Showing posts with label security risk. Show all posts
Showing posts with label security risk. Show all posts

Monday, November 5, 2012

Study finds 25 percent of Android apps to be a security risk

PCWorld - According to a new report from Bit9—a security vendor with a focus on defending against advanced persistent threats (APT)—there is a one in four chance that downloading an Android app from the official Google Play market could put you at risk. Bit9 analyzed 400,000 or so apps in Google Play, and found over 100,000 it considers to be on the shady side.

Does that mean that the sky is falling, and everyone with an Android smartphone or tablet should abandon it immediately? No. The research by Bit9 illustrates some issues with app development in general, and should raise awareness among mobile users to exercise some discretion when downloading and installing apps, but it’s not a sign of any urgent crisis affecting Android apps.

The report from Bit9 isn’t about apps that contain malware, or are even overtly malicious for that matter. Bit9 reviewed the permissions requested by the apps, and examined the security and privacy implications of granting those permissions. The reality is that many apps request permission to access sensitive content they have no actual need for. 

More

Tuesday, September 4, 2012

Time to Give Java the Boot?

Analysis: The programming language has become one of the weakest links in a PC’s and Mac's defenses against external threats, and is slowly -- and rightly -- being abandoned.



PCWorld - Java, the programming language designed to make the web fun and interactive, has become one of the weakest links in a PC’s and Mac's defenses against external threats. Consider the most recent Java vulnerability, a weakness currently being exploited by malware distributors: When Oracle, Java's maker, released an emergency update to fix the software, security analysts reported that even the hot-off-the-presses code contains additional vulnerabilities.

But the most recent security problems with Java are far from unique. Security firm Sophos, for example, blames underlying Java vulnerability for attacks by the Flashback malware last April that infected one out of five Macs.

The risks don't outweigh the rewards, security experts say. “I'd say 90 percent of users don't need Java anymore,” says Dominique Karg, the founder and chief hacking officer of AlienVault, a security software company. “I consider myself a ‘power user’ and the last and only time I realized I had Java installed on my Mac was when I had to update it.”

If you own a PC you know that nagging feeling of insecurity when you're asked to update your Windows PC for the umpteenth time. It may only be moderately disruptive, but it’s a monthly reminder that your computer, and the personal information contained therein, remains a target for criminals.

More