CIO Today

CIO Today Network Sites:   Top Tech News  |   CIO Today   |   Mobile Tech Today   |   Data Storage Today
Daily Briefing for Technology's Top Decision-Makers
Vblock™ Systems:
Advanced converged infrastructure
increases productivity & lowers costs.

www.vce.com
Wednesday, April 16th 
24/7/365 Network Uptime!
This ad will display for the next 20 seconds. Please click for more information, or scroll down to pass the ad, or Close Ad.
Trending Topics:   Security Heartbleed Big Data Cloud Computing Windows XP Data Centers OS X Mavericks
Home
Enterprise Software
Enterprise Hardware
Big Data
Network Security
Cloud Computing
CRM Systems
Data Storage
Operating Systems
Communications
CIO Issues
Mobile Tech
Chips & Processors
World Wide Web
Business Briefing
After Hours
Press Releases
 
Free Newsletters
Top CIO News
 
Mobile Tech Today
 

Wireless Security

Samsung Galaxy S4 Vulnerable to Malware

Samsung Galaxy S4 Vulnerable to Malware
December 26, 2013 12:57PM

Bookmark and Share
A Ph.D student in Israel says adding an innocuous app to the non-secure area of Samsung's Knox architecture can lead to malware compromising the secure area due to the security breach. Samsung's Knox is a state-of-the-art, secure mobile architecture, so the student was surprised to find that such a big "hole" exists and was left untouched.

APC has an established a reputation for solid products that virtually pay for themselves upon installation. Who has time to spend worrying about system downtime? APC makes it easy for you to focus on business growth instead of business downtime with reliable data center systems and IT solutions. Learn more here.

Adding apps to Samsung's Knox architecture for its Galaxy S4 might create a vulnerability that could allow e-mails, data transfers and browser histories to be accessed by third parties, says a research team at a prominent Israeli scientific university.

The supposed flaw could even allow hackers to manipulate data believed to be secure, a potential setback to the global smartphone king's efforts to have its Android-based devices adopted by employees of the U.S. Department of Defense, which has given preliminary approval for them.

Was Software Up To Date?

Samsung did not respond to our request for comment in time for publication but told The Wall Street Journal for its report on the flaw Monday that it is investigating the matter.

Samsung "takes all security vulnerability claims very seriously" a spokesman told the paper, while stressing that a preliminary investigation showed that "the threat appears to be equivalent to some well-known attacks."

The team at Ben Gurion University (BGU) of the Negev appears to have conducted the test on a device that was not running the complete software that would have been used by corporate clients, Samsung said.

"Rest assured, the core Knox architecture cannot be compromised or infiltrated by such malware," the spokesman said.

Discussing the finding on BGU's Web site, the researchers said a Ph.D. student, Mordechai Guri, stumbled onto the vulnerability during an unrelated project he is working on with a research team at the cyber security labs of the Homeland Security Institute at the campus, located in Beer-Sheva.

“To us, Knox symbolizes state-of-the-art in terms of secure mobile architectures and I was surprised to find that such a big ’hole‘ exists and was left untouched," Guri said in a statement.

"The Knox has been widely adopted by many organizations and government agencies and this weakness has to be addressed immediately before it falls into the wrong hands," he added.

Full details were provided to the South Korea-based electronics giant, BGU said.

Knox, whose name is meant to invoke the heavily fortified Kentucky Army base that contains much of the U.S. gold reserve, consists of a secure "container" within the regular phone environment with better security protection. BGU claims that adding a seemingly innocuous app to the non-secure area can lead to malware compromising the secure area due to the security breach.

Cause For Concern

"Users should be concerned about this apparant security flaw," said technology analyst Jeff Kagan. "However it is important for every user to understand that security flaws show up all the time in [devices] by various manufacturers."

Tell Us What You Think
Comment:

Name:



 Wireless Security
1. NSC Backs Disclosing Vulnerabilities
2. How, Why Heartbleed Got Its Name
3. Is Heartbleed the Biggest Threat Ever?
4. States Probing Massive Data Breach
5. Google Expands Virus Scans to All Apps




 Most Popular Articles
1. BlackBerry Drops T-Mobile After Nasty Spat
2. Will Satya Nadella Launch an Office for iPad?
3. Google Unveils Android Wear for Smart Watches
4. Cisco, IBM Launch Internet of Things Consortium
5. IBM Applies Big Data Analytics To Fight Against Fraud


Have an informed opinion on this story?
Send a Letter to the Editor.
We want to know what you think.
Send us your Feedback.

