovered and need to be fixed every year. This trend shows no signs of slowing, and as mobile devices get ever smarter with more software and capabilities, there will be more bugs that hackers can exploit.

Taking a deeper look into the security of mobile devices shows that in August 2016 alone, there were 42 security vulnerabilities detected in the Android operating system or the Nexus device hardware. In July 2016, 54 such vulnerabilities were found. This monthly trend has been consistent for years. There is no sign that it will stop. You can be assured that every mobile device has 10-50 security vulnerabilities that will be discovered in the next month. And the month after that. And so on.

Of interest is that about half of the discovered vulnerabilities were not in the phone’s operating system itself, but instead were found in the operating systems and software that run the chips inside the device. These tiny bits of software, called firmware, contain dozens of security bugs, which are discovered every month. These firmware security vulnerabilities impact the software that operates cell phone modems, cameras, Wi-Fi, sound, displays, USB, Bluetooth, power drivers and more on each device. These components are from a variety of manufacturers around the world. It is simply impossible to ensure that these myriad components are secure.

Furthermore, it is critical to point out that 65 percent of Android devices in use around the world still run old versions of the operating system, with hundreds of known bugs.

The iOS operating system is also not immune to security bugs. Security fixes have been, and will be, continuously applied to the iOS operating system for Apple iPhones and iPads once they are reported. For example, in July 2016 alone, fixes for 29 types of security vulnerabilities were released by Apple. These fixes addressed 46 separate issues.

In August 2016, only one month later, news broke that hackers and governments were infiltrating iPhones with advanced spyware to steal data and spy on all app communications, even encrypted apps. Attackers simply sent users a text message with a malicious link. The attacks appear to be created by a commercial company in Israel, called NOS, that makes spyware for mobile devices.

And what about those Wi-Fi networks we rely on when in airports and at hotels? Make no mistake, they often spy on our communications. The so-called “captive portal,” where you have to enter your hotel room number, or just click on a terms of service agreement, are often traps to capture your email, passwords and web browsing activities. Be vigilant about which networks you connect to while traveling. If you receive a warning when connecting to a new Wi-Fi network, do not click “Continue.” Try another network.

All of these issues make it impossible for a single device to be completely secure. Organizations need mobile threat defense security tools that will protect the enterprise as employees connect their devices to malicious networks and download questionable data-stealing apps around the world. Consumers need to be vigilant before downloading apps (read and confirm permissions are in place), be wary of text messages from unknown sources and only join known and trusted Wi-Fi networks.

And hang up on the hype of an “unhackable phone.”

More TechCrunch

After Apple loosened its App Store guidelines to permit game emulators, the retro game emulator Delta — an app 10 years in the making — hit the top of the…

Adobe comes after indie game emulator Delta for copying its logo

Meta is once again taking on its competitors by developing a feature that borrows concepts from others — in this case, BeReal and Snapchat. The company is developing a feature…

Meta’s latest experiment borrows from BeReal’s and Snapchat’s core ideas

Welcome to Startups Weekly! We’ve been drowning in AI news this week, with Google’s I/O setting the pace. And Elon Musk rages against the machine.

Startups Weekly: It’s the dawning of the age of AI — plus,  Musk is raging against the machine

IndieBio’s Bay Area incubator is about to debut its 15th cohort of biotech startups. We took special note of a few, which were making some major, bordering on ludicrous, claims…

IndieBio’s SF incubator lineup is making some wild biotech promises

YouTube TV has announced that its multiview feature for watching four streams at once is now available on Android phones and tablets. The Android launch comes two months after YouTube…

YouTube TV’s ‘multiview’ feature is now available on Android phones and tablets

Featured Article

Two Santa Cruz students uncover security bug that could let millions do their laundry for free

CSC ServiceWorks provides laundry machines to thousands of residential homes and universities, but the company ignored requests to fix a security bug.

10 hours ago
Two Santa Cruz students uncover security bug that could let millions do their laundry for free

OpenAI’s Superalignment team, responsible for developing ways to govern and steer “superintelligent” AI systems, was promised 20% of the company’s compute resources, according to a person from that team. But…

OpenAI created a team to control ‘superintelligent’ AI — then let it wither, source says

TechCrunch Disrupt 2024 is just around the corner, and the buzz is palpable. But what if we told you there’s a chance for you to not just attend, but also…

Harness the TechCrunch Effect: Host a Side Event at Disrupt 2024

Decks are all about telling a compelling story and Goodcarbon does a good job on that front. But there’s important information missing too.

