Oh I totally agree! We have already seen smartphone botnets for hire - for example the Android malware known as notcompatible installs a proxy on devices it infects. While right now it is being used to evade geographic anti-fraud measures the reality is it is perfectly positioned to offer on-demand access to enterprises or even specific people (assuming they get a wide enough distribution of infected devices). Our smartphones are incredibly personal to us and that means we take them everywhere. The potential rewards for someone that manages to become an invisible passenger on a smartphone carried by a high value intelligence asset will be HUGE.