<?xml version="1.0" encoding="utf-8"?>
<?xml-stylesheet href="http://blogs.forum.nokia.com/styles/rss.css" type="text/css"?>
<rss version="2.0">
 <channel>
  <title>Lucian Tomuta's Forum Nokia Blog - Can you write an antivirus?</title>
  <description>Forum Nokia Blogs</description>
  <link>http://blogs.forum.nokia.com/summary.php</link>
  <generator>LifeType 1.2</generator>
        <item>
    <title>That&#039;s pointless</title>
    <description>&lt;p&gt;Looks, i can post comments, becouse captcha is always wrong.&lt;/p&gt;
&lt;p&gt;Interesting, wat you want to hear? Magic wand does&#039;t exists. Mobile malware problem is not different from a PC security problems, and even for PC there are no &quot;simple&quot; solution. Nokia alrady make &quot;curse of silence&quot; protection tool. Does Nokia going to provide a separate tools for every malware application? If no, then you should write antivirus with db as tote_b5 says, if you really need a solution. And keep its up to date. Thats simple.&lt;/p&gt;
&lt;p&gt; Everything can be cracked and bypassed if attacker see a big piece of cheese in the end of that maze. Actually i face once with guys who ask me to make a trojan like that (of cource, i reject their proposal) - finally, after all tricks, all what they really need is to send sms and make calls to predefined set of numbers. Thats only way to gain profit. Nobodie want just to harm your device. And i&#039;m sure that malware connect to internet host just to update a list of those &#039;payed&#039; SMS and phonenumbers. Attacker doesn&#039;t interested in anything else: nor your logs, nor your photo&#039;s, nor a CPU for DDOS. At least for now. I&#039;m sure the only rational way to stop malware on mobile phones is to protect not a phones itself, but payed services which they provide. I wonder how easely you can lost your money - just send sms and network provider happy to decrease your account. No any confirmations, no any captcha, no any security locks.. Thats freedom to become looted. I have to enter captcha even to post that free comment, but you never find any protection on a short payed sms numbers. My opinion, what network providers have to increase security of those services, becouse they make me a desired target of attackers even if i dont know about those services, never use them and don&#039;t give them any agreement to provide those services for me. But I wonder if network providers will do any confirmation captcha mechanism  without judgement. And I&#039;m sure what malware problem never be solved becouse nobodie really interested in that - finally end user will pay for all, to hackers for unconcern or to security companies for protection, or to both. And even device monufacturers does&#039;t really interested in security of their devices - they even does&#039;t want to prevent their stealing.&lt;/p&gt;
</description>
    <link>http://blogs.forum.nokia.com/blog/lucian-tomutas-forum-nokia-blog/2009/02/21/can-you-write-an-antivirus#comment24851</link>
    <guid>http://blogs.forum.nokia.com/blog/lucian-tomutas-forum-nokia-blog/2009/02/21/can-you-write-an-antivirus#comment24851</guid>
    <author>truf</author>
    <source url="http://blogs.forum.nokia.com/rss.php?blogId=300033&amp;profile=rss20">Lucian Tomuta&#039;s Forum Nokia Blog</source>
   </item>
        <item>
    <title>I&#039;m hapy with Mark&#039;s solution ...</title>
    <description>&lt;p&gt;... but I&#039;ve thrown in the remarks about public APIs and capabilities only to make the problem appear more complex :) Any &quot;creative&quot; solution in that context could have been fun to read, as fun as some of the comments one can read in some of the blogs that cover the subject.&lt;/p&gt;
&lt;p&gt;As for real and complete solutions, whatever the APIs and capabilities they need, I live that in the hands of the security companies, it&#039;s their business to make them work.&lt;/p&gt;
</description>
    <link>http://blogs.forum.nokia.com/blog/lucian-tomutas-forum-nokia-blog/2009/02/21/can-you-write-an-antivirus#comment24817</link>
    <guid>http://blogs.forum.nokia.com/blog/lucian-tomutas-forum-nokia-blog/2009/02/21/can-you-write-an-antivirus#comment24817</guid>
    <author>ltomuta</author>
    <source url="http://blogs.forum.nokia.com/rss.php?blogId=300033&amp;profile=rss20">Lucian Tomuta&#039;s Forum Nokia Blog</source>
   </item>
        <item>
    <title>The requirements are so vague</title>
    <description>&lt;p&gt;Lucian,&lt;/p&gt;
