First case of malware in the Apple App Store.
securelist.com
securelist.com
Many applications do that for sanity checks, I don't think it's any kind of indication of malware. It's a common technique to have some "magic number" that you can recognize to make it less likely that a transfer of data has some kind of corruption [1]. The benefit of using a number like 0xdeadbeef over, say, 0x1857de89 is that you can tell at a glance if the first one is correct.
[1] Yes, one should use error codes and do this the real way. Not everyone does.
I remember a blog post of someone who ran the whole dictionary through 'l337sp34k' filter. The best word they found was 0xdefeca7e.
- Easy to remember and type
- Not leet speak
- Reminds you to keep ego in check
It's simply an app that uploads your address book to a remote server. Up until recently, it was considered industry standard to do that.
The only thing this app does different is that the server then sends SMS messages to the numbers it uploads from your address book.
All this really is showing is that Apple should've made iOS from the beginning ask the user for permission before allowing an app to access the address book. After iOS 6, this app won't do anything.
As a total aside, if you are an AT&T customer you can just forward SMS spam to 7726 (SPAM) and they take care of it - I'm not affiliated with AT&T (just a customer) and I wish they would publicize this stuff more.
ceejayoz is right about Verizon also supporting this feature (I just reported the spam message I had from the other day). Via https://community.verizonwireless.com/message/696743#696743 :
From MikeS1_VZW
We have heard our customers on this, and we have launched a new program
to help with SPAM. Take one (or several) of the SPAM messages and
forward it to 7726 (which spells SPAM). This is a new process. Once you
forward the message to 7726, you will get a reply text message asking
the identity of the SPAM sender (the "From" address in the SPAM message
you received). Once received, you will get a "Thank-you" message from
the 7726 number. We will investigate on the back end.
The messages you send to and receive from the 7726 number are free of
charge. This is a brand new program we are testing, and it just started
on 09/1/11. Please make this common practice when receiving SPAM
messages. This is not to be confused with alerts though. If you get
alerts (something you signed up for), you should reply STOP to the
message received before going the whole 7726 route.Here's what I want: a whitelist. If I want to add you to my whitelist, I put my phone into "receiving" mode. I get your text, confirm adding you, then go back into normal mode, where texts from anyone not on the list are rejected and I don't pay for them.
Careful what you wish for. It might end up being implemented as an expensive and useless marketing ploy.
But it does sound useful. And if it gets mindshare, competition could make it cheaper or free.
As more people get mobile e-mail, things like iMessage, etc., they're going to have to keep SMS from being overly spammy or people will stop using it.
But I agree with you for the most part a distinction between known senders and unknown senders would be great. The only exception to this that I can think of personally, is for things like the Google 2-factor auth messages which appear to be sent from random numbers (in addition to being random numbers!).
Verizon apparently supports, as well.
You're right though, that it's basically exposing a hole in the OS security metaphor. Two really: the address book was unprotected and the application review process didn't work.
I was thinking more of "this will not steal my credit card" (unless you keep that info in your address book) type of malware. But, yes. I get your point.
Ideally apple has contact information for this developer, and, presuming the Developer violated some license with regards to what they can do with user data, Apple can now take legal steps against this developer.
They should really just sandbox the apps and put a proper permission granting system in place.
Few processes in practice are 100% effective. One, or a even few, failures does not indict the idea of curation, but rather, in my mind at least, reinforces its value.
Of course, as others have mentioned, software protections of the Address Book would be nice, and are coming (though I'm not sure they would have stopped this app from doing its thing).
Whether that trade-off is worth it is a completely different question (I think it is not – Apple should allow users to install whatever they want, they can even make enabling that needlessly complicated, but they should allow it.) but if you are immediately jumping to the conclusion that Apple’s curated approach is devoid of value because one piece of malware made it through your analysis of the situation is lacking and populist.
It seems to be 'scaling' just fine.
http://www.securityweek.com/sneaky-ios-malware-surfaces-app-...
Agreed.
Re: the rest, well, it depends on who controls the remote server. The action itself might not be so worrisome, but what the action enables could be, IMO.
Facebook's issue was email. This is phone number SMS.
- How can a 3rd party send a message that appears to be from the user that ran the program?
- Why can't someone have the same control over SMS as they can over email? (Filter based on trust, spam control)
I'd also be interested to know what sort of filtering is done by mobile operators. I'm guessing there is some, (based off of pacaro's comment), but do these features differ by operator? Is there a standard?
Unfortunately this is just an issue of cid spoofing. Nothing new and carriers still let it happen.
http://news.ycombinator.com/item?id=4156438
I guess that's just one more reason to keep their marketing the new way.