Do you monitor the outgoing traffic from your cellphone?
There is no evidence that it is happening, with plenty of security researchers and interested amateurs keeping their eyes open for it. There's nothing special about iOS that prevents you from discovering this sort of app behaviour that isn't present on Android.
You mean other than seeing it happen in the biggest similar ecosystem?
There's nothing special about iOS [...] that isn't present on Android
Exactly. So why should iOS be different with regard to malware then?
It's being noticed in the biggest similar ecosystem, too, so by that logic it should be noticed in both if it is present in both.
> Exactly. So why should iOS be different with regard to malware then?
The Apple review process is present in iOS. The process to market is markedly different.
Sorry, but how does discovering one instance of malware in the android market imply that any instance in the iOS Store will be discovered at the same time? Is there some sort of quantum-link that I'm missing?
The Apple review process is present in iOS.
I was told the Apple review process does not involve a full code analysis. And even if it did, malware authors are known to be quite creative in hiding their payloads.
Apps you have installed might or might not already contain shell-code embedded into seemingly innocent images or assets, with very little chance of detection.
I'm not a security researcher or blackhat. But under the premise that you can (afaik) not root a phone without the user noticing, my strategy for pulling off an attack would be a sleeper-strategy. I'd first seed my payload silently, and then pull the trigger all at once, at some point in the future.
Moreover, considering there has been a one-click safari jailbreak[1], you may not even need to embed actual malware in an app. It may be enough to be able to remotely instruct the app to load a specific URL at your command - now how's that for an attack vector.
So, technically there is no difference between doing either on android or doing it on iOS.
If you still want to claim otherwise then you should come up with a better argument than "but apple has a review process!".
[1] http://lifehacker.com/#!316287/jailbreak-your-iphone-or-ipod...
Twofold: this is not the only incidence of malicious software on Android, and I never made the claim that all instances should necessarily be immediately found - just that, if it's as easy to slip in as the OP claimed, that SOMETHING should've been found by now.
Well, I'm working about as hard as PG. No, actually I work much harder. I SHOULD have found the one startup-idea by now that takes off and makes me as wealthy as him!
Notice the flaw in your reasoning? There is no correlation.
If inserting malware into iOS is simple, it would be done, and done widely. If done widely, the chances are very good that someone would've detected it in at least one such application.
Oh, you think so? Both are a function of skill, heuristics, sweat - and a great deal of luck.
If inserting malware into iOS is simple...
I'm not sure how I could make it any clearer, perhaps look at some of the other threads on this article?
So I'll just repeat:
iOS is not different to Android with regard to malware.
Long version: The difference is so small as to be negligible.I'm not sure I understand why that is such a bitter pill to swallow for some people.
Then why is malware being identified on Android but not iOS?
I know that Objective C and messaging is different from function linking in some fashion, but certainly there must be a way of determining if disallowed APIs are ever called, at all, without just using the app and hoping you trap them.
I think at the very least they should be able to examine the executable for object types used, and function signatures used, as well as determining what signatures are passed to which objects.
They do. I used an old example from the Internet, and that API was now private; Apple rejected the app and included the name of the API that I wasn't supposed to use.
"In theory there is no difference between theory and practice. In practice there almost always is!"