Technology Sectors

Market Sectors

Malware impact on short text messaging overstated, says expert

Harris: copycats
can't foil Zitmo

Zeus is the king of the Greek gods but in malware circles, Zeus is a king of another kind — king of the banking bandit worms. So it's not surprising that a wave of worry swept over the security community when a mobile variant of the bad app, Zitmo, had found a way to compromise authentication systems based on short text, or SMS, messaging.

"The malware poses as a banking activation application," Fortinet mobile malware researcher Axelle Apvrille wrote in company blog on July 8. "In the background, it listens to all incoming SMS messages and forwards them to a remote Web server. It’s simple, but just enough for the Zeus gang to grab your banking TANs."

A TAN, or Transaction Authentication Number, is a one-time password used in addition to a user's permanent password to authenticate a bank transaction.

Anxiety among bad app fighters, though, may be misplaced, according to Chris Russell, vice president of technology at Swivel Secure, a U.K. maker of authentication software for mobile phones. While acknowledging that Zitmo can crack some authentication schemes, he asserted that reports that all authentication technology based on SMS text message transmission may be at risk were "overstated."

He boasted that his company's application, PINsafe, is designed to foil such exploits. “Unlike other technologies that involve the user receiving the login credential via SMS, PINsafe delivers a random security string which needs a fixed PIN to generate the response," he explained in a statement. "At no time during the process is the user asked to enter their personal PIN so it is never transmitted either by SMS or over the Internet so cannot be intercepted by any digital eavesdropper, rendering the Trojan ineffective.”

PINsafe uses a very simple, patented protocol to generate a one-time-code for each login session, Swivel elaborated. Users are sent a random alpha-numeric security string in advance of the requirement as a text message to their phone. This is not what the user sends back to the server so is of no use to the hacker. With the SMS message transmitted via the mobile network and the OTC returned via an SSL link to the server the process is doubly secure.

“This is one of our key differentiators,” added Swivel Managing Director Richard H. Harris. “There are a number of copycat systems that use SMS as part of the process; typically the user is sent a code that they then simply return to prove their identity."

"Of course," he continued, "it only proves that the person has the phone at the time of the login and yes, the code can be intercepted en route from the client to the server, in which case the reports would be right to say that the Zeus worm is a potential threat. This is not how PINsafe works.”

Security has been cited in surveys as a major factor slowing down the adoption of mobile banking apps. The rate of adoption of mobile banking barely budged between 2010 and 2011, despite aggressive promotions by financial institutions, Javelin Strategy & Research revealed in a recent report. One reason, the report said, is smartphone owners perceive mobile banking as less secure. "Between 2009 and 2010 the number of consumers who rated mobile banking as 'unsafe' or 'very unsafe' increased by a shocking 54 percent," it added.

 

Recent Webinars

Thu, 04/26/2012 - 2:00pm - 3:00pm

Extracting real-time intelligence from Big Data with deep analytics is valuable but dif

Upcoming Events

Event Details Dates of Event
SANS Security West 2012 May 10 - 18
SANS Toronto 2012 May 14 - 19
SANS Secure Indonesia 2012 May 14 - 19
SANS at iTWeb Security Summit 2012 May 17 - 18
New Fire & Emergency Communications Codes Educational Seminar May 18 - 18
Managing Your Physical Security Program: Collaborate and Manage Smarter May 21 - 24
SANS Brisbane 2012 May 21 - 26
CEIC 2012 (Computer and Enterprise Investigations Conference) May 21 - 24
NERC CIP Compliance Training May 24 - 24
Symantec NetBackup User Group May 24 - 24
NESCO Town Hall: Security Risk Management Practices for Electric Utilities May 30 - 31
Advanced Hands-On CAMEO Training Jun 4 - 6
Security Program Design: A Critical Infrastructure Protection Model Jun 4 - 5
Facility Security Design Jun 4 - 6
SANS Rocky Mountain 2012 Jun 4 - 9
F5 Government Technology Symposium Jun 6 - 6
SEL Modern Solutions Power Systems Conference Jun 6 - 8
Second Annual Citizen Engagement Seminar Jun 12 - 12
ASIS Assets Protection Course: Functional Management (APC III) Jun 18 - 21
SANS Malaysia 2012 Jun 18 - 23
Data Center Brainstorm 2012 Jun 19 - 19
SANS Forensics and Incident Response Summit 2012 Jun 21 - 27
Vanguard Security & Compliance 2012 Jun 25 - 28
SANS Canberra 2012 Jul 2 - 10
SANSFIRE 2012 Jul 7 - 15
Executive Protection Jul 9 - 10
Military Vehicles Exhibition & Conference Jul 10 - 13
NERC CIP Compliance Training Jul 12 - 12
Security Force Management Jul 16 - 17
Physical and Logical Security: Advanced Applications and Economics Jul 16 - 19
Investigative Interviewing Methods Jul 18 - 19
SANS Thailand 2012 Jul 23 - Aug 4
SANS San Francisco 2012 Jul 30 - Aug 6
College & University Police & Investigators Conference Jul 31 - Aug 3
SANS Boston 2012 Aug 6 - 13
Radiological Emergency Planning: Terrorism, Security, and Communication Aug 20 - 24