&lt;p&gt;Are you interested in such a solution that is similar to what existing antivirus solutions do? I.e. keep track of a central database with some metadata (e.g. UID, vendor name, etc.) for each virus and whenever a new application is being installed we query that database to see if we should worry. Because during *installation* we can&#039;t really do much more. Even more, as long as a virus is not in the database *yet* we will not recognize it as an undesirable component for the system.&lt;/p&gt;
&lt;p&gt;Or perhaps it&#039;s not only *installation* that you think of, but tracking what 3rd-party applications do during their lifetime? When they do something that matches a &quot;suspicious&quot; pattern (such as getting data from Contacts and sending SMS to all/sending all data to a remote server, etc.) we ask the user for confirmation if she is really aware that one of the 3rd-party applications she installed is doing something suspicious and if it&#039;s really allowed. Getting an affirmative answer would indicate that we should no more worry on that application in the future - OTOH a &quot;Yeah, it&#039;s really strange&quot; answer could trigger us to remove that component right away before doing too much damage. And we could report that to our central database, too (wherever it would be).That is, it would be a self-learning &quot;firewall&quot; in the sense that it&#039;d actively monitor the device.&lt;/p&gt;
&lt;p&gt;Briefly: more info needed. :)&lt;/p&gt;
</description>
    <link>http://blogs.forum.nokia.com/blog/lucian-tomutas-forum-nokia-blog/2009/02/21/can-you-write-an-antivirus#comment24816</link>
    <guid>http://blogs.forum.nokia.com/blog/lucian-tomutas-forum-nokia-blog/2009/02/21/can-you-write-an-antivirus#comment24816</guid>
    <author>tote_b5</author>
    <source url="http://blogs.forum.nokia.com/rss.php?blogId=300033&amp;profile=rss20">Lucian Tomuta&#039;s Forum Nokia Blog</source>
   </item>
        <item>
    <title>Sorry!</title>
    <description>&lt;p&gt;Without the SID, or some pretty powerful capabilities I don&#039;t think there are many interesting alternatives.  It&#039;d still be good to know if others have some more &quot;creative&quot; solutions though.&lt;/p&gt;
</description>
    <link>http://blogs.forum.nokia.com/blog/lucian-tomutas-forum-nokia-blog/2009/02/21/can-you-write-an-antivirus#comment24815</link>
    <guid>http://blogs.forum.nokia.com/blog/lucian-tomutas-forum-nokia-blog/2009/02/21/can-you-write-an-antivirus#comment24815</guid>
    <author>Sorcery-ltd</author>
    <source url="http://blogs.forum.nokia.com/rss.php?blogId=300033&amp;profile=rss20">Lucian Tomuta&#039;s Forum Nokia Blog</source>
   </item>
        <item>
    <title>Oh Mark ...</title>
    <description>&lt;p&gt;... I was hoping for some more &quot;creative&quot; solutions first :) Obviously your solution is *the* trivial solution and it is also effective against this particular threat since I don&#039;t expect a new signed release of it soon.&lt;/p&gt;
</description>
    <link>http://blogs.forum.nokia.com/blog/lucian-tomutas-forum-nokia-blog/2009/02/21/can-you-write-an-antivirus#comment24814</link>
    <guid>http://blogs.forum.nokia.com/blog/lucian-tomutas-forum-nokia-blog/2009/02/21/can-you-write-an-antivirus#comment24814</guid>
    <author>ltomuta</author>
    <source url="http://blogs.forum.nokia.com/rss.php?blogId=300033&amp;profile=rss20">Lucian Tomuta&#039;s Forum Nokia Blog</source>
   </item>
        <item>
    <title>The trivial solution</title>
    <description>&lt;p&gt;1) Take any example application from the Forum Nokia that requires no capabilities (to get least capabilities requirement)&lt;br /&gt;
2) Change the name of the executable written to the device (only need change in the package file) to EConServer.exe&lt;br /&gt;
3) Build the project, self-sign and install the SIS file&lt;/p&gt;
&lt;p&gt;Installer will now not allow this virus to install because of name conflict in \sys\bin.&lt;/p&gt;
&lt;p&gt;That should do the trick.  Not really an &quot;anti-virus&quot; though and very easy for the attackers to work around.&lt;/p&gt;
&lt;p&gt;Mark&lt;/p&gt;
</description>
    <link>http://blogs.forum.nokia.com/blog/lucian-tomutas-forum-nokia-blog/2009/02/21/can-you-write-an-antivirus#comment24813</link>
    <guid>http://blogs.forum.nokia.com/blog/lucian-tomutas-forum-nokia-blog/2009/02/21/can-you-write-an-antivirus#comment24813</guid>
    <author>Sorcery-ltd</author>
    <source url="http://blogs.forum.nokia.com/rss.php?blogId=300033&amp;profile=rss20">Lucian Tomuta&#039;s Forum Nokia Blog</source>
   </item>
   </channel>
</rss>
