On mySimon: Ecko Street Trak Sneakers
BNET Business Network:
BNET
TechRepublic
ZDNet

June 11th, 2007

10 million iPhones = An ideal platform for malware

Posted by Adrian Kingsley-Hughes @ 4:29 am

Categories: Apple, Gadgets, Industry, Security, Thoughts

Tags: Apple iPhone, Steve Jobs, Security, Platform, Malware, Cell Phone, Let, Adrian Kingsley-Hughes

In Focus » See more posts on: iPhone

Let’s make a few assumptions. First off, let’s assume that Steve Jobs is bang on right and the iPhone will be a massive success. Let’s assume that it will be the biggest thing since the iPod. Let’s also assume that Steve’s right when he says that Apple can shift 10 million iPhones over a year and capture 1% of the cellphone market. If everything works as Steve Jobs iPhonesees it playing out, then he’ll be responsible for having created one juicy platform for malware writers.

OS X doesn’t dominate any market it’s in, but the iPhone might, and that will be the key difference when it comes to malwareHave you ever wondered why you don’t regularly come into contact with malware when using your cellphone? One of the main reasons is that no single cellphone has managed to gain enough of a market share to become a large enough platform for malware to leverage. The current cellphone market is diverse and fragmented across a multitude of platforms. Even if you confine yourself to looking at a single specific platform, you’ll come across totally incompatible sub-platforms. The fact is that it’s tough enough to write legitimate mobile applications using something like J2ME (Java2 Micro Edition) that’ll work smoothly across a small number of phones. The combination of an abundant lack of standards and the number of companies competing aggressively means that no single platform has managed to capture enough users to create a critical mass. If legitimate applications written by legitimate programmers find it difficult to work across platforms, what chance do the malware writers have of coming up with code that works over a enough phones to make their efforts worthwhile? It’s negligible at best. The current state of play offers security. Sure, it’s security through obscurity, but so far it’s served us well. As it stands now, owning a cellphone is relatively risk-free and doesn’t open a door to malware.

But Steve Jobs wants to change how things are. He is not happy with entering the cellphone market in a small, reserved way. He wants to enter the market with a bang and hopes that within 12 months Apple will be able to create a dominant platform where one didn’t exist before. If things work according to plan, by the end of 2008 we’ll see a mobile platform large enough to make it a worthwhile target for malware and cyber criminals. And don’t think that this won’t happen. A platform of 10 million users, all of whom will have spent $600 on a cellphone is a group well worth targeting.

Now Apple’s counter to this is to put restrictions on the running of third-party code on the iPhone. A few weeks ago at D 2007 Steve Jobs told Walt Mossberg the reason why Apple placed restrictions on the iPhone’s capability to run third-party code:

This is an important tradeoff between security and openness. We want both. We’re working through a way… we’ll find a way to let 3rd parties write apps and still preserve security on the iPhone. But until we find that way we can’t compromise the security of the phone.

I’ve used 3rd party apps… the more you add, the more your phone crashes. No one’s perfect, and we’d sure like our phone not to crash once a day. If you can just be a little more patient with us I think everyone can get what they want.

Personal note: The part where Jobs says “I’ve used 3rd party apps… the more you add, the more your phone crashes” strikes me as peculiar. What third party apps? The iPhone’s not even out yet but Jobs is blaming crashes on random applications. That statement more than any other gives me the impression that the cut-down version of OS X on the iPhone might be too cut down to run much beyond what is already bundled – and more than likely that been tweaked with so it will run on the iPhone.

Now while this might be ample security to prevent people with nothing better to do from tinkering with the iPhone and running their own code (and possibly causing the iPhone to crash, something that Steve Jobs is keen to avoid, and more seriously, causing disruption to the cellphone network), it’s going to have to be watertight if it’s going to keep hackers out. You can expect that hackers will be looking closely for any weakness and will hammer relentlessly at any that are discovered. Just because Apple has had a good security track record with OS X doesn’t guarantee that the iPhone will be as lucky (OS X doesn’t dominate any market it’s in, but the iPhone might, and that will be the key difference when it comes to malware). In fact, given that they’re rushing iPhone out of the doors at Cupertino, the chances of coding blunders are high. It’s certainly not a platform I’d like to integrate into a corporate or other critical environment until many of the bugs, especially security bugs, have been shaken out.

So, those who buy into the iPhone phenomenon could find themselves having bought into a platform that gives them more than they’d bargained for. Malware, security vulnerabilities and patches could become a way of life for the iPhone early adopter. Personally, I’m happier using a cellphone that isn’t part of such a big ecosystem. I feel safer that way.

Thoughts?

