Topics Mobile Tech News Wednesday, June 19

Headlines

Contact us


Site search:
complete archives list




Site Sponsors:


Don't forget AT&T and Verizon promo codes at Sidepon.com to save money.


HTC America Settles FTC Charges
Posted: 22-Feb-2013 [Source: Federal Trade Commission]

[HTC is ordered to take steps to improve the security around its implementation of Carrier IQ and HTC Logger software on its smartphone devices. "Due to these vulnerabilities," the FTC charged, "millions of HTC devices compromised sensitive device functionality...all without the user’s knowledge or consent."]

Washington DC -- Mobile device manufacturer HTC America has agreed to settle Federal Trade Commission charges that the company failed to take reasonable steps to secure the software it developed for its smartphones and tablet computers, introducing security flaws that placed sensitive information about millions of consumers at risk.

The settlement requires HTC America to develop and release software patches to fix vulnerabilities found in millions of HTC devices. In addition, the settlement requires HTC America to establish a comprehensive security program designed to address security risks during the development of HTC devices and to undergo independent security assessments every other year for the next 20 years.

HTC America, Inc., a leading mobile device manufacturer in the United States, develops and manufactures mobile devices based on the Android, Windows Mobile, and Windows Phone operating systems. HTC America has customized the software on these devices in order to differentiate itself from competitors and to comply with the requirements of mobile network operators.

The Commission charged that HTC America failed to employ reasonable and appropriate security practices in the design and customization of the software on its mobile devices. Among other things, the complaint alleged that HTC America failed to provide its engineering staff with adequate security training, failed to review or test the software on its mobile devices for potential security vulnerabilities, failed to follow well-known and commonly accepted secure coding practices, and failed to establish a process for receiving and addressing vulnerability reports from third parties.

To illustrate the consequences of these alleged failures, the FTC’s complaint details several vulnerabilities found on HTC’s devices, including the insecure implementation of two logging applications - Carrier IQ and HTC Loggers - as well as programming flaws that would allow third-party applications to bypass Android’s permission-based security model.

Due to these vulnerabilities, the FTC charged, millions of HTC devices compromised sensitive device functionality, potentially permitting malicious applications to send text messages, record audio, and even install additional malware onto a consumer’s device, all without the user’s knowledge or consent. The FTC alleged that malware placed on consumers’ devices without their permission could be used to record and transmit information entered into or stored on the device, including, for example, financial account numbers and related access codes or medical information such as text messages received from healthcare providers and calendar entries concerning doctor’s appointments. In addition, malicious applications could exploit the vulnerabilities on HTC devices to gain unauthorized access to a variety of other sensitive information, such as the user’s geolocation information and the contents of the user’s text messages.

Moreover, the complaint alleged that the user manuals for HTC Android-based devices contained deceptive representations, and that the user interface for the company’s Tell HTC application was also deceptive. In both cases, the security vulnerabilities in HTC Android-based devices undermined consent mechanisms that would have otherwise prevented unauthorized access or transmission of sensitive information.

The settlement not only requires the establishment of a comprehensive security program, but also prohibits HTC America from making any false or misleading statements about the security and privacy of consumers’ data on HTC devices. HTC America and its network operator partners are also in the process of deploying the security patches required by the settlement to consumers’ devices. Many consumers have already received the required security updates. The FTC encourages consumers to apply the updates as soon as possible.

The settlement with HTC America is part of the FTC’s ongoing effort to ensure that companies secure the software and devices that they ship to consumers. Earlier this month, the FTC introduced Mobile App Developers: Start with Security, a new business guide that encourages app developers to aim for reasonable data security. In addition, on June 4, 2013, the Commission will host a public forum on malware and other mobile security threats in order to examine the security of existing and developing mobile technologies and the roles that various members of the mobile ecosystem can play in protecting consumers.

The Commission vote to accept the consent agreement package containing the proposed consent order for public comment was 3-0-2, with Chairman Jon Leibowitz not participating and Commissioner Maureen Ohlhausen recused. The FTC will publish a description of the consent agreement package in the Federal Register shortly. The agreement will be subject to public comment for 30 days, beginning today and continuing through March 22, after which the Commission will decide whether to make the proposed consent order final. Interested parties can submit comments electronically or in paper form by following the instructions in the “Invitation To Comment” part of the “Supplementary Information” section. Comments in paper form should be mailed or delivered to: Federal Trade Commission, Office of the Secretary, Room H-113 (Annex D), 600 Pennsylvania Avenue, N.W., Washington, DC 20580. The FTC is requesting that any comment filed in paper form near the end of the public comment period be sent by courier or overnight service, if possible, because U.S. postal mail in the Washington area and at the Commission is subject to delay due to heightened security precautions.

