Subscribe:

Thursday, August 25, 2011

Illegal Keygen for Reputed Antivirus Comes Bundled with Malware

Care to install a “virused” antivirus?
It is common practice for crooks to use pirated software as a means of disseminating malware. It’s an approach that has been used for years and it still works as a charm. Any new software product launch is awaited and included into this malware distribution cycle. A much anticipated movie or software product becomes the perfect lure for users who are inclined towards piracy rather than legal product or service acquisition.
This is exactly the scenario we spotted last week, when crooks started using the latest Internet Security avtivirus product from Trustport as bait for malware dissemination. They tampered with an illegal keygen (identified by our labs as Application.Keygen.BW) in order to bind it with a piece of backdoor malware  that is also deployed on the users’ systems along with an illegal key for the AV product.
This keygen spreads via P2P sharing services, USB media, instant messaging services or e-mail clients and users may end up downloading serious trouble on their systems as this particular illicit tool does a lot more than it is supposed to do.
The piece of malware inside the keygen is identified by Bitdefender as Trojan.Agent.ASDM and starts its wrongdoing by injecting itself into explorer.exe and adding a list of exceptions to the locally installed firewall. Afterwards, it deploys a keylogger and a backdoor component on the compromised computer. Depending on how you’re using your computer, this piece of malware does the following:
-          steals passwords cached in various web browsers such as Mozilla Firefox or Internet Explorer;
-          spies on the users’ habits and gathering critical information about the compromised computer and, worst of all, showing great interest for all that has to do with e-banking accounts and money transactions;
-          downloading further malware either via internet or from ftp accounts; the sample we analyzed is capable of downloading and installing  Zeus BOT, SpyNet RAT, Bandook RAT, Scwarze Sonne RAT, Apocalypse RAT, Bff BOT, Solitude RAT, PoisonIvy,  Cybergate, which hints to a possible cooperation between Trojan.Agent.ASDMand other cyber-criminal gangs.;
-          captures video and audio  streams from the users’ computer webcams;
-          logs conversations that take place on social networks or instant messenger;
It is safe to say that there’s an extremely high chance that pirated software leads to malware and it’s definitely a risk not worth taking.
This article is based on the technical information provided courtesy of Doina Cosovan, BitDefender VirusAnalyst.
All product and company names mentioned herein are for identification purposes only and are the property of, and may be trademarks of, their respective owners.

Wednesday, August 24, 2011

Microsoft asks for ban of Motorola's smartphones

Microsoft is presenting a case before the International Trade Commission (ITC) in which they claim Motorola Mobility is using technology in their Android-based smartphones that was derived from Microsoft products. The world’s largest software maker is asking the ITC to halt imports of certain Motorola phones.
Bloomberg reports that the trial began on Monday in Washington and that Microsoft claims Motorola infringed on seven patents. Microsoft singled out the Droid 2, Droid X, Cliq XT, Devour, Backflip and Charm handsets among those guilty of infringement. The ITC does have the ability to halt imports if they feel a product violates US patent rights.
“We have a responsibility to our employees, customers, partners and shareholders to safeguard our intellectual property,” David Howard, Microsoft’s corporate vice president and deputy general counsel for litigation, said in an e-mail. “Motorola is infringing our patents and we are confident that the ITC will rule in our favor.”
Motorola is defending themselves against the patent suit and a company spokeswoman said they have also brought legal actions of their own against Microsoft in the US and Europe for the same reasons.
This is the first of what is likely to be many more lawsuits brought upon Motorola Mobility since Google agreed to buy the company for $12.5 billion last week. The main reason Google made the purchase was to acquire a wealth of patents from Motorola Mobility to protect themselves as well as the Android platform. Interestingly enough, Google isn’t named in the complaint.
The judge in the case is scheduled to make a decision on November 4 and the ITC has until March 5, 2012 to complete their investigation.

