[Warning] App spy on bank accounts

There was one for USAA, too. They sent out a warning to their members and got the app removed from the library.

Bad ju-ju!
 
Wachovia's website actually sent me to the apps market to download their software.

Danny

On Android? Really? I didn't think Wachovia was using an app, just a mobile web page. Can yopu point me yo where you found that?

JJ
 
I am so surprised at the amount of folks that say they don't bank online (even a bank employee lol), I mean really do you all think the banks move your money around via Pony Express! There are many bank that offer mobile banking, and here's something to consider the same encryption they use to move your money around you have that as well when you log onto their sites.

Here's another freebie - the next time you're ready to make any transactions online just take a look at the "address bar" if the site is requesting and financial info and their address starts off with "http://" DON'T PUT YOUR BANKING INFO ON THAT PAGE AT ALL. However, should the address starts with "https://" THEN THAT IS A SECURE SITE, THE SAME ENCRYPTION USED BY BANKS TO MOVE YOUR MONEY AROUND.

HTTP:// No banking information

HTTPS:// It's all Good!

And as for "Pageonce" Their reputation speaks for itself...
 
yep

1% of apps in market place downloaded contain spyware! that is according to a report filed to google to the FCC. While 1% may seem like a rather small number given the vast quantity of apps in their store, it's a big deal. Two of the apps removed were capable, and in a few cases, successful at gaining access to personal banking information and routing numbers.
 
I have to say that I'm a little disappointed that Google disentangle offer a section of the market that has Alps that have been reviewed by Google.
 
sorry, noob questions here....
How do I check to see if any of my apps are from the "DROID09" person...
and would an antivirus (that I had and uninstalled) have detected such spying at all??
thanks guys....

Rudimentary anti-virus and anti-spyware apps (read all mobile AV apps) use signature based detection. They scan the binary file for a piece of code that is known to be part of the virus/spyware, so the malicious code has to be known first. After you see a few variants of the same app, then you can go to the next level called heuristics ... which attempts to detect new versions by knowing how previous versions worked. Heuristic analysis slows down scanning and would be a huge drain on batteries. That having been said, the app that I use (Lookout) has actually posted information on their blog about this particular group of applications.

The Official Lookout Blog

They claim that this developer didn't actually steal any information in the versions that they tested and that the reason these apps were removed is that they were not authorized to use the bank logos or names.

This highlights the problem with detecting any type of malware. You have to see it before you can block it, which means there is likely to be a group that gets infected.

As far as AV apps go, I decided to go with Lookout because of the backup and missing device locate functionality. The AV was just a nice bonus and the app was free.
 
Whoo pageonce Personal Assistant is safe! Phew...I love this app too. Although I must say I was VERY iffy about putting my bank info on one app but it seems rather safe, specially since I don't keep the passwords stored on my phone anymore.
 
Little Paranoid Now

From BofA website:

"Android:

Click on the Market icon on your device to access the Android Market
Search for "Bank of America"
Click Install"


PayPal emailed a security alert this morning, and sure enough there was a unauthorized transaction. Got a spoofing email a few weeks back, didn't click it and notified PayPal. It's just curious. It's to PP's credit that they caught this before I did, but I'm still thinking about closing the account. I've downloaded the BofA market app but am having second thoughts about activating it. Sure would be handy on vacation. Anyone having any problems with this app?
 
Back
Top