Phishing app hits Android market...3 weeks ago
itworld.com
itworld.com
When you download the Bank of America app, you click on the link on the Bank of America website and it goes directly to the Android App Market where I can download the application. That is all the vetting I need.
There is obviously going to be some issues with the Android App Market since it is completely open, but I would rather take the risk, vet claims myself and not be limited to the apps I am offered.
You really think everyone is going to visit the Bank of America site first? People will simply Google "BofA app for droid" ... then they may land on an unauthorized phishing app.
You could then teach users to only give passwords via the proper OS interface. (One which would be able to display some sort of 'trust phrase' established earlier by the user.)
If the phishing app doesn't collect and retain your usernames/passwords directly, risk is mitigated.
It wouldn't hurt to prominently display certified sources either. Some sort of interface cue that the App you're downloading is verified to have been signed by the same people who run the site it's trying to access.