Security firms squabble over mobile threats

By Tom Espiner, ZDNet UK
Tuesday, July 25, 2006 10:39 AM

After launching a mobile-security service last week, Finnish antivirus specialist F-Secure is being accused of magnifying threats to smart phones.

Software and services company CA in a statement Monday said F-Secure is marketing its service, which is designed to help protect mobile devices against malicious software, by carrying out a sustained campaign of hype.

"F-Secure is saying there's a huge risk of malcode spreading, but they've built this up," said Simon Perry, the European vice president of security for CA. "If you look at their behavior, they've consistently pushed this message. But it's a theoretical; not a real threat."

The Finnish company signed a deal with U.K. wireless service provider Orange last week to provide security for the operator's smart devices.

Matias Impivaara, director of mobile security for F-Secure, denied that the company had engaged in hype.

"It's amusing--the idea that I could sell something to an operator that they don't need," Impivaara told ZDNet UK. "Orange had a formal procurement process, where they put the contract out to tender, based on their own analysis. It's a process that doesn't happen by accident."

The company's marketing machine is not so big that it could change the opinion of the world, Impivaara added. "It's flattering for me as a salesperson, but I'm just not that good," he said.

CA, which makes corporate security products and the eTrust consumer protection range, insists that the threat to smart-phone users is minimal and that Orange customers are better off not spending their money on mobile security. "Dig below the skin, and the message stops sounding pithy and starts smelling rather rotten. At the core of the rot is the mostly undeniable fact that there is no threat to protect against," Perry said.

F-Secure accepted that there were few examples of malicious software targeting smart phones at the moment, but it said cases had been seen in the wild. "It's not a global epidemic, but there are real people who have got it. There have been several tens of different viruses. (These are the) early days for mobile virus writers," Impivaara said.

CA said criminals do not have an economic incentive to develop malicious code and that the risk of such attacks spreading around smart phones is minimal because of a lack of interoperability between platforms and phone models. Network services don't allow for the fast spreading of code from phone to phone, and user interaction is required for any viruses to spread, the company added.

It said F-Secure has created an atmosphere of fear, uncertainty and doubt to sell its product, undermining the relationship of trust that has been established between the industry and vendors.

QUICK POLL
Do you agree that mobile security threats are overhyped?
No, I was a victim of mobile viruses
Yes, antivirus companies are spreading fear, uncertainty and doubt
Maybe, I've not been hit before, but I won't discount the threat

"While F-Secure's bankers and owners may be pleased with the cash flowing into their coffers from the deal, every security professional should be appalled by the perception this creates of our market," Perry said. "Industry and vendors are now more consultative and honest about risks, not just beating something up to sell it. F-Secure has done the industry a disservice."

F-Secure's Impivaara responded by saying that both mobile operators and clients had approached the company.

"It could be bad for the industry if we were trying to scare people, but people call us with real problems and real viruses. We have created a solution to these threats for our customers. If we have mobile operators coming to us, we would be quite stupid to turn them down," he said.

"I have difficulty understanding how this can be bad for (the antivirus) business. This is not a mass problem for all consumers. But our solution is available to those who need it, and there are people who need it today," Impivaara added.


See also:  Security
WORTHWHILE?

0

0 votes
Blog

Talkback 2 comments

Absolute rubbish. This is not fear-mongering. This is proactive thinking.

I work with financial auditors. There are huge financial incentives for malware authors to target smart phones (execs who store their logon information on the devices is only one). I want to hear from the naysayers when the first virulent outbreak hits--the one that can replicate from phone to phone until it finds a dual-mode device that can also connect to a WiFi hotspot (it's not that far off).
Posted by Andrew James Riemer on Tuesday, July 25 2006 10:38 PM

Just please explain to me than why CommWarrior is so widespread in Asian countries? You get like thousands of Bluetooth beams an hour if you're in public place and have Bluetooth discoverable. In some Asian countries one on 5-10 MMS is sent by CommWarrior. Mobile malware not dangerous? Check this out than:

(web link)
Posted by anonymous on Tuesday, July 25 2006 11:17 PM

Guest user

Guest user

Level: 
Joined: —
Already a member? Log in »



 

Loading...

Tech Jobs Now!

Replicating your infrastructure in a lab

Enterprise Servers & Storage

Learn two ways to replicate your current environment for testing and evaluation of new server platforms.


Read more »



  • HPC Applications

    Ever wondered if High Performing Computing systems really matter in our day-to-day world? HPC is not just reserved for the some obscure high-end scientific studies.

    David Scott from Intel Corporation gives you a quick tour to the process of developing HPC applications and the interesting world of HPC Applications in today's industries, including the lucrative oil industry.
    Play video


  • Maximize IT Spend: Business Acceleration

    How do you ensure your IT solutions are well integrated and streamlined across your enterprise? Rajendhiran Sanggaran from Oracle explains the processes and important considerations required to enable IT to fuel your business to the next level of growth.
    Play video

Tags

  1. antivirus
  2. attack
  3. attacks
  4. by
  5. cards
  6. china
  7. cisco
  8. companies
  9. face
  10. firefox
  11. flaws
  12. google
  13. mac
  14. microsoft
  15. mobile
  16. online
  17. os
  18. prompts
  19. routers
  20. security
  21. server
  22. site
  23. threat
  24. trojan
  25. uk
  26. vista
  27. warning
  28. warns
  29. windows
  30. xp

What's the Indian definition of privacy?

Blog thumbnail

Two days back, I was having dinner at an aunt's place. She is a leading doctor. We were discussing my school friend, who happens to be her patient.

My aunt..... by Swati Prasad

Read more »