Showing posts with label Mobile Security. Show all posts
Showing posts with label Mobile Security. Show all posts

Saturday, July 6, 2013

Privacy and Smartphones


I feel a bit naive starting with the definition of a smartphone. A recent infographic by the Lebanese carrier "Touch" posted on their facebook page shows that 82.66 % of people using their mobile service are using either a Blackberry, an Iphone or an Andriod phone.

Anyways, a Smartphone is a small handheld electronic device that has features of both a mobile phone and a computer. This device allows us to communicate voice, text, and video, along with sending pictures, sending emails, managing bank accounts, and sharing locations.

Similar to PCs and Laptops, smartphones are currently equipped with powerful processors providing the user with high computing power. Yet unlike ordinary PCs and laptops, smartphone are always in our hand or in our pockets, their small size and easy mobility makes them man's best friend.

Privacy is a major concern to smartphone users; No matter what they do, there will always be seen and unseen pitfalls that may lead to the loss of privacy

Privacy Compromised:

Service Provider

By using a mobile phone, you can rest assured that your service provider is by default retaining log files that include:  
  • Incoming and outgoing calls: the phone numbers you call, the numbers that you receive calls from, and the duration of the call;
  • Incoming and outgoing text messages: the phone numbers you send texts to and receive texts from;
  • How often you check your e-mail or access the Internet;
  • Your location. (GPS / Cell usage)

In addition to the default data collected by your Smartphone service provider, you should also be aware of the possible privacy issues surrounding the collection or disclosure of:

  • Any photos or video you take on your phone;
  • The contacts you have stored in your phone;
  • Passwords;
  • Financial data;
  • What you store in your phone's calendar;


Picture Geo-tags

Depending on the brand and settings, your smartphone can use its built-in GPS capability to embed your exact location into the file of photos you take using the smartphone’s camera, this process is called geotagging. If you happen to share any geotagged picture, people can use the geotag to track your movements or find out where you live. 

Malware

Malware is malicious software that poses a threat to your smartphone just as it does to your computer. The apps on your smartphone are a rich environment for transmitting malware. Some malware care about stealing money (financial), other malware are concerned only with collecting data and transmitting it to a remote receiver.

Free Apps and Advertisers 

There are hundreds of thousands of applications for smartphones across all platforms, anyone can create an app. Most of these applications are free, free means cost free and not risk free. These apps can collect all sorts of data and transmit it to the app-maker and/or third-party advertisers. It can then be shared or sold.  Most free applications contain ads, to customize these ads up to the user preferences, personal date should be collected from the user‘s smartphone.

The privacy concern here is that information captured could be used to build a complete profile about you without your knowledge or approval.


Protect yourself 

1- Limit others' physical access to your Smartphone

A person who gains access to your smartphone can see all your private stuff or even worse they can physically install a malware capable of collecting data and then discretely transmit this data to other parties.

So in order to decrease the risk of privacy loss via physical access to your smartphone you should:
  • Password protect your phone; 
  • Do not allow your smartphone to automatically remember login passwords for access to email, VPN, and other accounts;
  • Use your phone’s security lockout feature. Set the phone to automatically lock after a certain amount of time not in use;
  • Install security software that allows you to remotely lock your phone and wipe the data;
  • Never leave your phone unattended. 


2- Usage of Public Wi-Fi Networks

When your smartphone uses a public Wi-Fi network to connect to the Internet (eg. coffee shop), it may be possible for others to “see” the data being transmitted by your smartphone so: 

  • Avoid the usage of untrusted public Wi-Fi networks 
  • If not possible, when using public and untrusted Wi-Fi networks. Do not conduct activities that use sensitive information such as mobile banking.

3- Mobile Security Software

Many individuals take great care to protect their computers with security software, but forget to do the same with their smartphones. Products from Eset, AVG, and McAfee may be able to:

  • Protect your smartphone against malware,
  • Back up your smartphone data, store data elsewhere
  • Track your phone if it is lost or stolen;
  • Lock your phone remotely, and wipe your data remotely.


4- Applications

Install applications only from trusted application sources. Read carefully what the application is trying to access before you install / use it, and only then decide whether to use this application or not. 

To most of us, the smartphones are the last thing we put from our hand before we sleep and the first thing we check when we wake up in the morning.  I think they deserve a little more caution on our part. 