Firefox 7 beta now available, final build due next month

A beta version of Mozilla’s Firefox 7 is now available for Windows, Mac and Linux. Despite releasing version 6 of the popular browser earlier this week, it’s the next iteration that many expect to solve persistent memory leak issues that have plagued the software for years.
Firefox 7 will introduce MemShrink, an initiative that began in June to eradicate the browser's memory inconsistencies. Mozilla developer Nicholas Nethercote claims that Firefox 7 uses less memory than the past three versions, between 20 and 50 percent less in some instances.
In addition to MemShrink, the new build also features better Javascript garbage collection. It's said to work more frequently now and should free up more memory when multiple tabs are open. The upcoming browser also implements Azure Direct2D for Canvas which increases canvas-based animations in HTML5.
There are also tools built into Firefox 7 that will help developers measure load times. Synchronization of bookmarks and passwords is said to be faster, too.
Version 7 is part of Mozilla’s recent rapid deployment of browsers. The developer released Firefox 5 in June and earlier this week it quietly launched Firefox 6 a day ahead of the planned release date.
Mozilla’s browser has been criticized for needing large amounts of RAM and then not freeing that memory once windows or tabs have been closed. Nethercote acknowledges these shortcomings, indicating that some versions were more efficient than others. He praised Firefox versions 3, 3.5 and 3.6 but said things deteriorated with version 4 partly because of all its new features, aggressive JavaScript garbage collection and image decoding.
The final version of Firefox 7 should be available by September 27.

Sunday, August 21, 2011

Gaming community highly exposed to bitcoin-mining Trojan

While distributed denial of service and spam sending are still some of the most effective ways of monetizing a large-scale Botnet, cyber-criminal gangs have also turned their attention towards the increasingly popular peer-to-peer currency system known as Bitcoin.
The first week of August brought under our scope a miner Trojan identified by Bitdefender as Trojan.Antiminer.A, that highjacks compromised machines with the purpose of creating a botnet of infected PCs and uses their resources to produce virtual money. The Trojan silently deploys a legit Bitcoin miner that uses the GPU of the machine to compute virtual currency.
Inspired by the fact that the Bitcoin (BTC) parity is one to 15 US dollars, the crooks have laid eyes on computer systems with powerful GPUs to make easy money. The gaming community is therefore highly exposed since the modern games on the market require powerful GPUs to support the latest developments in the visual effects industry.
“If you happen to download cracked games via Torrent or other P2P sharing services, chances are that you may become a victim of this lucrative Trojan bundled with a genuine GPU miner. We advise you to start checking your system for signs of infection, especially if you are constantly losing frames-per-second,” advises Catalin Cosoi, head of BitDefender Threats Lab.  “The Trojan’s mission is dramatically facilitated by the fact that hardcore gamers do not run antivirus solutions as these are traditionally perceived as bottlenecks on high-performance computers,” he continued.
It may be true that a single miner – be it powered by the most advanced GPU on the market – calculates a limited number of Bitcoins per day. That is why the masterminds behind this operation target a large number of compromised computers that act like an extensive capable of processing large amount of hashes that are transformed into Bitcoins. It is obvious that more computers produce more virtual money while, at the same time, increasing statistically the chances of getting the randomly-awarded bounty of 50 coins for participation in the pool’s effort.
If the Bitcoin system needs any clarification at all, then you should know that it is a cryptographic virtual currency meant to help people make transactions over the Internet while keeping the utmost privacy of their identity. These trades can be made under the mask of anonymity, where there’s no real identity associated to the online persona. Plus there is no bank or state authority to govern over the production or use of this digital cash either.
This attack is just one take at the big pot of money that revolves around Bitcoin. There have been a series of incidents in which cyber-criminals tried to tamper with the system to their own advantage and we expect to see increased malicious activity related to Bitcoin mining on the computing resources of unwary users.
All product and company names mentioned herein are for identification purposes only and are the property of, and may be trademarks of, their respective owners.
Download now the removal tool for Trojan.Antiminer.A!


Worried about your money while on-line? You should be!

