<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: ZeuS Trojan for Google Android Spotted</title>
	<atom:link href="http://krebsonsecurity.com/2011/07/zeus-trojan-for-google-android-spotted/feed/" rel="self" type="application/rss+xml" />
	<link>http://krebsonsecurity.com/2011/07/zeus-trojan-for-google-android-spotted/</link>
	<description>In-depth security news and investigation</description>
	<lastBuildDate>Wed, 19 Jun 2013 20:40:46 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
	<item>
		<title>By: Dohn Joe</title>
		<link>http://krebsonsecurity.com/2011/07/zeus-trojan-for-google-android-spotted/comment-page-1/#comment-25120</link>
		<dc:creator>Dohn Joe</dc:creator>
		<pubDate>Mon, 15 Aug 2011 05:41:02 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=10651#comment-25120</guid>
		<description><![CDATA[A list of all infected official marketplace apps is here:  http://insan-it.blogspot.com/2011/08/android-security-year-in-review.html]]></description>
		<content:encoded><![CDATA[<p>A list of all infected official marketplace apps is here:  <a href="http://insan-it.blogspot.com/2011/08/android-security-year-in-review.html" rel="nofollow">http://insan-it.blogspot.com/2011/08/android-security-year-in-review.html</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jane</title>
		<link>http://krebsonsecurity.com/2011/07/zeus-trojan-for-google-android-spotted/comment-page-1/#comment-24117</link>
		<dc:creator>Jane</dc:creator>
		<pubDate>Wed, 13 Jul 2011 13:52:26 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=10651#comment-24117</guid>
		<description><![CDATA[Not just eBay.  Maybe you remember the scare a couple years ago with electronic picture frames coming from *the factory* with viruses.  

It&#039;s &quot;in the news&quot; again.  I&#039;ve never tried posting a link here before, but here goes nothing:  

Homeland Security: Devices, Components Coming In With Malware (informationweek)
http://www.informationweek.com/news/government/security/231001333

DHS: Imported Gadgets Possibly Include Malicious Software (pcmag)
http://www.pcmag.com/article2/0,2817,2388361,00.asp
(I take exception with this one in the very first paragraph.  &quot;A Homeland Security official confirmed ... popular American gadgets, are often infected with malicious software.&quot; -- not supported by the quote a few lines later.)]]></description>
		<content:encoded><![CDATA[<p>Not just eBay.  Maybe you remember the scare a couple years ago with electronic picture frames coming from *the factory* with viruses.  </p>
<p>It&#8217;s &#8220;in the news&#8221; again.  I&#8217;ve never tried posting a link here before, but here goes nothing:  </p>
<p>Homeland Security: Devices, Components Coming In With Malware (informationweek)<br />
<a href="http://www.informationweek.com/news/government/security/231001333" rel="nofollow">http://www.informationweek.com/news/government/security/231001333</a></p>
<p>DHS: Imported Gadgets Possibly Include Malicious Software (pcmag)<br />
<a href="http://www.pcmag.com/article2/0,2817,2388361,00.asp" rel="nofollow">http://www.pcmag.com/article2/0,2817,2388361,00.asp</a><br />
(I take exception with this one in the very first paragraph.  &#8220;A Homeland Security official confirmed &#8230; popular American gadgets, are often infected with malicious software.&#8221; &#8212; not supported by the quote a few lines later.)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rod</title>
		<link>http://krebsonsecurity.com/2011/07/zeus-trojan-for-google-android-spotted/comment-page-1/#comment-24113</link>
		<dc:creator>Rod</dc:creator>
		<pubDate>Wed, 13 Jul 2011 11:57:13 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=10651#comment-24113</guid>
		<description><![CDATA[I have news for ya: infected android and iphones are already sold on ebay with the virus PRE INSTALLED!]]></description>
		<content:encoded><![CDATA[<p>I have news for ya: infected android and iphones are already sold on ebay with the virus PRE INSTALLED!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Louis Leahy</title>
		<link>http://krebsonsecurity.com/2011/07/zeus-trojan-for-google-android-spotted/comment-page-1/#comment-24089</link>
		<dc:creator>Louis Leahy</dc:creator>
		<pubDate>Tue, 12 Jul 2011 21:40:08 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=10651#comment-24089</guid>
		<description><![CDATA[Another issue with your comments is that you appear to fail to understand the meaning of proprietary. In fact contrary to your assertion the majority of attacks occur on interfaces that use either ascii or unicode number sets which are in the public domain and the main source of the problems.]]></description>
		<content:encoded><![CDATA[<p>Another issue with your comments is that you appear to fail to understand the meaning of proprietary. In fact contrary to your assertion the majority of attacks occur on interfaces that use either ascii or unicode number sets which are in the public domain and the main source of the problems.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Louis Leahy</title>
		<link>http://krebsonsecurity.com/2011/07/zeus-trojan-for-google-android-spotted/comment-page-1/#comment-24088</link>
		<dc:creator>Louis Leahy</dc:creator>
		<pubDate>Tue, 12 Jul 2011 21:21:18 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=10651#comment-24088</guid>
		<description><![CDATA[Well I didn&#039;t say completely I said largely I have read a lot of media commentary globally and this has not been reported elsewhere in the mainstream media but in any case I wonder what your motive is in attacking someone who is actually endeavouring to do something about the problems good luck with that attitude I am sure you are really proud of your efforts.]]></description>
		<content:encoded><![CDATA[<p>Well I didn&#8217;t say completely I said largely I have read a lot of media commentary globally and this has not been reported elsewhere in the mainstream media but in any case I wonder what your motive is in attacking someone who is actually endeavouring to do something about the problems good luck with that attitude I am sure you are really proud of your efforts.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Neej</title>
		<link>http://krebsonsecurity.com/2011/07/zeus-trojan-for-google-android-spotted/comment-page-1/#comment-24072</link>
		<dc:creator>Neej</dc:creator>
		<pubDate>Tue, 12 Jul 2011 17:40:26 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=10651#comment-24072</guid>
		<description><![CDATA[&quot;...Krebs seems to be largely alone in highlighting these problems and we find that particularly frustrating given the gravity of these issues ....&quot;

Seriously?  Maybe you only read this blog but even then I just counted 4 different websites linked in this post to people other than Brian that are &quot;highlighting these problems&quot;.

