Showing posts with label devices. Show all posts
Showing posts with label devices. Show all posts

Tuesday, 12 April 2011

GCHQ says BlackBerry is safest

Mobile
BlackBerrys are the only recommended smartphones for handling highly sensitive Government data, according to a GCHQ division.

The UK's National Technical Authority for Information Assurance at GCHQ (CESG) has published smartphone security guidance for public sector workers.

The advice published today covers various phones, including the Apple iPhone, Windows Phone 7 devices, Nokia hardware and BlackBerrys.

Four security procedures documents have been produced, outlining how to best secure any mobile deployment for UK Government departments and organisations on those platforms.

“These security procedures cover architectural issues (such as recommended network layout, recommendations for operational monitoring), configuration advice, user education and training suggestions, and information on residual risks that senior risk owners will need to take into account,” a CESG spokesperson told IT PRO.

“The publication of this risk management advice and guidance is intended to ensure all UK Government organisations have access to the information they need to take educated risk management decisions when deploying remote working solutions using smartphones.”

CESG worked with the telecoms industry to produce the report on how to secure smartphones for remote working, covering lower risk situations.

The guidance document itself was not available to the press.

CESG claimed the document will help many parts of the public sector work more efficiently and effectively, in turn saving money for the taxpayer.

As for more handling serious data, however, the GCHQ body said the only way was BlackBerry.
“The BlackBerry Enterprise Solution from Research In Motion remains the only smartphone system to have been formally evaluated by CESG and is approved to protect material classified up to and including ‘restricted,’” CESG said.

RIM was unsurprisingly buoyant about that particular comment, as a host of supporters talked about BlackBerry security credentials.

“The BlackBerry platform remains, in my opinion, the leader in this respect, providing the highest levels of assurance without the added cost or complexity of needing to bring third-party software into the equation,” said Nick McQuire, director for enterprise mobility at analyst house IDC.

BlackBerry devices are not infallible of course, as the recent Pwn2Own contest highlighted when a Torch 9800 was successfully hacked.

“The reality is that BlackBerry does have more enterprise features and controls such as remote kill, email retention, guaranteed message deliver with application and encryption controls,” said Ron Gula, chief executive (CEO) of Tenable Network Security.

“However, while this is important, a lot of it is just details, and we'll probably see some leapfrogging between the various mobile vendors as they get bitten and react.”

[ITPro]

Thursday, 3 March 2011

Keep Your Mobile Devices Secure While Traveling


From coffee shops to planes, trains, and cruise ships, we've become accustomed to having ready access to the Internet just about anywhere. The problem is, it's easy to forget how vulnerable that makes us to security threats.

I learned this the hard way recently when traveling from San Jose to Tampa, passing through four cities along the way. Even though I'm well aware of the potential for others to hack into my devices, I'd never had any problems previously. Unfortunately, there's always a first time: When I got back home, Facebook alerted me to some suspicious activity. I had been "Firesheep'd"!

Apparently someone in Chicago (using Firefox and a Windows PC) had logged into my Facebook account via Firesheep, a Firefox extension that can intercept unencrypted cookies from certain Websites on any open Wi-Fi network, making it possible to steal login credentials for sites like Facebook and Twitter, or even access your e-mail.

Think it can't happen to you? Think again. Fortunately, a combination of plain old common sense and some technology can protect your devices--quickly and fairly easily.

How Your Gadgets May Be Vulnerable

Whether you're traveling with a laptop, netbook, smartphone, iPad, or all of the above, the risks and defenses against them are basically the same, according to Joe Nocera, an information security expert and a principal with PricewaterhouseCoopers. "Many of the security concerns that people think about when they think about their personal computers are applicable in the mobile world." As mobile devices become more sophisticated, they lend themselves to the same types of access to e-mail, passwords, and other secure information that PCs have done in the past.

Because today's devices are so much more powerful and can hold so much more information than ever before, the risks are increasing, says Martin Hack, information security expert and executive vice president of NCP Engineering, a software company that helps businesses with their secure remote access systems. Add to that our tendency to carry both personal and business information around with us on the same device, and our mobile devices have never looked so appealing to hackers, he says.

As specific mobile devices become more popular, they become more of a target for hackers. "Five years ago, the vulnerabilities were Microsoft-based and targeting PCs. Apple tended not to be targeted so often," says Nocera. 

"But, in the last year and a half or so, we're seeing a shift. More and more often we're seeing either Android- or iPhone-based vulnerabilities being targeted. We predict that by 2014 you'll see those types of vulnerabilities being the most targeted as more and more users go to those mobile devices."