10 safety tips for on-line banking and shopping Several years ago, I've worked with a very gifted teacher who wrote a wonderful IT&C manual that I've edited. As we were going through the final revision, she came up with the idea of adding a motto for each chapter. Although I was a bit reluctant at that time, eventually I agreed. And it turned out just fine, as the high school kids that actually used this book liked it too. A week ago, as I was reading an article about e-banking applications that aren't actually working on all types of browsers, I've suddenly remembered two of the most simple and apparently contradicting statements that my author used in her manual. One of them - “If you aren't on-line, you don't exist” - opened the Internet chapter. The other - “The only way to stay safe is off-line” - introduced the Security section. If we play a bit with their meaning and we are (not-so-fallaciously) speculating it, we get the following assertion: “As long as you are on-line, you are in danger”, which makes more sense than the sophism “You're safe if you don't exist”.
However, banks and e-commerce Web sites tell us a different story. That we are effectively safe and secure while we access on-line our deposits and accounts and that we shouldn't worry at all. If you don't trust me, listen to this guy. Fast forward to 15:10 and you will see that even a hacker says so. He's actually kidding and even banks and on-line merchants are partially kidding, no matter how reputable they are, by saying that everything is fine when it comes to e-banking and e-commerce. And mark my words, you shouldn't take that for granted. Why is that? For the same reason that you shouldn't cross a street without looking left, then right (or vice-versa, if you leave in UK and other places where traffic works in reverse), and even if the light is green (or says 'WALK').
If so, what should we do? Not using e-banking or e-commerce at all? It doesn't make any sense, especially for a 21st-century-extremelly-busy-and-technology-dependent-person right? Right. Well, I'm not saying that we shouldn't using them at all. That would be just as locking yourself inside the house and hiding under the bed because there are cars running outside on the same street you are supposed to cross. Just be careful. And here are some tips:
1. Use a dedicated machine. Get a cheap netbook, laptop or desktop configuration and use it solely for e-banking and e-commerce. Password-protect it, so that you limit the access (you wouldn't want kids to mess around with it), and always connect it to the Internet through a wired connection instead of WiFi to avoid traffic interception. Refrain from shopping or banking on-line from public computers or via wireless unsecured network connections, such as those in coffee shops or airports. Also, it would be a good idea not to buy or make any transaction while on bus, subway or any crowded places – one can never tell who's looking over your shoulder.
2. Ideally, your e-commerce/e-banking-dedicated machine should not run Windows – use a Linux distribution or MacOS. Don't get me wrong, I'm no one's advocate here, but as Windows is the most widely-spread operating system in the world, chances to get infected or compromised are higher. If you don't believe me, then read this story. However, if it is more convenient for you to run Windows or MacOS, then installing a security suite with at least a Firewall, Antispyware and Antimalware is a must. Check this out: BitDefender Facebook fans get 6 extra months of protection for free with the best defensive solution currently on the market, BitDefender Internet Security 2011! Pretty cool, isn't it? By the way, no matter what OS is on that machine, update it frequently. Do the same for your browser and for your security suite. It's crucial in keeping malware and attackers away from your system!
3. Beware of phishing or vishing attempts – banks and retailers will never ask you to change login credentials or other important account details on the phone or via e-mail and sms. If you have any suspicion, make a visit to the bank or try to call them back at the number provided in the contract or agreement you signed (for phone calls it will be a good idea to write down the name of the person who called you and ask for him or she, to see if that person actually exists within that organization).
4. As your Internet browser is your gateway to any on-line financial transaction, clean its cache before and after going on-line, regardless of your operating system. Empty cookies and all plug-in data, as well as all automatically filled data it may save. Disable Autocomplete and Save Passwords options. Moreover, you should refrain from storing any transaction details on your computer. Additionally, you may want to add a free cross-browser controller, such as BitDefender TrafficLight extension, to make your Web surfing even safer.
5. Use on-screen keyboard. Search for it in accessibility tools of your OS and click with your mouse the screen instead of typing on your keyboard. It can spare you the trouble of keystrokes being intercepted by keyloggers.
6. Always manually introduce the address of your bank or on-line retailer in the browser's address bar to avoid redirection towards phishing pages mimicking the genuine page. One single misspelled letter and you could end up handling to cybercriminals all your login credentials on a silver plate.
7. Before proceeding, make sure that the Web page where you enter sensitive data (user name, password, transaction confirmation number, credit card number, CVC and other data) is encrypted. Normally, you should see a locked padlock somewhere in your browser and a page prefix that is https:// in the address bar.
8. For e-banking, you should check with your bank for at least a two-factor authentication procedure – usually based on a security-token. As for online shopping, before making any transactions, enroll your credit card in a supplementary verification program, usually provided free of charge, such as 3-D Secure.
9. Add an insurance to your on-line transactions. It could cost you a bit extra, but it's worthing. Better safe than sorry/broke!
10. Always do some reconnaissance before subscribing or buying online. Find out what others have to say about the e-banking service you want to enroll or a Web site you want to shop from. Ask relatives, friends, your lawyer and bank adviser or simply search on the Internet.
 
Safe e-banking and e-commerce everybody!
 
All product and company names mentioned herein are for identification purposes only and are the property of, and may be trademarks of, their respective owners.

