2011: The year your mobile phone becomes your wallet
money.cnn.com
money.cnn.com
At Defcon 18, there was a presentation on how to access RFID from long range (http://www.youtube.com/watch?v=nEBrslz0Xf4). It makes me nervous that other people can also do this stuff.
There are already cards that do NFC, such as MBTA (public transportation) Charlie cards and American Express credit cards. However once NFC becomes even more common, will this invite the bad kind of hackers to bump up their efforts to steal your money?
So, how secure is this?
I think all of the smart phone operating systems have had a trojan horse app on them at some point. Most of them probably just did simple things before like a backdoor, making phone calls or stealing info. If your phone also controls your money...
Also, trojans still have to compromise the OS security. It's not the same deal as with non-secure information (like spyware games accessing the contacts list, just because users don't care about app permissions) - the certificate store will be certainly guarded way more carefully.
* I'm not trying to make you guys paranoid. Just wondering about the possibilities and playing devil advocate.
However, you have a point: classic "dancing bunnies" problem[1] is certainly out there. Promise average user nice things, ask him to do some cryptic actions, and he'll happily follow your instructions without really understanding any consequences.
A random app from the Market? Hell no, it's not getting root and it's not getting access to my data.
The thing is, this vector already exists. Download the Paypal app. Login. Now download drivebyacct2's malicious app on the Market. If you grant it root access through SuperUser, it could theoretically read out your Paypal credentials and do all kinds of stuff.
Personally, I consider it to be very low risk.
I suppose 2011 is more the year where you will pay $5 for your Latte with your mobile phone on the condition to have an account with an organization charging you a percentage when loading your account, plus a small transaction fee and doing the same to the shop using this system.
I am sarcastic, maybe the effect of going through a PCI DSS compliance extortion scheme yesterday. Out of topic technical bonus point, the SSL ciphers allowed for your server to be "compliant": !EXPORT:!eNULL:!MEDIUM:!LOW:TLSv1:SSLv3.
It's no secret that the banking industry is screwed up. It will be interesting to follow how this industry changes as new startups and technologies are applied to traditional banking models. Hopefully somehow I end up with more money in the process :)
Is 2011 also the year of Linux on desktop?