Adrian Kingsley-HughesAdrian is a technology journalist and author who has devoted over a decade to helping users get the most from technology. He also runs a popular blog called The PC Doctor. See his full profile and disclosure of his industry affiliations

Want to get in touch? Got a tip? Feel free to drop me a note! I ALWAYS respect anonymity. I'm also on Twitter (@the_pc_doc)

Right to Reply: Should any industry representatives wish to comment on any posts on Hardware 2.0, I will be happy to publish their reply verbatim on this blog.

Subscribe to Hardware 2.0 via Email alerts or RSS.

  • Talkback
  • Most Recent of 61 Talkback(s)
Painting the Devil on the wall.
the description of Apple's AJAX-based iPhone API in the keynote seems
dangerously similar to the kind of web-desktop integration that Windows suffers
from. I hope I misunderstood... if not,
... (Read the rest)
Posted by: Mikael_z Posted on: 06/17/07 You are currently: a Guest | | Terms of Use
I?m happier using a cellphone that isn?t part of such a big ecosystem.  mrlinux | 06/11/07
You know what they say about ASSumptions...  BitTwiddler | 06/11/07
Sigh  tic swayback | 06/11/07
If anything  Michael Kelly | 06/11/07
If you can just be a little more patient  Michael Kelly | 06/11/07
What problem?  BitTwiddler | 06/11/07
Are you suggesting  Michael Kelly | 06/11/07
That Jobs may have been referring to other phones?  Spoon Jabber | 06/11/07
What problem?  nomorems | 06/11/07
Solve the problem first....?  Spoon Jabber | 06/11/07
Talk about a fud campaign?  dave95. | 06/11/07
Agreed!  HouseOfZen | 06/11/07
What third party apps?  tic swayback | 06/11/07
What a crapy statement  Hakime | 06/11/07
I think Steve's referring to current cell phones, not the iPhone.  ye | 06/11/07
Something else to think about  tic swayback | 06/11/07
Is 10 Million enough  voska | 06/11/07
Nokia alone sold 92 Million in JUST the 1st quarter of 07  j.m.galvin | 06/11/07
re: Nokia alone sold 92 Million in JUST the 1st quarter of 07  M.R. Kennedy | 06/11/07
Nokia sold 645 Million phones...  msalzberg | 06/11/07
That's it brave knights, defend the King!!!!  James T. Kirk | 06/11/07
Huh?  msalzberg | 06/11/07
No... ZDNet's pathetic lack of a PREVIEW POST feature strikes yet again  James T. Kirk | 06/11/07
Ah. Well, considering the quality of much...  msalzberg | 06/11/07
Chimps are cheap  macbill | 06/11/07
Stop insulting chimps!  Spoon Jabber | 06/11/07
re: Huh?  M.R. Kennedy | 06/11/07
It's going to be juicy because it's an.....  jsargent | 06/12/07
Ho hum  betelgeuse68 | 06/11/07
OS X  systemx | 06/11/07
A complete waste of space.  heres_johnny | 06/11/07
Adrian Kingsley-Hughes = Microsoft Shill  nomorems | 06/11/07
Sorry - NonZealot to strike !  Jim888 | 06/11/07
Market share myth  Resuna | 06/11/07
Market Share does play a part,  Narg | 06/11/07
So, about all of those iTunes viruses?  Spoon Jabber | 06/11/07
You missed the point. BUT!  Resuna | 06/11/07
That's not what changed  notsofast | 06/11/07
That is precisely what changed. BUT...  Resuna | 06/11/07
Painting the Devil on the wall.  Mikael_z | 06/17/07
Do you know enough about the iPhone to write this article?  jpate86 | 06/11/07
The article jumps to unsupported conclusions  filker0 | 06/11/07
Well one thing is for certain the iPhone software...  mrlinux | 06/11/07
Wow, I think I'm scared enough not to get one now, NOT!!  Kid Icarus-21097050858087920245213802267493 | 06/11/07
The part where Jobs says ?I?ve used 3rd party apps? "  nix_hed | 06/11/07
Adrian you should be speaking of all the malware that has attacked  Intellihence | 06/11/07
It would be impossible  NonZealot | 06/11/07
Secret APIs?  cmjrees | 06/11/07
yeah 3rd party apps suck!  panic man | 06/11/07
3G chips in court. iPhone benefits..?  Jim888 | 06/11/07
Another homerun!  NonZealot | 06/11/07
LOL  TripleII | 06/11/07
What do you expect?  Spoon Jabber | 06/11/07
Alert moderator to offensive message  Spoon Jabber | 06/11/07
Malware responsibility  Doug Flint | 06/11/07
10m phones overly optimistic.  kraterz | 06/11/07
Don't shoot the piano player  j.vankerkhove@... | 06/11/07
You could do worse than listen to this podcast  ConfusedOne | 06/12/07
this is a silly argument  pnjunk@... | 06/12/07
Nothing short of slander  s_gamgee | 06/12/07
FUD - an old game in town again  ivan_valkov@... | 06/13/07

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

Click Here
advertisement

Recent Entries

advertisement
Click Here

Archives

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here