Source: malwarecity.com

Trojan.FakeAV.LVT– Plays You (Like) in Movies

What happens when screenplay writers, social engineers and software developers meet
A video on Facebook is used as vector of infection for a Trojan, the rogue AV component artfully mimics the antivirus you have installed on your system and the downloader adds the compromised PC to a network of infected systems that constantly exchange malware between them.
Exquisite spreading mechanism
Trojan.FakeAV.LVT takes social engineering to a whole new level.  The scenario is extremely complex and efficient: imagine a friend that initiates a conversation with you in a Facebook chat window. The dialogue seems a bit rigid and soon you are teased with questions such as "Hi. How are you?”, “It is you on the video?” or “Want to see?” that introduce a link to nothing else but a movie allegedly starring yourself. Classic you may say; and you wouldn’t be completely wrong. However, the juicy details are yet to come.
First of all, you are shown a Youtube page with a movie that mentions your name in the title, which is, by the way correctly spelled, as it is taken directly from your Facebook profile. At this point, the video is probably gaining your full trust. On top of that, some of your friends (also taken from your Facebook account friends list) appear to have already commented the video, adding thus yet another huge plus to this crafty scam. In short, you have a movie that is allegedly about you and some friends’ comments that either worship you or appear to be utterly disappointed. Wouldn’t you care to see why?
The video file appears to be missing a codec
Well, if the answer is yes, you will be requested to download a new version of Flash Player, because it appears that your version is “outdated”. This should ring a bell that something is “phishy”, but given the fact that it is a message you have seen quite a lot of times on the legit website, you might not even notice it. Once you click the link, you get immediately caught in a scenario that seems to be taken straight from science fiction movies, because what you download is an extremely insidious Trojan.
Act two: behind the closed curtains
While you think that you are downloading a Flash Player, you are in fact welcoming a Trojan on you PC that will shortly start wreaking havoc on your system. The malicious code hides under the innocent name and appearance of a Flash Player. It copies itself as %windir%\services32.exe and as %windir%\update.X\svchost.exe, where update is a hidden directory and X is the version of the malware. After that, it adds a registry key in %SYSTEM% and the malicious code is added thus to the list of authorized applications for the firewall or it disables the firewall altogether.
Then it proceeds to disabling all notifications generated by the firewall, the update module and whatever antivirus it finds installed on the PC. Yes, you’ve got it right, it strips you off whatever protection you have in place.
Act three: the mutant, multi-faceted, rogue AV
One thing I find utterly disappointing with Rogue AV software is the fact that they fail to trick anyone but those who hardly spend any time in front of the computer. Trojan.FakeAV.LVT however has a rogue AV component that is indeed innovative. We all know that fake antivirus solutions trick users into downloading a product by showing alarmist pop-ups claiming that the PC is packed full with malware. This one takes things to a whole new level. It starts by displaying personalized warning message windows that are strikingly similar to the AV solution it finds installed on the system. Yes, it is a chameleon that has a copycat kit for all the important AV products on the market. It goes so far in that it initially determines the AV running on the machine and the interface language selected by you. It will afterwards use the captions, the icons and the messages consistent with the personalized settings of the installed AV.
In order to leave you totally unprotected, the Trojan displays a popup warning and kindly asks you to reboot the system in order to perform the clean-up. But, before that, it queues your antivirus for uninstallation, then uses the genuine Microsoft bcdedit.exe (command line tool for managing BCD (Boot Configuration Data) files) in order to instruct the system to boot in safe mode after restart.
The piece of malware will successfully start in safe mode, as it has created the following Registry key: "HKLM\SYSTEM\ControlSet001\Control\SafeBoot\AlternateShell = %windir%\services32.exe". After it has successfully removed your antivirus, the Trojan uses bcdedit. exe again to execute the following: 'BCDEDIT /deletevalue safeboot /set safebootalternateshell false' and restart the computer in normal mode.

Alert window imitating a genuine product
Now that you have seen how good the “antivirus” is, you are also notified that qualified help could be provided in a couple of hours by a support specialist, if you send them your cell-phone number.
Act four: the tragic ending
The Trojan also packs under its hood a downloader component that fetches files from different URLs depending on the OS of the infected system. The systems running Windows Vista, for instance, will download files from a different location than those running XP. The downloaded file contains a list of IPs saved as %windir%\front_ip_list.txt.
The malware contains a hardcoded list of IPs, as well. These are the IPs of other infected systems which will be used at exchanging malware between them, creating a fully-fledged malware distribution system with peer-to-peer update capabilities. These IP lists are changed regularly and so infected system are always in contact and constantly exchanging malicious code.
Conclusion
Cyber-crooks have given a new dimension to their operations. This carefully-planned “sting operation” hunts the Facebook user down, refers it to a popular video-sharing website where all their friends are laughing at a clip starring themselves, then forces them to download a Trojan. After that, the Trojan ensures that the user gets completely stripped off of their security solution, in order for the malware to take full control of the severely compromised system. What happens then surpasses any reasonable thinking: the computer is used by the cyber-crooks for a wide range of purposes that are constantly expanded through the use of malicious plug-ins. All these happen while you think that you’re completely safe and that nothing can happen to you.
This article is based on the technical information provided courtesy of Doina Cosovan and Răzvan Benchea, BitDefender VirusAnalysts.
All product and company names mentioned herein are for identification purposes only and are the property of, and may be trademarks of, their respective owners.

