Showing posts with label smartphones. Show all posts
Showing posts with label smartphones. Show all posts

Thursday, 28 April 2011

Why Apple Collects Detailed Location Data from Your iPhone

All iSpy conspiracy bullshit aside, you are probably more interested in what your iPhone does with location data. Well, if you opt-in to the iPhone's location services, detailed—but anonymized—location data is transmitted back to Apple on a regular basis.

Gadget Lab reminds us of a letter Apple general counsel Bruce Sewell sent to a couple of Congressman last year explaining how and why Apple collects location data. (Wired's hosting the letter here.) Basically, if you've got Location Services turned on, whenever you request current location data (like via an app), Apple collects info about nearby cell towers and Wi-Fi hotspots. If you happen to be using GPS, it'll collect the GPS coordinates too. That data's then transmitted to Apple every 12 hours over "secure" Wi-Fi networks, anonymized with a "random identification number generated every 24 hours by an iOS device," so neither Apple nor anybody can personally identify you.

If you remember, Apple started doing its own location services last year (from iOS 3.2 onward), instead of using Google or Skyhook's location data. So, it needs to build and maintain its own database of known tower locations and Wi-Fi hotspots—that's where this info comes in. You're an official location scout for Apple, in other words. When your device asks where it's at, it hits up this database before zeroing in with GPS.

Not too crazy, though it doesn't make the ease with which your location history can be extracted from your Mac or iPhone any less unnerving. Also, it makes the lack of a purge after the data's transmitted to Apple seem more and more like a mere oversight.

More on this is at Gadget Lab: [Gadget Lab] via [Gizmodo]

Tuesday, 12 April 2011

GCHQ says BlackBerry is safest

Mobile
BlackBerrys are the only recommended smartphones for handling highly sensitive Government data, according to a GCHQ division.

The UK's National Technical Authority for Information Assurance at GCHQ (CESG) has published smartphone security guidance for public sector workers.

The advice published today covers various phones, including the Apple iPhone, Windows Phone 7 devices, Nokia hardware and BlackBerrys.

Four security procedures documents have been produced, outlining how to best secure any mobile deployment for UK Government departments and organisations on those platforms.

“These security procedures cover architectural issues (such as recommended network layout, recommendations for operational monitoring), configuration advice, user education and training suggestions, and information on residual risks that senior risk owners will need to take into account,” a CESG spokesperson told IT PRO.

“The publication of this risk management advice and guidance is intended to ensure all UK Government organisations have access to the information they need to take educated risk management decisions when deploying remote working solutions using smartphones.”

CESG worked with the telecoms industry to produce the report on how to secure smartphones for remote working, covering lower risk situations.

The guidance document itself was not available to the press.

CESG claimed the document will help many parts of the public sector work more efficiently and effectively, in turn saving money for the taxpayer.

As for more handling serious data, however, the GCHQ body said the only way was BlackBerry.
“The BlackBerry Enterprise Solution from Research In Motion remains the only smartphone system to have been formally evaluated by CESG and is approved to protect material classified up to and including ‘restricted,’” CESG said.

RIM was unsurprisingly buoyant about that particular comment, as a host of supporters talked about BlackBerry security credentials.

“The BlackBerry platform remains, in my opinion, the leader in this respect, providing the highest levels of assurance without the added cost or complexity of needing to bring third-party software into the equation,” said Nick McQuire, director for enterprise mobility at analyst house IDC.

BlackBerry devices are not infallible of course, as the recent Pwn2Own contest highlighted when a Torch 9800 was successfully hacked.

“The reality is that BlackBerry does have more enterprise features and controls such as remote kill, email retention, guaranteed message deliver with application and encryption controls,” said Ron Gula, chief executive (CEO) of Tenable Network Security.

“However, while this is important, a lot of it is just details, and we'll probably see some leapfrogging between the various mobile vendors as they get bitten and react.”

[ITPro]

Friday, 1 April 2011

Hackers target business secrets

Filing cabinet, Eyewire Many net-savvy thieves are scouring corporate networks for saleable secrets


Intellectual property and business secrets are fast becoming a target for cyber thieves, a study suggests.

Compiled by security firm McAfee, the research found that some hackers are starting to specialise in data stolen from corporate networks.

McAfee said deals were being done for trade secrets, marketing plans, R&D reports and source code.
It urged companies to know who looks after their data as it moves into the cloud or third-party hosting centres.

"Cyber criminals are targeting this information based on what their clients are asking for," said Raj Samani, chief technology officer in Europe for McAfee.

He said some business data had always been scooped up when net thieves compromised PCs using viruses and trojans in a search for logins or credit card details.

The difference now was that there exists a ready market for the data they are finding. In some cases, said Mr Samani, thieves were running campaigns to get at particular companies or certain types of information.

The McAfee report mentioned cases in Germany, Brazil and Italy in which trade secrets were either stolen by an insider or cyber thieves tried to get hold of via a concerted attack.

In some cases, said the McAfee report, companies made the job of the criminals easier because they did little to censor useful information about a corporate's culture or structure revealed in e-mails and other messages.

