This morning I found a Webroot SecureAnywhere Mobile Complete screen up on my phone with 4 items it believes are threats. There is an "enter your password to continue" dialog but no good way to confirm it is from web root. Hitting the back button makes the password dialog go away, but it comes back when I next do something in the app. This seems to indicate it is a webroot thing, particularly since all 4 of the threats it detected are semi-false positives (the software does contain exploits, but it is part of a rooting toolkit and some analysis software which do actually utilize exploits legitimately).
It's a little odd though because I've previously marked those items as being safe, so I'm not sure why they are back again or why I'd be getting a password prompt this time. Was there some type of software update that changed system behavior? Is the dialog legitimate? As another feature suggestion, it might be good to have an ability to use OTPs for this kind of situation. Perhaps allow generation of a one time password from the webroot website that could be used from a known good computer that can be used when prompting on a potentially compromised device. Training users to enter their passwords in to a dialog they didn't initiate themselves is not a good practice.
(Additional wierd note, by continuously ignoring the prompt and hitting back, I was still able to add the software back to the ignore list and do everything I needed in Webroot, which seems extremely odd if it was promptingi me. The prompts stoped when I switched out of Webroot, so it seems like it was Webroot asking, but why was it asking if it wasn't actually needed?
Reply
Login to the community
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.