Business Wire
Welcome
  • Log In
  • Sign Up
Search News:
Help
http://www.veracode.com
March 10, 2010 08:30 AM Eastern Time 

Veracode Responds to Cell Phone Stalker Story: The Threat Isn’t Just Who You Know

Greater Risks Exist With Seemingly Innocent Mobile Downloads; Applications Must Be Held to Higher Standards to Ensure What Happened on the PC Does Not Happen on Cell Phones

BURLINGTON, Mass.--(BUSINESS WIRE)--With the recent headline-grabbing story about a stalker who hijacked his ex-girlfriend’s cell phone for three years (story), Veracode’s CTO Chris Wysopal warns that greater threats are lurking beyond spyware intentionally installed by someone you know. According to Wysopal, “the more insidious story is that a user could easily download an application innocently - a game, a social media app, or a banking or shopping app - that subsequently installs similar spyware.”

“The industry should use examples like these to hold application providers’ feet to the fire so we don’t allow what’s happened to the PC to happen on cell phones”

This “innocent” downloading is exactly why application providers and app stores need to provide independent proof that their software doesn’t behave inappropriately or have vulnerabilities that can be exploited by malware. Unfortunately, many consumers have a false sense of security, assuming that everything in official app stores must be trustworthy. That simply isn’t the case.

The Veracode team has witnessed first-hand how an application developer, with just a few days of work, can incorporate spyware behavior in a legitimate application. With this most recent cell phone stalker story coming on the heels of concerns associated with apps like Storm8, 09Droid and Symbian Sexy Space, we are only at the tip of the iceberg. “The industry should use examples like these to hold application providers’ feet to the fire so we don’t allow what’s happened to the PC to happen on cell phones,” continued Wysopal.

To gain a better understanding of the reality of these threats, Tyler Shields, a senior security researcher with Veracode, recently gave a presentation at ShmooCon 2010 to raise awareness about the threats of mobile spyware, particularly as it relates to data privacy. One of the goals was to demonstrate how mobile applications can access and leak sensitive information, using only the provider’s APIs and no trickery or exploits of any sort. View the presentation on Veracode’s blog here: http://www.veracode.com/blog/2010/02/is-your-blackberry-app-spying-on-you/.

If you are interested in speaking with Chris Wysopal about emerging mobile application threats, and what users and corporations can do to protect themselves, please contact Liz Campbell at veracode@famapr.com or +1 617-758-4149.

About Veracode

Veracode is the world’s leader in cloud-based application risk management. With patented binary code analysis, dynamic web assessments, and partner or Veracode delivered manual penetration testing, combined with developer e-learning and access to open source security ratings, Veracode SecurityReview allows you to independently verify application security in both internally developed applications and third-party software without requiring source code or expensive tools. Veracode provides the simplest, most complete, and most accurate way to implement security best practices, reduce operational cost and comply with internal security policies or external standards such as OWASP Top 10, CWE/SANS Top 25 and PCI. Recognized as a Gartner “Cool Vendor,” The Wall Street Journal’s “Technology Innovation Award,” The Banker’s “Information Security Project of the Year” with Barclays, SC Magazine’s “Best Vulnerability Assessment Solution,” Information Security “Readers’ Choice Award,” and AlwaysOn Northeast’s “Top 100 Private Company,” Veracode is Software Security Simplified™. For more information, visit www.veracode.com.