 Related Topics  Latest News & Special Reports

  Zebra Buys Motorola Enterprise Biz
  How To Beat the Heartbleed Bug
  Google's Modular Phone Set for January
  CTIA Caves, Offers Kill Switch Plan
  OpenSSL Calls for More Support

 Technology Marketplace

Business Intelligence
Get real-time, cloud-based information services with Neustar.
 
Cloud Computing
BMC's I.T. solutions unleash the power of your business
Next Generation Data Center Is Here! Vblock™ Systems from VCE
 
Contact Centers
HP delivers the future of the contact center with HP Qfiniti 10.
 
Data Storage
Next Generation Data Center Is Here! Vblock™ Systems from VCE
2.5" Enterprise-class SATA & SAS SSDs for server & storage applications
Barium Ferrite (BaFe) is the future of tape.
 
Enterprise Hardware
2.5" Enterprise-class SATA & SAS SSDs for server & storage applications
Barium Ferrite (BaFe) is the future of tape.
 
Enterprise I.T.
BMC's I.T. solutions unleash the power of your business
 
Hardware
Protect your network with APC Smart-UPS battery backup
 
Network Security
Protect your network with APC Smart-UPS battery backup
 

Network Security Spotlight
How To Beat the Heartbleed Bug
Heartbleed headlines continue as IT admins scramble for answers no one has. Early reports of stolen personal data, including 900 social insurance numbers in Canada, are starting to trickle in.
 
After Heartbleed, OpenSSL Calls for More Support
The president of the OpenSSL Foundation says more support is needed from companies and governments that use its software so that it can better spot and fix flawed pieces of code such as Heartbleed.
 
NSC Backs Disclosing Software Vulnerabilities
Disclosing vulnerabilities in commercial and open source software is in the national interest and shouldn't be withheld unless there is a clear need, says the National Security Council.
 

Enterprise Hardware Spotlight
Vaio Fit 11A Battery Danger Forces Recall by Sony
Using a Sony Vaio Fit 11A laptop? It's time to send it back to Sony. In fact, Sony is encouraging people to stop using the laptop after several reports of its Panasonic battery overheating.
 
Continued Drop in Global PC Shipments Slows
Worldwide shipments of PCs fell during the first three months of the year, but the global slump in PC demand may be easing, with a considerable slowdown from last year's drops.
 
Google Glass Finds a Home in Medical Education, Practice
Google Glass may find its first markets in verticals in which hands-free access to data is a boon. Medicine is among the most prominent of those, as seen in a number of Glass experiments under way.
 

Mobile Technology Spotlight
Zebra Tech Buys Motorola Enterprise for $3.45B
Weeks after Lenovo bought Motorola Mobility’s assets from Google for $2.91 million, Zebra Technologies is throwing down $3.45 billion for Motorola’s Enterprise business in an all-cash deal.
 
CTIA Caves, Volunteers Kill Switch Plan
After bucking against the concept of a smartphone kill switch, the CTIA just announced the “Smartphone Anti-Theft Voluntary Commitment” to thwart smartphone thefts in the U.S.
 
Is Amazon Launching a 3D Smartphone?
Once known for selling books on an e-commerce platform, Amazon is now a bona fide hardware maker -- and it's reportedly rolling out an innovative smartphone with a 3D screen.
 

Navigation
CIO Today
Home/Top News | Enterprise Software | Enterprise Hardware | Big Data | Network Security | Cloud Computing | CRM Systems
Data Storage | Operating Systems | Communications | CIO Issues | Mobile Tech | Chips & Processors | World Wide Web
Business Briefing | After Hours | Press Releases
Also visit these Enterprise Technology Sites
Top Tech News | CIO Today | Mobile Tech Today | Data Storage Today

Services:
FreeNewsFeed | Free Newsletters | XML/RSS Feed

About CIO Today Network | How To Contact Us | Article Reprints | Services for PR Pros (In partnership with NewsFactor) | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2014 CIO Today. All rights reserved. Article rating technology by Blogowogo. Member of Accuserve Ad Network.