The good news is it's not difficult or even expensive to protect your devices and the information on them. The fixes are simple. The problem, stated quite eloquently in an old Pogo comic strip, is: "We have met the enemy and he is us."

10 Tips for Keeping Your Mobile Devices Secure

1. Make sure your software is up-to-date. The first line of defense, says Nocera, is making sure that all your software is up-to-date. "Almost every release of software patches a number of security vulnerabilities that are out there," he says. Before every trip, or at least every few weeks, it's a good idea to check the manufacturer's Web site (or search Google) to see if a software or firmware update is available. If there's a new one, download it, unless there's a massive firestorm of negative reviews from early adopters.

2. Employ strong passwords. "Be sure to use some combination of letters, numbers and/or special characters of 8 characters or more," says Jeremy Miller, director of operations for Kroll Fraud Solutions. "Avoid using dictionary words. Instead, [use] acronyms for things like favorite songs, restaurants or other items known only to you. And change the password frequently--at least once every six months." If you're just not feeling clever enough to create your own passwords, programs like RoboForm will do it for you.

3. Don't mess with the security settings. Nocera notes that most of the default browser settings in Android, iPhone, and Blackberry phones are fairly secure out of the box. "I recommend not going in to change browser security settings--they're pretty good already," he says.

4. Avoid unencrypted public wireless networks. Such Wi-Fi networks require no authentication or password to log into, so anyone can access them--including the bad guys. In some cases, bad guys set up an open network to snare unsuspecting people. Encrypted networks, on the other hand, are those that require an ID or password for access--you'll find such networks at many hotels and coffee shops that offer Wi-Fi services. These networks have two different types of security--WEP (wired equivalent privacy) and WPA (Wi-Fi protected access); the second is most secure. Even encrypted networks, though, have risks--it's possible for bad guys to gain access to encrypted networks at a hotel or café, for instance, so be cautious about the sorts of things you do on such networks.

Besides avoiding connecting to unencrypted networks, turn off Wi-Fi when you're not using it. This will prevent you from automatically connecting to networks (and it will extend your device's battery life).

5. Paying to access a Wi-Fi network doesn't mean it's secure. Access fees do not equal security. Just because you pay a fee to access a Wi-Fi network doesn't mean that the network is secure.

6. URLs beginning with 'https:' are safer (but not foolproof). Whenever you're accessing a site where you'll be sharing personal or confidential information--your bank's site, for example--you want to make sure that you're doing so securely. The s in https means that you're connected to the site via the Secure Socket Layer (SSL). In layman's terms, this means that all data transmitted to that particular Website over the Internet is encrypted.

SSL is not foolproof though: If you're on an unencrypted network connection, you may still be subject to man-in-the-middle (MITM) attacks, a form of eavesdropping where the bad guy makes a connection independently with two parties and then "gets in the middle," making both believe that they are talking directly to each other.

These types of attacks are rare, but to guard against them, make sure you're both connected to a secured network and that Websites use https when you're entering sensitive information.

In addition, says Nocera, most e-mail service providers have both a clear text option (that sends unencrypted data) and an encryption (SSL) option. "Make sure you have the SSL option enabled," he says.

7. Use VPN. If you have access to a VPN (virtual private network), use it. A VPN provides secure access to an organization's network and allows you to get online behind a secure layer that protects your information.

8. Turn off cookies and autofill. If your mobile device automatically enters passwords and login information into Websites you visit frequently, turn that feature off. It's convenient, but it can also be a privacy threat. To get back some of the convenience that autofill offers, you can try third-party apps, available for most platforms, that can manage saved passwords with a higher level of security. Mac OS X, for instance, comes with a built-in password manager--Keychain. KeePass is a free, open-source password manager for some versions of Windows. For iOS and Android smartphones, there's LastPass, 1Password, and SplashID. Using them is not as secure as turning off autofill altogether, but it's one way to strike a good balance. In the end, a little inconvenience can go a long way toward added security.

9. Watch your apps! Apps are great, and many are free, so it can be tempting to download with abandon. But, Nocera cautions, you should be selective about the apps you download, particularly in the Android market, because "the Android app market is a little bit more open," without the strict developer guidelines found in Apple's App Store. Do some due diligence before downloading apps. Make sure that you trust the developer and have taken the time to review some of comments.

TaintDroid is an Android tool that can identify apps that transmit private data and notify users that a third-party application is requesting private information. However, it's not an app that's offered through the Android Market. Instead, users have to manually compile and build the app using the framework provided by an app analysis company.

If You Still Get Hacked...

If you do everything right and still have your information stolen, what should you do? The damage can often be repaired simply by changing your password (to one much stronger) and sending a message via the network that was affected, explaining what happened. What if one of your devices gets stolen? Be sure that all of your mobile devices have a remote wipe or autowipe feature. For Apple's iPhone and iPad, there's Apple's MobileMe service. 

