All the latest UK technology news, reviews and analysis

F-Secure blocks spying app for Windows and Android

by Iain Thomson

18 Oct 2010

Be the first to comment

  • Tweet this
F-Secure

F-Secure is blocking a sophisticated mobile phone spying application, despite being ambivalent about the creator's motives.

Phone Creeper is a Windows Mobile application that lets an outside user access a mobile phone's calls, SMS logs, contacts, calendar information and GPS data that tracks location. The developer has said that an Android version will be released shortly.

"This is a phone espionage suite. It can be silently installed by just inserting an SD card with the files below on it," said Phone Creeper creator Chet Striker from XDA-Developers in the latest update.

However, in an Ethical Statement, Striker said that he created the code to show what was possible with the handset, and because it was fun to develop something unique.

He said that he will work with other XDA developers to find a solution to blocking the flaws and will release it as open source code.

F-Secure said that it is blocking the application with its mobile security software because of its functionality, but does not believe that Striker's motives are in question.

"Striker doesn't seem like a bad guy in our book, but a silently installing espionage suite should be detected by a security suite. The author's motives aren't as important as what the tool actually does," said Sean Sullivan, security advisor at F-Secure, in a blog post.

The move highlights the continuing problems between security researchers and software firms over responsible disclosure of flaws.

While most responsible researchers tell companies about flaws, many complain about the speed, or lack thereof, with which the security holes are fixed.

Microsoft's recent Coordinated Vulnerability Disclosure system has sought to lure more developers but still has a way to go it seems.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

35%

0%

11%

54%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Symanteccloud

Social networking: a guide for IT managers

Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them

Riverbed

Mitigating the risks of IT change

The importance of understanding your infrastructure

Lead PHP Developer - Technical Architect - Ecommerce Manager

Lead PHP Developer - Technical Architect - Ecommerce...

C# / .NET Software Engineers – Leeds City Centre – C# (£30-50k)

C# Software Engineers required to join rapidly expanding...

Java / J2EE Developers – Leeds City Centre – Java / J2EE (£30-50k)

Java / J2EE Software Engineers required to join rapidly...

Developer (MIS - SQL / T-SQL, HTML, CSS or Javascript)

Developer (MIS / Business Systems - SQL / T-SQL, HTML...

To send to more than one email address, simply separate each address with a comma.