Such information could prove key for thieves mounting a "social engineering" in which they pose as employees to penetrate networks.

The report detailed efforts by firms to watch casual and contract employees and the use of behavioural analysis software to spot anomalous activity on a corporate network.


Perimeter defences

Thefts of intellectual property or key documents could be hard to detect, said Mr Samani.

"You may not even know it's stolen because they just take a copy of it," he said.

Defending against these threats was getting harder, he said, because key workers with access to the most valuable information were out and about using mobile devices far from the defences surrounding a corporate HQ.

"Smartphones and laptops have crossed the perimeter," said Mr Samani.

The report comes in the wake of a series of incidents which reveal how cyber criminals are branching out from their traditional territory of spam and viruses.

2010 saw the arrival of the Stuxnet virus which targeted industrial plant equipment and 2011 has been marked by targeted attacks on petrochemical firms, the London Stock Exchange, the European Commission and many others.

Mr Samani said that, as firms start to use cloud-based services to make data easier to get at, they had to work hard to ensure they know who can see that key corporate information.

Otherwise, he warned, in the event of a breach, companies could find themselves losing the trust of customers or attracting the attention of regulators.

"You can transfer the work but you cannot transfer the liability," said Mr Samani.

[BBC]

Thursday, 24 March 2011

Mobile Phones are Being Hacked and Cloned

Cloning occurs when hackers scan the airwaves to obtain SIM card information, electronic serial numbers and mobile identification numbers, and then using that data on other phones.

Cloning can happen anywhere, anytime that you’re using your phone. The bad guy simply uses an interceptor, hardware, and software to make a phone exactly like yours.

A few years ago, I was in San Diego on business. Two weeks later I received a call from my carrier alerting me to $1500.00 worth of international calls I had not made. The activity triggered an alert within their system and they shut my account down.

Fortunately for me, my carrier recognized the fraud and relieved me of the charges, rather than me discovering it and having to fight to reverse the charges. Apparently, it was a known issue that scammers in Tijuana were cloning U.S.-based phones.

Anita Davis, another mobile clone victim, wasn’t so lucky. One month, her cell phone bill showed $3,151 worth of calls in one month, to Pakistan, Israel, Jordan, Africa, and other countries.

Anita called her carrier immediately and told them she didn’t know anyone in those countries, or anyone outside the U.S. for that matter.

She says, “They told me I had to have directly dialed these numbers from my cell phone and I needed to make a payment arrangement or they would send my bill to collections.”

After begging and pleading, Anita convinced them to drop the charges.

The extent of your vulnerability varies depending on your phone and the network you’re on. Cloning mobile phones is becoming increasingly difficult, but consumers can’t do anything to prevent it from happening.

The best way to mitigate the damage is to watch your statements closely. The moment you see an uptick in charges, contact your carrier and dispute the calls.


Robert Siciliano, personal security expert contributor to Just Ask Gemalto, discusses mobile phone spyware on Good Morning America. (Disclosures)

[InfoSecIsland]

Lock Down Your Life: How to Secure Your Home, Auto and Smartphone

The more sophisticated technology gets, the more sophisticated the criminals get.
Because of that, protecting yourself and your family these days involves a lot more than just making sure the front door is locked and that you haven't left the keys in the car.

Smartphone owners, for example, are increasingly the target of the same sorts of attacks and scams — many of which can result in identity theft — that have been plaguing computer users for years.
Users of Android-based phones users recently learned that more than 50 malicious apps had been uploaded to the Android Market app store, and then installed on roughly 260,000 phones within a few days.

(Google yanked the apps from the Android Market, then used its “kill switch” to remotely remove the installed apps from users’ phones; Apple has a similar “kill switch” for iPhones and iPads.)

Landlines can also be hit by scams, such as the call-forwarding *72 attack in which a stranger tricks the victim into forwarding all incoming calls to another number — and then proceeds to rack up charges on the account.

Even cars, which have security systems built into nearly all new models, continue to be a major target. According to the National Insurance Crime Bureau, a vehicle is stolen every 33 seconds in the United States.

And, of course, home break-ins continue. The FBI reports that in 2009, the most recent year with confirmed data, there were 2.2 million burglaries in the U.S., costing victims an estimated $4.6 billion in lost property.

So how can you protect yourself from scams and break-ins?

In addition to writing down the vehicle-identification number of your car and serial numbers for expensive equipment, such as a flat-screen TV or computer, there are several ways to protect everything from your phone to your home using some relatively simple technology.

Smartphones: For your smartphone, first make sure you've enabled password protection. Then consider a "lost phone" tracking app, as well as anti-virus/malware software.

There are several on the market, including one from Lookout Mobile Security. A free version is available for Android and Blackberry phones, and it includes a lost/stolen-phone location service and virus scanning. If you can't get your phone back, it will also remotely wipe your personal info from the device.

Credit: Lookout, Inc.

A premium version, for $29.99 a year, includes privacy tracking and protection.

Vehicles: Car and truck owners can also take advantage of GPS tracking and warning devices. For GM owners, there's the OnStar service, but any car can be outfitted with similar security and tracking features.