Pitch Deck Teardown: Goodcarbon’s $5.5M seed deck

Slack is making it difficult for its customers if they want the company to stop using its data for model training.

Slack under attack over sneaky AI training policy

A Texas-based company that provides health insurance and benefit plans disclosed a data breach affecting almost 2.5 million people, some of whom had their Social Security number stolen. WebTPA said…

Healthcare company WebTPA discloses breach affecting 2.5 million people

Featured Article

Microsoft dodges UK antitrust scrutiny over its Mistral AI stake

Microsoft won’t be facing antitrust scrutiny in the U.K. over its recent investment into French AI startup Mistral AI.

11 hours ago
Microsoft dodges UK antitrust scrutiny over its Mistral AI stake

Ember has partnered with HSBC in the U.K. so that the bank’s business customers can access Ember’s services from their online accounts.

Embedded finance is still trendy as accounting automation startup Ember partners with HSBC UK

Kudos uses AI to figure out consumer spending habits so it can then provide more personalized financial advice, like maximizing rewards and utilizing credit effectively.

Kudos lands $10M for an AI smart wallet that picks the best credit card for purchases

The EU’s warning comes after Microsoft failed to respond to a legally binding request for information that focused on its generative AI tools.

EU warns Microsoft it could be fined billions over missing GenAI risk info

The prospects for troubled banking-as-a-service startup Synapse have gone from bad to worse this week after a United States Trustee filed an emergency motion on Wednesday.  The trustee is asking…

A US Trustee wants troubled fintech Synapse to be liquidated via Chapter 7 bankruptcy, cites ‘gross mismanagement’

U.K.-based Seraphim Space is spinning up its 13th accelerator program, with nine participating companies working on a range of tech from propulsion to in-space manufacturing and space situational awareness. The…

Seraphim’s latest space accelerator welcomes nine companies

OpenAI has reached a deal with Reddit to use the social news site’s data for training AI models. In a blog post on OpenAI’s press relations site, the company said…

OpenAI inks deal to train AI on Reddit data

X users will now be able to discover posts from new Communities that are trending directly from an Explore tab within the section.

X pushes more users to Communities

For Mark Zuckerberg’s 40th birthday, his wife got him a photoshoot. Zuckerberg gives the camera a sly smile as he sits amid a carefully crafted re-creation of his childhood bedroom.…

Mark Zuckerberg’s makeover: Midlife crisis or carefully crafted rebrand?

Strava announced a slew of features, including AI to weed out leaderboard cheats, a new ‘family’ subscription plan, dark mode and more.

Strava taps AI to weed out leaderboard cheats, unveils ‘family’ plan, dark mode and more

We all fall down sometimes. Astronauts are no exception. You need to be in peak physical condition for space travel, but bulky space suits and lower gravity levels can be…

Astronauts fall over. Robotic limbs can help them back up.

Microsoft will launch its custom Cobalt 100 chips to customers as a public preview at its Build conference next week, TechCrunch has learned. In an analyst briefing ahead of Build,…

Microsoft’s custom Cobalt chips will come to Azure next week

What a wild week for transportation news! It was a smorgasbord of news that seemed to touch every sector and theme in transportation.

Tesla keeps cutting jobs and the feds probe Waymo

Sony Music Group has sent letters to more than 700 tech companies and music streaming services to warn them not to use its music to train AI without explicit permission.…

Sony Music warns tech companies over ‘unauthorized’ use of its content to train AI

Winston Chi, Butter’s founder and CEO, told TechCrunch that “most parties, including our investors and us, are making money” from the exit.

GrubMarket buys Butter to give its food distribution tech an AI boost

The investor lawsuit is related to Bolt securing a $30 million personal loan to Ryan Breslow, which was later defaulted on.

Bolt founder Ryan Breslow wants to settle an investor lawsuit by returning $37 million worth of shares

Meta, the parent company of Facebook, launched an enterprise version of the prominent social network in 2015. It always seemed like a stretch for a company built on a consumer…

With the end of Workplace, it’s fair to wonder if Meta was ever serious about the enterprise

X, formerly Twitter, turned TweetDeck into X Pro and pushed it behind a paywall. But there is a new column-based social media tool in town, and it’s from Instagram Threads.…

Meta Threads is testing pinned columns on the web, similar to the old TweetDeck

As part of 2024’s Accessibility Awareness Day, Google is showing off some updates to Android that should be useful to folks with mobility or vision impairments. Project Gameface allows gamers…

Google expands hands-free and eyes-free interfaces on Android