Feeds

Nokia seeks lost Marble widgets

Fiddling Finns need a wake-up call

High performance access to file storage

Comment If you heard an unearthly groan coming from your IT department today, the following news may be responsible. Nokia today revealed that it was bringing the security and stability of Web 2.0 to its mobile handsets.

Yes, the class of PC bloatware known as "Widgets" are to run on Nokia's S60 handsets, and the formal announcement speaks of "transforming mobility and the Internet with rich Web 2.0 experiences".

Permit us to translate.

For "Transforming mobility" read: "opening up a secure platform" and for "rich Web 2.0" experience read: "to Javascript worms, pop-up windows and stealth dialers". In other words, it's the presentation layer people who think they can solve infrastructure level problems - and this time, they're coming for your phone.

We already know what you Reg readers think of Web 2.0 security: this survey of opinion should be a must-read for phone executives tempted to sprinkle a little of the Web 2.0 pixie dust on their business strategies.

JavaScript worms are a popular delivery mechanism for Malware on the PC, but as the J in AJAX, they've recently been adopted to take advantage of Web 2.0: causing havoc on MySpace, Yahoo! and, er... MySpace again.

Nokia says it will initially restrict the functionality of the JavaScript worms, before opening the floodgates. Ovum analyst Tony Cripps has glimpsed the horror that awaits us - this is what he said:

"Scripting-based security exploits are commonplace on the desktop," he writes in a research note, "and we believe countermeasures need to be employed early to avoid such issues arising on mobile phones."

He goes on, "Nokia promises to remove the sandbox in a future version once developer support and a signing process have been put in place."

At best, this creates an audit trail after the damage has been done, although there'll surely be something more sinister than a wild goose at the end of it. Many of the people behind these scams do not answer the door politely.

"So overall then, a good effort by Nokia to advance the cause of mobile widgets in a rational way," concludes Cripps.

But what's this "cause of widgets", of which he speaks?

High performance access to file storage

Next page: Nokia forgets Nokia

More from The Register

next story
A black box for your SUITCASE: Now your lost luggage can phone home – quite literally
Breakfast in London, lunch in NYC, and your clothes in Peru
Broadband Secretary of SHEEP sensationally quits Cabinet
Maria Miller finally resigns over expenses row
Skype pimps pro-level broadcast service
Playing Cat and Mouse with the media
Beat it, freetards! Dyn to shut down no-cost dynamic DNS next month
... but don't worry, charter members, you're still in 'for life'
EE dismisses DATA-BURNING glitch with Orange Mail app
Bug quietly slurps PAYG credit - yet EE denies it exists
Like Google, Comcast might roll its own mobile voice network
Says anything's possible if regulators approve merger with Time Warner
Turnbull leaves Australia's broadband blackspots in the dark
New Statement of Expectations to NBN Co offers get-out clauses for blackspot builds
Facebook claims 100 MEEELLION active users in India
Who needs China when you've got the next billion in your sights?
prev story

Whitepapers

Securing web applications made simple and scalable
In this whitepaper learn how automated security testing can provide a simple and scalable way to protect your web applications.
Five 3D headsets to be won!
We were so impressed by the Durovis Dive headset we’ve asked the company to give some away to Reg readers.
HP ArcSight ESM solution helps Finansbank
Based on their experience using HP ArcSight Enterprise Security Manager for IT security operations, Finansbank moved to HP ArcSight ESM for fraud management.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Mobile application security study
Download this report to see the alarming realities regarding the sheer number of applications vulnerable to attack, as well as the most common and easily addressable vulnerability errors.