Contacts

fama PR
Liz Campbell, +1 617-758-4149
veracode@famapr.com

Recent Stories from Veracode

  • Veracode and Security Innovations to Lead Webinar on Building an Application Security Training Program for Software Developers
    February 09, 2012
    BURLINGTON, Mass.--(BUSINESS WIRE)--Veracode, Inc., the leader in cloud-based application security testing, today announced details of an upcoming webinar, “How to Build an Application Security Tra... more »
  • Veracode and Security Innovations to Lead Webinar on Building an Application Security Training Program for Software Developers
    February 07, 2012
    BURLINGTON, Mass.--(BUSINESS WIRE)--Veracode, Inc., the leader in cloud-based application security testing, today announced details of an upcoming webinar, “How to Build an Application Security Tra... more »
  • View Press Release
    Veracode Licenses Security Innovation’s eLearning Suite to Deliver Full-Spectrum Application Security and Security Education
    February 07, 2012
    WILMINGTON, Mass. & BURLINGTON, Mass.--(BUSINESS WIRE)--Veracode, Inc. and Security Innovation today jointly announced a partnership to license the Security Innovation eLearning suite to Veracode t... more »
More Stories
RSS feed for Veracode
http://www.veracode.com

Release Versions

  • EON: Enhanced Online News

Company Information Center

Veracode RSS feed for Veracode

Share

  • Facebook
  • Twitter
  • LinkedIn
  • Delicious
  • Reddit
  • StumbleUpon
  • Digg
  • MySpace
  • Newsvine
  • Google Bookmark
  • Yahoo! Bookmark
  • EmailEmail
Tweet
  • EmailEmail
All News
Business Wire
  • Home
    • Home
    • Membership Benefits
    • Submit a Press Release
  • News
    • All News
    • News with Multimedia
    • News by Industry
    • News by Subject
    • News by Language
    • RSS Feeds
    • Business Wire Mobile
    • Features
    • Company NewsCenters
    • Smart Marketing Pages
    • Company Profiles
    • Annual Reports
  • Events
    • Trade Shows & Events
    • Earnings & Conference Calls
    • Business Wire Events
  • PR Services
    • Press Release Distribution
    • Distribution Lists
    • Industry Targeting
    • LatinoWire & Ethnic Media
    • Public Policy Wire
    • Trade Show Services
    • Photos & Multimedia Marketing
    • GloMoSoMe
    • Press Release Measurement
    • Mobile Alerts
    • Clips & Research
    • Fax & Email Services
    • Online Newsrooms
    • News Feeds
  • IR Services
    • Material News Disclosure
    • XBRL
    • EDGAR (US)
    • IPO Services
    • SEDAR (Canada)
    • European Disclosure
    • Corporate Social Responsibility (CSR)
    • Investor Targeting
    • Fax & Email Services
    • Online Investor Centers
    • IR Resource Center
  • SEO Services
    • Press Release Optimization
    • EON: Enhanced Online News
    • Webinars & Resources
  • Journalist Tools
    • PressPass: Your News
    • Conduct Surveys
    • Business Wire News Feeds
    • Business Wire News On Your Website
    • Journalism Associations
  • Support & Education
    • FAQ
    • How to Write a Press Release
    • How To Optimize a Press Release for Search
    • How to Distribute a Press Release
    • Find Your News Online
    • Sample Press Release
    • Features News Tips
    • International Media Tips
    • SEC Regulations
    • Exchange Guidelines
    • White Papers
    • Webinars & Podcasts
    • Get WiredIn!
  • About Us
    • Business Wire Newsroom
    • Contact Us
    • History
    • Jobs
  • About Us
  • Contact Us
  • Site Map
  • Privacy Statement
  • Terms of Use
  • ©2012 Business Wire

More Business Wire sites

  • Canada
  • UK/Ireland
  • Deutschland
  • France
  • Italy
  • Japan
  • EON: Enhanced Online News
  • Tradeshownews.com
  • PYMNTS.com

About Us

  • Business Wire Newsroom
  • Contact Us
  • Business Wired blog

News on BusinessWire.com

  • All News
  • RSS Feeds
  • Business Wire Mobile Apps

Follow Us on Twitter

  • @BusinessWire
  • @BWSportsWire
  • @BWPolitics
  • @BWCSRNews
  • @EONpr
  • @TradeshowNews
  • @BW_Canada
  • @BWIntlMedia
  • @BWInfoDiva
  • @BusinessWireFR

Like Us on Facebook

  • Business Wire
  • Tradeshow News