And sorry to inform you of this (well, not really actually as you seem a little ... amatuerish) but most interfaces where attacks on virtual keyboards have been proprietary in nature.  Perhaps this is why Trusteer just ignores you, who knows.]]></description>
		<content:encoded><![CDATA[<p>&#8220;&#8230;Krebs seems to be largely alone in highlighting these problems and we find that particularly frustrating given the gravity of these issues &#8230;.&#8221;</p>
<p>Seriously?  Maybe you only read this blog but even then I just counted 4 different websites linked in this post to people other than Brian that are &#8220;highlighting these problems&#8221;.</p>
<p>And sorry to inform you of this (well, not really actually as you seem a little &#8230; amatuerish) but most interfaces where attacks on virtual keyboards have been proprietary in nature.  Perhaps this is why Trusteer just ignores you, who knows.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: sunhaq</title>
		<link>http://krebsonsecurity.com/2011/07/zeus-trojan-for-google-android-spotted/comment-page-1/#comment-24070</link>
		<dc:creator>sunhaq</dc:creator>
		<pubDate>Tue, 12 Jul 2011 16:12:28 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=10651#comment-24070</guid>
		<description><![CDATA[You missed the many security problems with the iPhone/iPad banking apps I guess.]]></description>
		<content:encoded><![CDATA[<p>You missed the many security problems with the iPhone/iPad banking apps I guess.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Louis Leahy</title>
		<link>http://krebsonsecurity.com/2011/07/zeus-trojan-for-google-android-spotted/comment-page-1/#comment-24065</link>
		<dc:creator>Louis Leahy</dc:creator>
		<pubDate>Tue, 12 Jul 2011 13:04:06 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=10651#comment-24065</guid>
		<description><![CDATA[Again Krebs seems to be largely alone in highlighting these problems and we find that particularly frustrating given the gravity of these issues. We wrote to Trusteer on multiple occasions in the last 2 years offering our solution to fix their interface however our communications have been ignored. We think Trusteers’ and other vendors systems that use these mechanisms can work if they implement proper authentication. We note Krebs arguments in previous articles against Virtual Keyboards however it is possible to defend against screen capture by disabling onscreen feed back our interface is designed to allow this to be done. We have released a demo on our site for the windows 7 phone which we have just completed. The key issue is that interfaces need to be proprietary in nature to render the costs of attacking far higher than they now are and the important issue with that is to automate the process of making the interface proprietary so that the costs of implementation are kept to a minimum.]]></description>
		<content:encoded><![CDATA[<p>Again Krebs seems to be largely alone in highlighting these problems and we find that particularly frustrating given the gravity of these issues. We wrote to Trusteer on multiple occasions in the last 2 years offering our solution to fix their interface however our communications have been ignored. We think Trusteers’ and other vendors systems that use these mechanisms can work if they implement proper authentication. We note Krebs arguments in previous articles against Virtual Keyboards however it is possible to defend against screen capture by disabling onscreen feed back our interface is designed to allow this to be done. We have released a demo on our site for the windows 7 phone which we have just completed. The key issue is that interfaces need to be proprietary in nature to render the costs of attacking far higher than they now are and the important issue with that is to automate the process of making the interface proprietary so that the costs of implementation are kept to a minimum.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Christian</title>
		<link>http://krebsonsecurity.com/2011/07/zeus-trojan-for-google-android-spotted/comment-page-1/#comment-24062</link>
		<dc:creator>Christian</dc:creator>
		<pubDate>Tue, 12 Jul 2011 12:39:32 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=10651#comment-24062</guid>
		<description><![CDATA[We&#039;re disabling all this &quot;premium services&quot; by default for our company mobiles.

Are there any serious companys using this stuff for billing?
Im not aware of any.


greetings]]></description>
		<content:encoded><![CDATA[<p>We&#8217;re disabling all this &#8220;premium services&#8221; by default for our company mobiles.</p>
<p>Are there any serious companys using this stuff for billing?<br />
Im not aware of any.</p>
<p>greetings</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: xyz</title>
		<link>http://krebsonsecurity.com/2011/07/zeus-trojan-for-google-android-spotted/comment-page-1/#comment-24060</link>
		<dc:creator>xyz</dc:creator>
		<pubDate>Tue, 12 Jul 2011 12:32:38 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=10651#comment-24060</guid>
		<description><![CDATA[@Michse Selba - &quot;this malware tries to catch THESE SMS codes on your phone&quot;

If the malware can do this, it can do anything else. 

Regardless, what is the fundamental difference now between a phone and a PC that can prevent the same well known triks in PC world on a smartphone?]]></description>
		<content:encoded><![CDATA[<p>@Michse Selba &#8211; &#8220;this malware tries to catch THESE SMS codes on your phone&#8221;</p>
<p>If the malware can do this, it can do anything else. </p>
<p>Regardless, what is the fundamental difference now between a phone and a PC that can prevent the same well known triks in PC world on a smartphone?</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using memcached (User agent is rejected)
Database Caching 5/19 queries in 0.004 seconds using memcached
Object Caching 377/387 objects using memcached

 Served from: krebsonsecurity.com @ 2013-06-19 16:43:39 by W3 Total Cache -->