GoogleApps offers a solution for Android as well. If your device is lost or you know there's been a breach, you can quickly and remotely perform a factory reset from any computer connected to the Internet, wiping out all of the device's data and even locking it indefinitely.

Private Smartphones, Tablets Threaten Office Networks

From the moment the first telecommuter logged into his work e-mail account from his personal computer, the line between work and home began to blur.

Today, thanks to mobile devices such as smartphones and tablets, we can surf the Web, send and receive e-mail and modify work documents from virtually anywhere.

Most smartphones and tablets are purchased by consumers for personal use. But many — even those on a family wireless plan — will also be used for work purposes both inside and outside the office.

This home/work overlap of mobile devices has created three major problems for the security industry as a whole.

Corporate IT teams can too easily lose control of the devices. Legal frameworks find it hard to demarcate between personal and corporate use. And security developers haven’t caught up with the new software.

Out of control


Smartphones and tablets streamline the way we communicate today. Forget about phone calls and e-mail -- these new devices make it easier to use social media, which is the way an increasing number of people, especially young adults, “talk” to each other.

However, the budgets of small or medium-size businesses often won’t cover networked mobile devices for anyone below top management levels.

So people bring their own devices to work and put them on the office network --- and, in many cases, don’t alert the IT or security departments about it.

Without knowing who’s accessing the network, or how often, it is difficult for a network administrator to make sure security policies are met.

The added risk of mobile devices is that they are easily lost or stolen. If the smartphone or tablet isn’t locked with password protection, outsiders will have access to potentially sensitive data and company e-mail messages.

IT departments do have options to protect corporate data on personal phones, said James Lyne, senior technologist at England-based security company Sophos.

“Platforms such as [Microsoft] Exchange can give administrators visibility of the types of devices users are using to access key services,” he said. “Acceptable use policies should also clearly outline users’ responsibilities: which devices are allowed, what security practices must be adhered to and how to notify IT if a device is lost or is otherwise compromised.”

If organizations don’t want employees using personal devices for business uses, devices can be restricted to services based on managed corporate assets, such as corporate-compliance software.

Many enterprises, however, will consciously allow users to mix personal and professional business on their smartphones or tablets. In these scenarios, it's critical that a security baseline is met and enforced.

No legal basis


Legal departments have their own challenges to face. Corporations have jurisdiction over company-owned devices, no matter how and where they are used. But privately owned devices aren’t as easily supervised.

In November, National Public Radio reported about a woman whose personal smartphone had been wiped clean by her employer. The remote wipe, which deleted everything on her phone, was a mistake, but the case raised the question of whether a company should have that much access to a personal device.

For corporate legal departments, it’s not clear which activities on a smartphone or tablet count as private use and which don’t.

What should legal departments be concerned about, and how should those concerns be passed along to the employee?

Lyne said mobile devices should be covered by the same compliance regulations as laptops or conventional computers. Loss of work-related data on a personal device is not acceptable.

“That said, the expectations of security controls on mobile devices are also less developed in many countries’ legal frameworks,” Lyne added. “Enterprises should make sure employees understand their obligations to manage and protect the device, but also should be conscious of the risk of data loss to their businesses. Where possible, minimize the flow of sensitive data to these device types to reduce the risk of loss.”

Hard to keep up

Mobile platforms present a new set of challenges to security, said Lyne. First of all, their presence greatly expands the number of operating systems – Android, BlackBerry, Apple’s iOS, HP’s WebOS -- that need to be protected.

“Microsoft operating systems have long been the primary focus area for security investment,” Lyne explained. “The broader set of platforms being used requires not only more coverage from solutions, but fundamentally protecting each of these devices is quite different in implementation and policy. These platforms, without standards, could increase the cost notably.”

Second, the mobility of these gadgets itself is a challenge. Each device constantly moves in and out of the network, and it almost certainly will be used for a blend of work and personal matters.

These changes in user behavior challenge conventional security policies, and will have a significant impact on the behavior of security technologies.

“The industry should not fall into the trap of trying to protect mobile devices with an identical model to the traditional computer,” Lyne said. “While security issues undoubtedly exist on these devices and we all need to recognize the likelihood of greater focus on these device by attackers, the threat vectors and protection model is different platform to platform.”

The immediate priority for businesses will be to manage the basic compliance of each mobile device.
Enterprises should know which devices are being used and ensure that password security, encryption and patching are all up to scratch.

Compliance is the key starting position for those looking to secure their mobile devices. However, as the threat evolves, so, too, will product requirements.

[SecurityNewsDaily]