Google denies Android botnet report. MS researcher guessed at source.


Recommended Posts

Yesterday, we told you how a Microsoft anti-spam engineer claimed to have found a network of Android devices designed to send spam. Today, it looks like that report might have just been an educated guess. While the emails do indeed say "Sent from Yahoo! Mail on Android," Google says its own analysis points a different direction. "The evidence does not support the Android botnet claim," the company wrote in a statement. "Our analysis suggests that spammers are using infected computers and a fake mobile signature to bypass anti-spam mechanisms in the email platform they're using."

More importantly, the security researchers who initially outed the botnet are now admitting that they actually don't know for sure. Terry Zink, the Microsoft researcher who originally wrote the report, now says that he considered that the messages could have been spoofed, but decided that it simply made more sense for them to have come from Android. Chet Wisniewski, a Sophos security advisor who suggested that users should install Sophos Mobile Security to avoid being infected by an app that could send this kind of spam, told The Wall Street Journal that "we don't know for sure that it's coming from Android devices."

Yahoo told The Register that it's investigating the issue.

There's still a definite possibility that this is indeed an Android botnet of some sort, and both researchers claim the evidence points that direction, but we're far less certain than we were before, and a little less trusting, too.

http://www.theverge.com/2012/7/5/3140108/google-denies-android-botnet-report

so Google lies... not the first one, barely the last

How in the hell did you conclude that Google lies out of that article? :huh: The guys who did the report were speculative and tried to sell the information as misleading guess and not facts, not Google. Geez.

Read the article before posting next time.

i did... the speculative nature of yesterday's article does not account for the continuously growing android malware scene; since aug 2011 there are more and more reports of these kinds so MAYBE the researcher was premature to shout wolf in this case (i would suggest waiting for yahoo and others to look into it) but nevertheless the problem is real, by denying google does the same apple did for years; considering these and the crappy update method google use anyone who says people are idiots, noobs etc are as big an ******* as somebody can get - it's google's job to maintain security of the os and the marketplace - or let us block any and all android devices, i can live with that too

i did... the speculative nature of yesterday's article does not account for the continuously growing android malware scene; since aug 2011 there are more and more reports of these kinds so MAYBE the researcher was premature to shout wolf in this case (i would suggest waiting for yahoo and others to look into it) but nevertheless the problem is real, by denying google does the same apple did for years; considering these and the crappy update method google use anyone who says people are idiots, noobs etc are as big an ******* as somebody can get - it's google's job to maintain security of the os and the marketplace - or let us block any and all android devices, i can live with that too

Read the article again. Google is not denying the existence of malware. They are just deny they are the soureof this specific botnet that the MS engineer found. This article is not about the growing number of malware in Android (which was posted on the front page)

This topic is now closed to further replies.
  • Posts

    • Vivaldi version 8.0.4033.50 released June 17: https://vivaldi.com/blog/desktop/minor-update-eight-8-0/
    • The Online part hasn't even been announced and probably won't be included on day one. This is a massive singleplayer game.
    • While I agree with all that, it just proves there's an a** built for every seat.
    • Lol are you mad because I'm not using AI? I'd rather pay people than lose a bunch of potential customers and get humilated because I used AI. A lot of people won't purchase a game if it used AI during development.
    • LibreWolf 152.0-1 by Razvan Serea LibreWolf is an independent “fork” of Firefox, with the primary goals of privacy security and user freedom. It is the community run successor to LibreFox. LibreWolf is designed to increase protection against tracking and fingerprinting techniques, while also including a few security improvements. This is achieved through our privacy and security oriented settings and patches. LibreWolf also aims to remove all the telemetry, data collection and annoyances, as well as disabling anti-freedom features like DRM. LibreWolf features: Latest Firefox — LibreWolf is compiled directly from the latest build of Firefox Stable. You will have the the latest features, and security updates. Independent Build — LibreWolf uses a build independent of Firefox and has its own settings, profile folder and installation path. As a result, it can be installed alongside Firefox or any other browser. No phoning home — Embedded server links and other calling home functions are removed. In other words, minimal background connections by default. User settings updates Extensions firewall: limit internet access for extensions. Multi-platform (Windows/Linux/Mac/and soon Android) Community-Driven Dark theme (classic and advanced) LibreWolf privacy features: Delete cookies and website data on close. Include only privacy respecting search engines like DuckDuckGo and Searx. Include uBlockOrigin with custom default filter lists, and Tracking Protection in strict mode, to block trackers and ads. Strip tracking elements from URLs, both natively and through uBO. Enable dFPI, also known as Total Cookie Protection. Enable RFP which is part of the Tor Uplift project. RFP is considered the best in class anti-fingerprinting solution, and its goal is to make users look the same and cover as many metrics as possible, in an effort to block fingerprinting techniques. Always display user language as en-US to websites, in order to protect the language used in the browser and in the OS. Disable WebGL, as it is a strong fingerprinting vector. Prevent access to the location services of the OS, and use Mozilla's location API instead of Google's API. Limit ICE candidates generation to a single interface when sharing video or audio during a videoconference. Force DNS and WebRTC inside the proxy, when one is being used. Trim cross-origin referrers, so that they don't include the full URI. Disable link prefetching and speculative connections. Disable disk cache and clear temporary files on close. Disable form autofill. Disable search and form history...and more. LibreWolf 152.0-1 changelog: Upstream release, see the Firefox 152.0 Release Notes Notable changes: The AppImages are now built on Codeberg along with the other releases We have decided to wait a bit longer to enable the settings redesign, due to use being aware of multiple upstream issues Download: LibreWolf 64-bit | Portable 64-bit | ~100.0 MB (Open Source) Download: ARM64 | Portable ARM64 Links: LibreWolf Home Page | Addons | Screenshot | Reddit Get alerted to all of our Software updates on Twitter at @NeowinSoftware
  • Recent Achievements

    • Week One Done
      Huge Trailer earned a badge
      Week One Done
    • Week One Done
      Classifyskilleducation earned a badge
      Week One Done
    • One Month Later
      eurospharma62 earned a badge
      One Month Later
    • Week One Done
      With What earned a badge
      Week One Done
    • Week One Done
      Harris Gilbert earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      560
    2. 2
      +Edouard
      169
    3. 3
      PsYcHoKiLLa
      73
    4. 4
      Michael Scrip
      64
    5. 5
      ATLien_0
      64
  • Tell a friend

    Love Neowin? Tell a friend!