More...

Back to Headlines...

iOS 7 iOS 7

Jolla Jolla

BlackBerry Z10 BlackBerry Z10

Galaxy S 4 Galaxy S 4

Galaxy Note 8.0 Galaxy Note 8.0

Ubuntu on Tablets Ubuntu on Tablets

HTC One HTC One

LG Optimus G Pro L-04E LG Optimus G Pro L-04E

Firefox OS Firefox OS

Sony Zperia Z Sony Zperia Z

iPhone 5 iPhone 5

Kindle Fire HD Kindle Fire HD

Nokia N920 Nokia N920

Sony Xperia Sony Xperia

LG Optimus Quad-core LG Optimus Quad-core

Google Nexus 7 Tablet Google Nexus 7 Tablet

Droid Incredible 4G LTE Droid Incredible 4G LTE

Samsung Galaxy S III Samsung Galaxy S III

HTC EVO 4G LTE HTC EVO 4G LTE

New iPad New iPad

Huawei Ascend D Quad Huawei Ascend D Quad

Nokia 808 PureView Nokia 808 PureView

Huawei Ascend P1 Huawei Ascend P1

Polaroid Android Camera Polaroid Android Camera

Nokia 900 Nokia 900

Nook Tablet Nook Tablet

Apple iPhone 4S Apple iPhone 4S

Amazon Fire Tablet Amazon Fire Tablet

HTC Rhyme HTC Rhyme

Sony S1/S2 Tablets Sony S1/S2 Tablets

Samsung Galaxy Smartphones Samsung Galaxy Smartphones

BlackBerry 7 Smartphones BlackBerry 7 Smartphones

Motorola Photon 4G Motorola Photon 4G

Sprint/HTC 3D Sprint/HTC 3D

Nokia N9 MeeGo Nokia N9 MeeGo

HP TouchPad HP TouchPad

Motorola Droid X2 Motorola Droid X2

Sony S1 and S2 Tablets Sony S1 and S2 Tablets

Nokia X7 Nokia X7

Sprint/HTC 3D Sprint/HTC 3D

CTIA 2011 CTIA 2011

Google Nexus S 4G Google Nexus S 4G

T-Mobile Sidekick 4G T-Mobile Sidekick 4G

iPad2 iPad2

Xperia Play Xperia Play

HP webOS Tablet HP webOS Tablet

Sprint/Kyocera Echo Dual-Screen Sprint/Kyocera Echo Dual-Screen

T-Mobile/Samsung Galaxy S 4G T-Mobile/Samsung Galaxy S 4G

AT&T/Motorola ATRIX 4G Smartphone AT&T/Motorola ATRIX 4G Smartphone

Verizon/Motorola XOOM tablet Verizon/Motorola XOOM tablet

Sprint/HTC EVO Shift Sprint/HTC EVO Shift

Nexus S Nexus S

Samsung Galaxy Tab Samsung Galaxy Tab

HP's Palm Pre 2 HP's Palm Pre 2

HTC's Windowsphone HTC's Windowsphone

Motorola DROID PRO Motorola DROID PRO

Verizon/Motorola CITRUS Verizon/Motorola CITRUS

BlackBerry PlayBook BlackBerry PlayBook

Sharp Galapagos E-Book Reader Sharp Galapagos E-Book Reader

HTC Desire HD HTC Desire HD

Nokia E7 Nokia E7

T-Mobile G2 T-Mobile G2

BlackBerry Torch 9800 BlackBerry Torch 9800

Sprint/Samsung Epic 4G Sprint/Samsung Epic 4G

Verizon/Motorola DROID X Verizon/Motorola DROID X

Motorola MILESTONE XT720 Motorola MILESTONE XT720

iPhone 4 iPhone 4

T-Mobile myTouch 3G Slide T-Mobile myTouch 3G Slide

Nokia N8 Nokia N8

KIN Social Phone KIN Social Phone

Samsung Galaxy S Samsung Galaxy S

Motorola MILESTONE Motorola MILESTONE

Apple iPad Apple iPad

Dell Mini 3 Dell Mini 3

Google Nexus One Google Nexus One



 

Valid HTML 4.1!

RSS © 1999-2013 Traques LLC
All times recorded in UTC
webmaster@MobileTechNews.com