Source: malwarecity.com

iPhone 5 rumor roundup for the week ending June 10

In the nick of time, Apple announced iOS 5. Single-handedly, it's saved the increasing stale, desperately-seeking iPhone 5 Rumor Industry from self-extinction. Re-energized, the rumoratchiks are streaming the stuff out: wireless charging, no iPhone 4S, iPhone 4S confirmed, the end of SMS as we know it, two iPhone 5 models, price cuts, 8 megapixel camera, SummerFallWinterSpring announcement date!
It's a great time to be rumoring. Here's the iPhone 5 rumor rollup for the week ending June 10.
MORE IPHONE RUMORS: iPhone 5 rumor rollup for week ending May 27
Delaying iPhone 5 is part of a clever Apple strategy.
The "delay" in announcing iPhone 5 is a Good Thing because it shows Apple is serious about the competition from Google Android and Microsoft, according to ITPortal's Desire Athow. So it's focusing energy on creating really cool software and services.
Athow gets extra points for creating this week's most-labored-analogy: "Announcing the iPhone 5 now would be the sporting equivalent of showcasing a horse for a race without knowing who the jockey will be; Apple needs both the hardware and the software to be ready."
Wireless charging for iPhone 5.
An Apple patent indicates the company could be readying a wireless charging system that would be built into its iMac computers to charge nearby wireless devices, such as a keyboard, mouse, "and -- yes -- iPhones containing the appropriate receivers," according to FoneHome.com, which headlined its story "Wireless iPhone 5 charging patent revealed."
FoneHome had picked up on the patent information posted at World Intellectual Property Organization (WIPO), which of course doesn't mention iPhone 5.
Apple's approach sounds similar to that of MIT researchers (and many others) using electromagnetic resonance between coils to transfer energy without wires and then convert it into power. The MIT team demonstrated a more efficient version of the technology just over a year ago.
Forget the "iPhone 4S."
Beatweek conclusively speculates that all the speculation about a kind of souped-up iPhone 4 model, usually dubbed iPhone 4S, preceding the iPhone 5 is and always was codswallop. "While there's no specific evidence to suggest that the iPhone 4S was 'made up' by folks with any intention to deceive, at the very least the iPhone 4S was indeed a made-up product. In other words, it never existed."
By contrast, Beatweek goes on to conclusively speculate on all we do "know" about the real iPhone 5. Stuff like ... it has an operating system: the just announced iOS 5. And: "We've identified at least two carriers that it'll be on. We know it'll sport an A5 processor."
Wow.
"We learn a little bit more about the iPhone 5 each day, piece by piece, and slowly," according to Beatweek. Sort of like weaving a tapestry of rumors, or like building a smartphone sculpture out of Legos.
There's only one problem with Beatweek's claim that iPhone 4S never existed ...
Sprint has the iPhone 4S. Or something.
"Sources" have told 9to5Mac that a version of the iPhone intended for Sprint is right now in "advanced testing." This is being done in Apple's sinisterly-but-coolly-named "Black Labs," presumably a reference to office space and not dogs.
Could it be the iPhone 5? "The physical design of this device is akin to the iPhone 4 of today, so this might be the iPhone 4S device with support for all carriers that we have been dreaming up and hearing whispers about." Unless you're Beatweek.
But there's more -- a second iPhone for Sprint that will support 4G, however that's defined by this month's TV ads: "Sources also say that talk of a 4G variant of the iPhone for Sprint is moving along, but the first generation Sprint iPhone that is currently in testing does not feature support for 4G bands."
So apparently the first Sprint iPhone will be the iPhone 4S, and the second Sprint iPhone will be the iPhone 4S 4G, which means the third Sprint iPhone will be the iPhone 5, which may or may not be 4G, because that would make it the iPhone 54G.
But there's even more. 9to5Mac linked to another rumor at TalkAndroid, which according to 9to5Mac claims that a Sprint iPhone will include dual-band support for T-Mobile, about which 9to5Mac rhetorically asks, "weird, right?"
It would be, if that's what TalkAndroid actually said. The rumor actually posted is this: "Sprint and T-Mobile will be getting the iPhone 4S. 'It's kind of a leap-frog system where AT&T/Verizon take turns getting the newer model first, then with Sprint/T-Mobile' [the quote is from one of TalkAndroid's sources, who are "some people in the Sprint store"]."
