Communications

Mobile Flaw Could Cloak Clicks

Researchers demonstrate that mobile phones are exceptionally vulnerable to a browser bait and switch.

  • Tuesday, August 17, 2010
  • By Robert Lemos

It's possible to craft a malicious website so that a user's clicks are secretly redirected to a legitimate site in a way that steals a user's passwords and other data. Many Web developers have added protections to block the tactic on standard websites, but Stanford University researchers warn that there are not nearly enough defenses against the technique on mobile websites, which are accessed from devices such as the iPhone.

As a result, a smart-phone user could think he's tapping to check a baseball score but is actually tapping on a button in a hidden page to confirm a money transfer.

Mobile users could be especially vulnerable to such tricks. For one thing, on smart phones, the parts of the user interface that indicate whether a page is secure generally appear in the browser bar, which usually disappears to maximize the screen area. Because the browser usually fills the whole screen of the phone, an attacker can "draw anything he wants on the screen, and the user cannot tell what's real and what is from the attacker," says Elie Bursztein, a postdoctoral fellow at the Security Laboratory at Stanford University.

Above all, mobile devices are becoming fatter targets, Bursztein says, because people are spending more time on them and exchanging important data. "People buy things on their phone, they use Facebook and Twitter, and soon enough they will be doing banking on the phone," he says.

Advertisement

Bursztein and the other Stanford researchers presented their findings at last week's Workshop on Offensive Technologies (WOOT) workshop. They called the problem "tapjacking," a reference to "clickjacking," a term used when the same method of attack is used on a PC browser.

"This is a bunch of small hacks hung together to create a big problem," says Kevin Mahaffey, chief technology officer of Lookout, a security firm that focuses on mobile devices. "And it will take a lot of concerted effort to solve the problem."

Print

Related Articles

How Android Security Stacks Up

An Android phone's approach to security is radically different from an iPhone's--but is it better?

Experts Break Mobile Phone Security

A researcher has shown that attacks on a long-standing mobile phone standard are possible.

Security in the Ether

Information technology's next grand challenge will be to secure the cloud--and prove we can trust it.

Close Comments

To comment, please sign in or register

Forgot my password

rsanchez1

213 Comments

  • 539 Days Ago
  • 08/17/2010

Jailbroken Hack

It was just a few days ago that Apple patched a hack that allowed iPhones to be jailbroken simply by pushing a button on a website. These devices have been shown to be extremely vulnerable from the browser, so it's no surprise they keep discovering these things.

Reply

technohigs

1 Comment

  • 538 Days Ago
  • 08/18/2010

mobile phone threats

Do people really use the phone browsers for sensitive activity like banking? Guess we have to be carefully what sites we visit online.

I worry more about apps like these
http://www.prweb.com/releases/2010/08/prweb4370174.htm
trackwary pro spy apps records everything your phone is doing at all times.

If something like this was to get on your phone from a browser security hole then I'd really be worried.



Reply

Advertisement

MAGAZINE

Can We Build Tomorrow's Breakthroughs?

Manufacturing in the United States is in trouble. That's bad news not just for the country's economy but for the future of innovation.

Advertisement

Technology Review Lists

TR50

Our list of the 50 most innovative companies, including the following:

Suntech

Layar

Calxeda

Square

More

Advertisement

Facebook

Advertisement