Article

  Comment(1)

 

Hesham Fahmy's Blog  >>

Share:    Email  

Smartphone Mobile Banking Can Thwart Phishing Attacks


Hesham Fahmy, hesham.fahmy@donriver.com  
Date Posted: Monday, October 19, 2009

Online phishing has become a very serious problem and the root of the problem is the fact that the majority of computer users are not very technically savvy. Thus they fall easy prey to phishing attacks since they lack the instinct to check things such as a web browser's site address or security certificate. However even technically savvy users are falling victims with attacks such as the online banking re-write attack. In this attack cybercrooks are hiding evidence of a victim's diminishing bank balance by rewriting the online bank statements on the fly within the web browser!

As mobile banking becomes ever more popular it will most definitely be subject to similar attacks. The damage will likely be more severe since the penetration rates of mobile phones are higher than computers, and the average user is less familiar with a phone's extended features to be able to spot a potential attack.

The good news is that the emergence of the native application and AppStore model being used by most smart phone manufacturers may inadvertently provide protection against such attacks in mobile banking. If mobile banking functionality is ONLY delivered through a dedicated phone application (downloaded and verified from the smartphone AppStore) then the possibility of phishing attacks and interceptions is greatly reduced. Users would not have to be tech savvy to protect themselves since they will be accustomed to only being able to access their mobile banking channel through this authorized application. The application itself would incorporate the necessary communication security to prevent interception and hacks. Of course the user is still susceptible to attacks where a phone virus would overwrite/replace the mobile banking app but one would hope that phone OS manufacturers would not expose this type of vulnerability.

This inherent security may be a compelling reason why mobile banking providers should avoid simpler channels such as WAP, SMS or mobile web browsing altogether.


Name: Hesham Fahmy
Title: Solutions and Technology Architect
Company: DonRiver
View Hesham Fahmy's Blog

Sponsored Links
 

 

  Article

   Comments(1)

 
Login or register to post comments

1 response to this article

Phishing

Most of the time, when it comes to phishing, you can avoid problems by watching the url of the page you are on and what you click. With the mobile industry exploding, there might be another threat and another form of phishing, but as far as I'm concerned, I try   
...more

by rares on Tuesday, November 9, 2010 - 15:48


Login or register to post comments


[Show comment]

Hesham'S Recent Blogs

Even the iPhone Falls Victim to Phishing Attacks
Canadian Mobile Operators are supporting the Collaborative approa
Developed Nation Consumers Are Showing They Will Use Mobile Finan
Mary Meeker - Mobile Web Will Be 10 Times As Big as the Desktop I
Smartphone Mobile Banking Can Thwart Phishing Attacks
Adobe Flash for Rich Mobile Financial Applications
Develop Incrementally for MFS Solutions
.NET and Java for the iPhone!
Is WebKit the solution for BlackBerry, iPhone, Android, Pre and S
Mobile Financial Services: Who Provides the Customer Support?

Stay Connected

 
Sign Up for the Latest in:
 
 
Mobile Money Transfer
Mobile Commerce
Micro Finance
Mobile Technology
EMEA
APAC
Mobile Payments
Mobile Banking
Mobile Marketing
Global
Americas
Company
(*)
 

MOST POPULAR

HEADLINES

1.U.S. Bank Launches Banking App for iPad
2.Visa expects mobile payments to surge at Olympics
3.Technology is taking over traditional banking functions
4.Roshan and Western Union Launch International Mobile Money Transf
5.How Cash Keeps Poor People Poor
6.How Cash Keeps Poor People Poor

FEATURED COMPANIES

MOST POPULAR

BLOGS

1.Getting Mobile Payments Done
2.MMU moves into an exciting new phase …
3.Mobile Roadmap: Calculating Hard ROI on Soft ROI Initiatives
4.Is a third-party provider the key to unlocking the potential of M
5.A missed opportunity: Mobile money failing to meet the needs of s
6.Mobile Payments and Android. Are you ready?
7.Announcing the results of the 2011 Global Mobile Money Adoption S
8.The Demise of Nokia Money

 
 

Mobile Financial News from around the web

 
 
 

Inside the DonRiver Network