TalkAndroid helpfully explains What It All Means. "What this is basically saying is that the iPhone 5 will probably be out first on AT&T/Verizon, and then Sprint/T-Mobile." In other words, Apple's alleged "leap-frog system" will have future iPhone models being released first on alternating pairs of carriers.
And for the record, TalkAndroid also thinks Sprint is getting something called iPhone 4S.
iPhone 5, and other iOS 5 devices, with iMessage means the end of SMS as we, and the carriers, know it.
"Apple iMessage an unexpected shock to carriers: Goodbye SMS cash-cow" screamed the Slashgear headline. Carriers were "blindsided" by this new messaging feature in iOS 5, the story reports, threatening the carriers' one really profitable revenue stream: SMS and MMS messaging.
The Slashgear "story" is based on one, brief blogpost by John Gruber, who writes the Daring Fireball blog. Gruber's post was a link to a MacRumors story on iMessage, and offered one comment and a parenthetical note. iMessage, Gruber wrote, "means iPhone users with iPhone-using friends and family no longer need SMS. I'll cancel my SMS plan as soon as this ships."
He concluded with a parenthesis that a "well-informed little birdie tells me that Apple's phone carrier partners around the world found out about iMessages when we did: during today's keynote [Monday, June 6, at Apple's Worldwide Developers Conference]."
The next rumor will be: As mobile carriers go bankrupt due to the loss of SMS revenues, Apple plans to deploy and run its own free, nationwide 4G cellular network.
There will be two iPhone 5 models, and two iPad 3 models. And iPhone 5 will be announced in September.
More "sources" spent some time sifting through USB device files in the beta iOS 5 firmware and shared what they what discovered with TUAW.com.
"TUAW sources inspecting the USB device files in yet-unreleased iOS 5 firmware have discovered suggestions of two future iPad 3 models as well as a pair of iPhone 5 models. What's most surprising is a big omission: no mention of an iPod touch 5."
The system files showed declarations referencing "iPad3,1" and "iPad3,2" as well as "iPhone4,1" and "iPhone4,2." Aha, you exclaim. How can the iPhone 5 be an iPhone 4?
TUAW has it figured out. "The iPhone 5 will be a 4th generation unit because the iPhone 3G was technically 1st generation," TUAW says. "This throws off the numbering and confuses everyone, so don't fret if you were confused." Or if, after that, you still are.
No mention of an iPod touch 5 shows the iPhone 5 will be announced in September! Here's the reasoning behind that, from International Business Times' Carl Bagh: "Apple customarily releases the iPod refresh in September. Since the iPod touch is not mentioned in the firmware, it seems the iPod refresh meet will be used by Apple to launch the iPhone 5."
Talk about QED.
iPhone 5 pricing will be the same or lower than iPhone 4.
That welcome rumor comes from OnlineSocialMedia.com, although it's not based on much more than wishful thinking.
This rumorwish notes that the iPhone 4 prices were $199 or $299, depending on storage capacity, subsidized by the carrier (and $499 and $599 for the unsubsidized models).
"We think it's likely then, given Apple's recent efforts to keep prices lower, that the iPhone 5 will be the same price on release as the iPhone 4 was (although it has recently been cut)," according to OSM. "In fact Apple could surprise us further by making prices at least $50 cheaper."
"Bear in mind here that the new Mac OS X Lion that was announced on Monday will have a price of only $29.99, and also Apple's iCloud was unveiled and will be completely free so this also shows that Apple is trying to shed its reputation for high-priced products," OSM confidently concludes.
At this rate, driven inexorably by Moore's Law, Apple will be paying users to buy iPhone 10.
iPhone 5 will unquestionably have an 8 megapixel camera.
The staff at International Business Times knows the difference between a mere rumor and a confirmation. "Now, it looks like the 8 megapixel camera is one feature that's finally confirmed," the site reports. And why? Because DigiTimes reports, citing "market source," that "OmniVision has grabbed a majority of total CMOS image sensor orders placed by Apple for the fifth-generation iPhone."
DigiTimes clearly is still confused about iPhone numerology even after it was explained by TUAW.