Smart Devices, Apps and Attacks
Just caught this article across my twitter feed and wanted to make a couple of quick comments. To summarize the article, there are plenty of attacks against apps for different devices and users should be wary.
Comment 1: Users don’t have enough foresight or concern to be digging into these problems. Because the user base is so large on these devices, it becomes next to impossible to educate them all. Even the most privacy disciplined individuals aren’t focused enough to spend the time focusing on the apps they install on their smart device.
Which leads me to comment 2. When discussing issues like this, you need to address it with the developers (or company). The great part about this is that most mobile development shops are just a couple of folks, making initial contact easier. The tradeoff is that they may not have the resources to immediately address the need. And in the case of the iTunes app store, there is review time as well.
And comment 3: the idea of putting together a group specifically focused on mobile device app analysis has been floating around in my head for a couple of years. Given the complexity of these apps, you’d need start with the most popular apps and dig into understand the use cases and trends that developers are exhibiting. But the idea does have some traction given the concerns of the researchers presenting in that article.