> I know there are some (?) ppl here actually working on AV apps for > Palm
Yup, there are some of us. :-) > How severe is the actual (or maybe upcoming) threat by malicious > apps for PalmOS? The Dark Side clouds everything... Difficult to see, the future is. :-) As for the present and specifically for Palm devices, the threat is minimal. The only known malware for Palm OS consists of 3-4 Trojan horses and one virus. The Trojan horses are pretty stupid - e.g., one of them sets the Hidden attribute of all applications in RAM. Nothing as sophisticated as keyloggers. The virus has no real chances of spreading (it is a direct-action virus) and is terribly obvious, since it is an overwriting virus and the infected applications immediately stop working. However, the virus writers are starting to discover the mobile platforms. The numbers of known viruses and Trojan horses for the Symbian platform are already explooding. There is at least one virus and one Trojan horse for the Pocket PC platform, maybe more (I haven't kept up-to-date with this platform). The main threats are communication, connectivity, popularity and user stupidity. User stupidity is constant - the humanity isn't getting any smarter. The other factors are increasing, except perhaps the popularity of Palm OS, which seems to be waning, mostly due to bad business decisions of the producers. Symbian has 60% of the market for intelligent mobile devices - this is why the virus writers are starting to prodce malware for it. If Palm OS and Windows Mobile become similarly popular, we'll start seeing more malware for them, too. The potential *is* there for all the three platforms, since each one of them allows sending of executables to another device - and often by several different means. All we need for a significant threat level is a large enough vulnerable population. Currently, this is starting to materialize only for the Symbian platform. Other than the network connectivity (e.g., Bluetooth, e-mail, etc.), the software distribution model for the mobile devices (mostly download from centralized distributors) isn't very malware-friendly. Nothing like the early PC era when people were wading around with bootable diskettes and passing around executables via bulletin board systems. Although the current software distribution model for mobile devices doesn't preclude malware distribution completely, of course. Here are a few papers on the subject of PDA security that you might find interesting: http://www.sans.org/rr/whitepapers/pda/ http://www.securityfocus.com/infocus/1521 http://www.securityfocus.com/infocus/1530 http://www.computerworld.com/printthis/2004/0,4814,90131,00.html http://downloads.securityfocus.com/library/security_analysis_palm_os.pdf http://agn-www.informatik.uni-hamburg.de/papers/doc/diparb_henrich_poehls.pdf http://www.remainsecure.com/whitepapers/antivirus/virpda.pdf http://sec.isi.salford.ac.uk/cms2004/Program/CMS2004final/p2a2.pdf http://www.fbtechies.co.uk/Content/Extras/Resources/WP-PortableComputingDeviceSecurity.pdf http://research.microsoft.com/users/helenw/papers/smartphone.pdf Regards, Vesselin -- For information on using the PalmSource Developer Forums, or to unsubscribe, please see http://www.palmos.com/dev/support/forums/
