Russian security vendor Kaspersky Lab last week began sounding the alarm about an overseas mobile-phone scam that smacks of the movie “Office Space” and may portend future dangers for global users.
Russian security vendor Kaspersky Lab this week began sounding the alarm about an overseas mobile-phone scam that smacks of the movie “Office Space” and may portend future dangers for global users.
It may also add grist to what has become an ongoing debate here, namely: What is the risk/reward ratio as mobile phones come to handle more and increasingly sophisticated financial transactions?According to Kaspersky, a new malicious program for Symbian and written in Python has been foisted upon customers of an Indonesian carrier. The Trojan sends SMS messages that prompt the transfer of small amounts — 45 cents to 90 cents — from the infected user’s account to that of the criminal. Small change, yes, but if the scam scales, the “result could be quite substantial,” Kaspersky notes.
The modest takes are no accident. The theory, as put forth in everybody’s favorite movie about sticking it to your employer, is that a whole bunch of missing change is less likely to be noticed than the loss of larger sums. The malware writers in this case were also helped by the carrier’s desire to provide a simple method of transferring funds to a customer base that depends upon that feature, as is the case in less affluent nations. “This is useful when you need to communicate with someone who does not have enough money in their account,” the Kaspersky analysts explain.
Simple, convenient . . . and apparently vulnerable.
Might the risk of such scams jump an ocean and land here in the States?
“It seems that the focus on financial fraud in the mobile malware industry will only get more pronounced over time,” says Denis Maslennikov, a senior malware analyst at Kaspersky Lab. “Until recently, many people thought that malicious programs that send SMS messages without the user’s knowledge were a purely Russian phenomenon. Now we can see that the problem no longer affects only Russian users — it’s becoming an international issue.”
Of course, it’s always worth noting that security vendors such as Kaspersky make their livings off of such worries, and, in some cases, stoking such worries. . . . But does anyone want to argue that he’s wrong.
Court rules Kentucky does not own the Internet
No, the government of Kentucky cannot seize the domain names of offshore Internet gambling operations just because the governor disapproves of wagering and believes himself ruler of the free world.
In a 2-1 decision that can only be described as the grownups regaining control, the Kentucky Court of Appeals last week overruled a lower court decision that allowed Gov. Steve Beshear’s Keystone Cops to confiscate 141 domain names last fall.
Faced with any number of grounds on which to toss this turkey, the appeals court chose to hang its decision on an interpretation of Kentucky’s “gambling device” forfeiture statute, writing:
“[I]t stretches credulity to conclude that a series of numbers, or Internet address, can be said to constitute a ‘machine or any mechanical or other device . . . designed and manufactured primarily for use in connection with gambling.’ “
Actually, Kentucky’s entire approach to this matter stretches credulity, especially given the state’s storied association with gambling of the racetrack variety.
So, that’s the end of that, right? Well, not necessarily.
A spokesman for the governor tells the Lexington Herald-Leader: “We want to take some time to review [the ruling]. No decision has yet been made on whether to appeal it to the state Supreme Court.”
It’s no secret that I believe online gambling should be legal, regulated and taxed. That others may disagree I can understand. Not so that Kentuckians would abide such legal folly — and such an affront to Internet freedom — on the part of their elected officials. Throw the bums out, people.