Read more about Mobile Security


Friday, July 6, 2012

Securing Mobile Devices


Mobile devices are without doubt people's greatest friends. Whether it is a Ipod, an Ipad , a Blackberry, an Android phone, or even a symbian phone these devices accompany us wherever we go.
People usually underestimate the security flaws of their mobile phones, although current mobile phones have the same computing power of a normal PC, people fail to treat them with equal importance.

Here are seven Tips to Secure Data stored on your Mobile Device 

I. Use the PassCode
Nowadays, nearly all mobile devices are manufactured with the ability to set access control passcodes that prevent unauthorized access to the confidential data stored on these devices.

Choose a strong passcode that is easy for you to remember but hard for others to guess, and for God sake don’t use your birthday or your girlfriend birthday (even though u should always remember that date). Use a mixed combination of letters and numbers.

Security tip: Don’t use consecutive numbers and letters because they are very easy to be guessed and surprisingly commonly used.
Grid pattern locks work fine, and fun to use, but beware that they leave finger smudge marks on the mobile touch screen especially when using a protective layer shield. This smudge makes it easier to guess your pattern.

Recent mobile devices offer device encryption for their files and data, whether for their own internal memory or their multimedia memory card. Using device encryption is the best method to protect your data from being stolen through plugging your phone to a PC to transfer data. 

II. Careful Use of Wireless Networks
Mobile phones can be set up to connect to available public WIFI networks automatically; this improper setup allows the mobile phones to shake hands with an insecure environment that might compromise your data.

So when you are not connected to a trusted wireless network, turn off the WIFI ability on your phone.

Moreover, Bluetooth communication could be exploited to spread mobile malware and eventually leak confidential data from your mobile. It is imperative to turn of the Bluetooth service when not using it.
Security Tip: Recent phones have the option to automatically turn off Bluetooth when it is gets idle for 5 minutes, use it.


III. Applications Access and permissions
Apps installed on mobile phones have the ability to access sensitive data stored on the phone itself. In general when you initially setup an application on your mobile device it requests special access, like accessing your contacts and storing them in the cloud, tracking your location, and sending you push notifications.

Usually people have the tendency to accept these modifications without thoroughly reading their content and assessing their risks. You should setup the permission level of each application depending on the level of sensitivity of your stored data.

Note that:
- You can disable push notifications by changing the settings in your device options.
- You can deactivate location based services by turning them off from your device menu. This option will stop your phone from broadcasting your GPS location regardless of the app using it. 

IV. Backup your Data
Backing up your data is the most effective way to prevent data loss, Data loss could be the result of lost or stolen phone, damaged memory card, bad application setup leaking data or even human error by messing with phone options.

Copy your data from your mobile phone to your PC or Laptop, schedule routinely backup notification in order to keep your backup copy updated.

Security tip: remember to encrypt your backup copy. Recent mobile management application enables you to utilize encryption as part of the synchronization process.

V. Firmware updates
Similar to your PC operating system, Your Smartphone should be updated in order to overcome any newly known exploits that could compromise security.

Firmware upgrades is not only limited to security issues but also to performance enhancement of you mobile experience.

Security Tip: Commit to using firmware that is certified by the vendor of your mobile Device. Tampered (Custom made) firmware might contain malicious codes that compromise your information security


VI. Remote Device Access
Many of the recent mobile phones and smart devices give u the ability to wipe its data remotely. You should exercise that option if your phone gets lost or stolen.

Moreover, you can setup your phone to automatically wipe itself clean of any personal data should the PIN guarding your phone is entered incorrectly for a certain number of attempts.

Security Tip: Don’t forget to remove your media card before sending your phone to any repair station.


VII. Sensitive Financial Data
Storing Financial Data on the phone is a big mistake; mobile phones are easily stolen or lost. I know people that used to store credit card numbers on mobile phones; others store ATM pin codes. People should really understand that it is much easier to lose data from smart mobile devices than losing their own wallets. For a start you will directly notice a missing wallet, but you will only find out a theft of sensitive info such as credit card number only when it is used or billed.

Remember: You should be always aware of shoulder surfers that scan around in order to catch you enter your PIN or passcode.

Finally, good judgment and cautious behavior are key factors to prevent data leak or loss caused by mobile devices.