Millions of Samsung Galaxy Phones May Be Vulnerable to Hackers

Millions of Samsung Galaxy Phones May Be Vulnerable to Hackers

Samsung's Galaxy S4 emerges to do battle on Apple's home turf
Reuters
By Andrew Lumby

If you’re one of the millions of users of a Samsung Galaxy phone, you might be a potential target for a malicious hacker.

A report released today by NowSecure, a security firm located in Chicago, found that a glitch in Swift, the keyboard software used by default on all Samsung Galaxy devices could allow a remote attacker to compromise your phone.

This particular bug makes the phone vulnerable to what is known as a “man in the middle” attack. The Swift software consistently sends requests to a server, checking for updates. To someone with the right knowhow, though, it’s possible to impersonate Swift’s server and send through software that can be used to gain control of the device.

The main problem with this vulnerability is that there’s no real solution. The Swift keyboard is so integrated into Samsung’s software that it cannot be removed or disabled — even if it is switched out with a different keyboard app. Steering clear of unsecured Wi-Fi networks will make you less likely to be targeted, but it won’t render you invulnerable.

Related: 10 Biggest Tech Flops of the Century​

Swift runs with elevated permissions, giving it pretty much free rein around the phone. This means that a hacker that worms his way into it can also access the Galaxy’s microphone and camera, track the user’s location or listen to their calls. They can even install apps.

NowSecure claims to have made Samsung and Google’s Android team aware of this vulnerability in late 2014, and Samsung reportedly has made a patch available to network providers. It’s not clear, though, whether providers have pushed out the patch to users yet. Many networks have a record of being notoriously slow to push through updates and security patches, and NowSecure’s tests found a number of Galaxy phones on different carriers were still vulnerable as of Tuesday.

If you’re of a more technical bent, you may be interested in seeing the details of NowSecure’s report on their blog. If you’re of a less technical bent, you might want to check with your carrier and try to avoid insecure Wi-Fi networks.

Quote of the Day: A Big Hurdle for the Tax Cuts

Reuters/Joshua Roberts
By The Fiscal Times Staff

“He goes in and campaigns on an issue, and the challenge is he then talks about executing drug dealers. Why do you think the press is going to cover the tax cuts if you’ve given them the much more exciting issue?”

-- Grover Norquist, president of tax-cutting advocacy group Americans for Tax Reform, on President Trump’s failure to sell the tax law.

The Obamacare Mandate That Could Produce $12 Billion in Fines in 2018

FILE PHOTO: A sign on an insurance store advertises Obamacare in San Ysidro
MIKE BLAKE
By Michael Rainey

Republicans effectively eliminated the individual Obamacare mandate in the tax package signed late last year. Although the new regulation reducing the mandate penalty to zero doesn’t take effect until 2019, President Trump has cited the rule change as a victory over the health law so many conservatives oppose. “Essentially, we are getting rid of Obamacare. Some people would say, essentially, we have gotten rid of it," Trump told a crowd in Michigan two weeks ago.

However, many parts of the Affordable Care Act are still in effect and will continue to operate even after the individual mandate is eliminated in 2019.

In particular, the employer mandate, which requires companies with more than 50 employees to offer health benefits or face fine of roughly $2,000 per worker, will continue to play a significant role in the Obamacare system. The Congressional Budget Office estimates that the mandate will produce more than $12 billion in fines in 2018 alone.

Some conservative groups are pushing lawmakers to stop enforcing the employer mandate, but the IRS is still working to enforce the law. According to The New York Times Monday, the IRS is sending out notices to more than 30,000 businesses that have failed to comply. 

Chart of the Day: It’s Still the Economy, Stupid

iStockphoto
By Yuval Rosenberg

Security may be the top policy issue for Republican voters, but the economy is the top concern for Democrats, independents and voters overall, according to Morning Consult’s latest polling on the midterm elections. Health care is third on the list, followed by “seniors’ issues.” The results are based on surveys with more than 275,000 registered U.S. voters from February 1 to April 30.

Number of the Day: $13 Billion

A congressional aide places a placard on a podium for the House Republican's legislation to overhaul the tax code on Capitol Hill in Washington
JOSHUA ROBERTS/Reuters
By The Fiscal Times Staff

An analysis by Bloomberg finds that the roughly 180 companies in the S&P 500 that have reported earnings for the first three months of the year saved almost $13 billion thanks to the corporate tax cut enacted late last year. Those companies’ effective tax rate dropped by more than 6 percentage points on average. About a third of the tax savings went to 44 financial firms.

How a Florida Doctor with Social Ties to Trump Delayed a $16B Billion VA Project

McDonald delivers an apology, for recent misstatements about his military record, to reporters outside VA headquarters in Washington
REUTERS/Jonathan Ernst
By The Fiscal Times Staff

A West Palm Beach doctor who is friends with Ike Perlmutter, the chairman of Marvel Entertainment and an informal adviser to President Trump on veterans’ issues, has held up “the biggest health information technology project in history — the transformation of the VA’s digital records system,” Politico’s Arthur Allen reports. Dr. Bruce Moskowitz “objected to the $16 billion Department of Veterans Affairs project because he doesn’t like the Cerner Corp. software he uses at two Florida hospitals, according to four former and current senior VA officials. Cerner technology is a cornerstone of the VA project. … Moskowitz’s concerns effectively delayed the agreement for months, the sources said.” Read the full story.