Newsletters
Customer Relationship Management News NewsFactor Sites:       NewsFactor.com     Enterprise Security Today     CRM Daily     Business Report     Sci-Tech Today  
   
Home CRM Systems Customer Service Business Intelligence Sales & Marketing More Topics...
Vblock™ Systems:
Advanced converged infrastructure
increases productivity & lowers costs.

www.vce.com
Digital Life
24/7/365 Network Uptime!
Average Rating:
Rate this article:  
Samsung Galaxy S4 Vulnerable to Malware
Samsung Galaxy S4 Vulnerable to Malware

By Adam Dickter
December 26, 2013 12:57PM

Bookmark and Share
A Ph.D student in Israel says adding an innocuous app to the non-secure area of Samsung's Knox architecture can lead to malware compromising the secure area due to the security breach. Samsung's Knox is a state-of-the-art, secure mobile architecture, so the student was surprised to find that such a big "hole" exists and was left untouched.
 


Adding apps to Samsung's Knox architecture for its Galaxy S4 might create a vulnerability that could allow e-mails, data transfers and browser histories to be accessed by third parties, says a research team at a prominent Israeli scientific university.

The supposed flaw could even allow hackers to manipulate data believed to be secure, a potential setback to the global smartphone king's efforts to have its Android-based devices adopted by employees of the U.S. Department of Defense, which has given preliminary approval for them.

Was Software Up To Date?

Samsung did not respond to our request for comment in time for publication but told The Wall Street Journal for its report on the flaw Monday that it is investigating the matter.

Samsung "takes all security vulnerability claims very seriously" a spokesman told the paper, while stressing that a preliminary investigation showed that "the threat appears to be equivalent to some well-known attacks."

The team at Ben Gurion University (BGU) of the Negev appears to have conducted the test on a device that was not running the complete software that would have been used by corporate clients, Samsung said.

"Rest assured, the core Knox architecture cannot be compromised or infiltrated by such malware," the spokesman said.

Discussing the finding on BGU's Web site, the researchers said a Ph.D. student, Mordechai Guri, stumbled onto the vulnerability during an unrelated project he is working on with a research team at the cyber security labs of the Homeland Security Institute at the campus, located in Beer-Sheva.

“To us, Knox symbolizes state-of-the-art in terms of secure mobile architectures and I was surprised to find that such a big ’hole‘ exists and was left untouched," Guri said in a statement.

"The Knox has been widely adopted by many organizations and government agencies and this weakness has to be addressed immediately before it falls into the wrong hands," he added.

Full details were provided to the South Korea-based electronics giant, BGU said.

Knox, whose name is meant to invoke the heavily fortified Kentucky Army base that contains much of the U.S. gold reserve, consists of a secure "container" within the regular phone environment with better security protection. BGU claims that adding a seemingly innocuous app to the non-secure area can lead to malware compromising the secure area due to the security breach.

Cause For Concern

"Users should be concerned about this apparant security flaw," said technology analyst Jeff Kagan. "However it is important for every user to understand that security flaws show up all the time in [devices] by various manufacturers."
 

Tell Us What You Think
Comment:

Name:



Barium Ferrite Is The Future Of Tape: Barium Ferrite (BaFe) offers greater capacity, superior performance, and longer archival life compared to legacy metal particle (MP) tape. Click here to learn more.


 Digital Life
1.   Yahoo COO Gets $58M Parting Gift
2.   Teen Arrested for Heartbleed Hack
3.   Malware Targets Facebook Users
4.   Mt. Gox Is Headed for Liquidation
5.   Amazon 3D Smartphone Pics Leaked


advertisement
BlackBerry Drops T-Mobile After Spat
Moving on to other carriers after snub.
Average Rating:
Yahoo COO Gets $58M Parting Gift
What was the company thinking?
Average Rating:
Teen Arrested for Heartbleed Hack
Data stolen from Canadian tax agency.
Average Rating:


advertisement
Product Information and Resources for Technology You Can Use To Boost Your Business

Network Security Spotlight
Google's Street View Software Unravels CAPTCHAs
The latest software Google uses for its Street View cars to read street numbers in images for Google Maps works so well that it also solves CAPTCHAs, those puzzles designed to defeat bots.
 
Canadian Teen Arrested for Heartbleed Hack
One week after the OpenSSL Heartbleed vulnerability was unveiled, Canadian authorities have made the first arrest -- a London, Ontario teenager -- connected to exploiting the security hole.
 
IBM Offers Security, Disaster Recovery as SoftLayer Service
New disaster recovery and security services for SoftLayer clients are being added by IBM. Big Blue said the new capabilities will speed cloud adoption by alleviating concern over business continuity.
 

Enterprise Hardware Spotlight
Vaio Fit 11A Battery Danger Forces Recall by Sony
Using a Sony Vaio Fit 11A laptop? It's time to send it back to Sony. In fact, Sony is encouraging people to stop using the laptop after several reports of its Panasonic battery overheating.
 
Continued Drop in Global PC Shipments Slows
Worldwide shipments of PCs fell during the first three months of the year, but the global slump in PC demand may be easing, with a considerable slowdown from last year's drops.
 
Google Glass Finds a Home in Medical Education, Practice
Google Glass may find its first markets in verticals in which hands-free access to data is a boon. Medicine is among the most prominent of those, as seen in a number of Glass experiments under way.
 

Mobile Technology Spotlight
Google Releases Chrome Remote Desktop App for Android
You're out on a sales call, and use your Android mobile device to grab a file you have back at the office on your desktop. That's a bit easier now with Google's Chrome Remote Desktop app for Android.
 
Amazon 3D Smartphone Pics Leaked
E-commerce giant Amazon is reportedly set to launch a smartphone after years of development. Photos of the phone, which may feature a unique 3D interface, were leaked by tech pub BGR.
 
Zebra Tech Buys Motorola Enterprise for $3.45B
Weeks after Lenovo bought Motorola Mobility’s assets from Google for $2.91 billion, Zebra Technologies is throwing down $3.45 billion for Motorola’s Enterprise business in an all-cash deal.
 

Navigation
CRM Daily
Home/Top News | CRM Systems | Customer Service | Business Intelligence | Sales & Marketing | Contact Centers | Customer Data | CRM Press Releases
NewsFactor Network Enterprise I.T. Sites
NewsFactor Technology News | Enterprise Security Today | CRM Daily

NewsFactor Business and Innovation Sites
Sci-Tech Today | NewsFactor Business Report

NewsFactor Services
FreeNewsFeed | Free Newsletters | XML/RSS Feed

About NewsFactor Network | How To Contact Us | Article Reprints | Careers @ NewsFactor | Services for PR Pros | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2014 NewsFactor Network. All rights reserved. Article rating technology by Blogowogo. Member of Accuserve Ad Network.