Possible security hole for Dialers/troyan horses

Jonathon Suggs jsuggs at murmp.com
Thu Mar 1 16:48:09 CET 2007


Martin Raißle wrote:
> On 3/1/07, Krzysztof Kajkowski <cayco at poczta.cayco.pl> wrote:
>> However there might be such attempts to create GSM trojans
>> and we should be aware to enable user to protect itself. The question
>> is how to do that?
>>
>> What do you think?
>
> First off all I think that there are good chances for a trojan, even
> if it has to be downloaded manually ... think about all the trojans
> for windows ... and in phase 2 and beyond this phone will probably
> have users that don't mind about security ... I think it would be a
> good idea to be able to set the rights of an application, like
> - can/cannot make calls / send sms
> - can/cannot read/edit adress book / calendar
> - can/cannot initiate gprs-connections
> - can/cannot use gps
>
> and to safe normal user all rights, that can create costs should be
> disabled by default ..
>
> regards
> martin
Isn't this something along the lines of SELinux?  If that is the case, 
is that something we should look at implementing?




More information about the community mailing list