LoJack has an Early Warning Package for $995 (installed). If your car is moved, the LoJack network can send a phone, email or text message alert.
Credit: Lojack


However, LoJack is available only in 29 states. For nationwide coverage, there's the Escort EntourageCIS, $400, plus $60 for installation and a $180-a-year subscription.
Credit: Escort, Inc.

Like LoJack, the EntourageCIS can warn a driver via email, text or phone message if a car is moved. More important, if your car is stolen and you don’t respond to alerts, a 24-hour monitoring station will contact local law enforcement and send them after the thieves.

Home: As the summer approaches and more home owners leave for long vacations, alarms and monitoring services can be useful. As an alternative to calling in a professional (and paying monthly fees), you now have the option of installing your own cameras and monitoring equipment.

Among the raft of do-it-yourself equipment now available is the $300 Logitech Alert 750i Master System. The video-based monitoring system can be installed in about 30 minutes and uses a home's electrical circuits to connect to a home network and the Internet.

Credit: Logitech

Using a Web browser, owners can log in any time for free to see and hear what's going on back home, or they can have email alerts sent to them whenever motion is detected.

Some people may find all this monitoring and scanning technology brings with it a touch of paranoia.

But, if you're ever the victim of a burglary or lose your phone, you won't seem so paranoid any more.

[SecurityNewsDaily]

Second hand phones contain extensive personal data

People are unsuspectingly selling their personal information to complete strangers as a new report from CPP finds half (54%) of second hand mobile phones contain extensive personal data.



Second hand mobile phones and SIM cards purchased on eBay and used electronics shops by CPP were examined in a live experiment to see what personal information was available on the handsets and whether it constituted a threat to their former owners' identities.

The experiment revealed 247 pieces of personal data that had been carelessly left on a range of mobile phones and SIM cards. The personal data included credit and debit card PIN numbers, bank account details, passwords, phone numbers, company information and log in details to social networking sites like Facebook and LinkedIn.

In research that supported the experiment, half of second hand mobile owners said they have found personal information from a previous owner on mobile phones and SIM cards they have purchased second hand.

Worryingly, the vast majority (81 per cent) of people claim to have wiped their mobiles before selling them, with six in ten confident they have removed all of their personal information from them. However, the experiment revealed that 54 per cent of mobile phones and SIM cards contained sensitive personal information putting people at unnecessary risk of identity and card fraud.

The variance could be explained by the fact that most people who claimed to have 'wiped' their handsets tried to erase the data manually – a process that security experts acknowledge leaves the data intact and retrievable.

And it seems personal information comes cheap with individuals selling their old handsets and SIMs for an average price of 47 pounds Sterling.

As people rely heavily on their mobile phones to store personal data such as e-mail addresses, social networking log in details, banks account details and even debit and credit card PIN numbers, CPP is calling on people to make sure they remove all of their personal and financial information from their mobile phones and undertake adequate security measures to protect themselves from identity theft.

Senior Vice President of CRYPTOCard Jason Hart said: "The safest way to remove all of your data from a mobile phone or SIM card is to totally destroy the SIM and double check to ensure that all content has been removed from your phone before disposal. With new technology does come new risks and our experiment found that newer smartphones have more capabilities to store information and that information is much easier to recover than on traditional mobiles due to the increase of applications."

[Net-Security]

Wednesday, 23 March 2011

Most users unaware of smartphone security risks

Consumers are indifferent to the many serious security risks associated with the storage and transmission of sensitive personal data on iPhone, Blackberry and Android devices, according to The Ponemon Institute.



Following are three of the most alarming results of the survey:
  • 89 percent of respondents were unaware that smartphone applications can transmit confidential payment information such as credit card details without the user’s knowledge or consent.
  • 91 percent of respondents were unaware that financial applications for smartphones can be infected with specialized malware designed to steal credit card numbers and online banking credentials, yet nearly a third (29 percent) report already storing credit and debit card information on their devices and 35 percent report storing “confidential” work related documents as well.
  • 56 percent of respondents did not know that failing to properly log off from a social network app could allow an imposter to post malicious details or change personal settings without their knowledge. Of those aware, 37 percent were unsure whether or not their profiles had already been manipulated.
Other smartphone security dangers include geo-tracking based on location data embedded onto image files; the transmission of confidential payment information without the user’s knowledge or consent; and unauthorized (and often unnoticed) premium-service orders on the monthly bill.


"The findings of this study signal what could be an overlooked security risk for organizations created by employees' use of smartphones. Because consumers in our study report that they often use smartphones interchangeably for business and personal, organizations should make sure their security policies include guidelines for the appropriate use of smartphones that are used for company purposes," said Dr. Larry Ponemon, chairman and founder of Ponemon Institute.

According to the study, 28 percent of respondents were unaware that using their smartphone for business and personal reasons can put business information at risk.

[Net-Security]

Friday, 4 March 2011

ZeuS Targets Mobile Users

As early as 2006, Trend Micro already recognized the fact that the BlackBerry technology could be exploited by cybercriminals. The smartphone may have remained spared from malware attacks over the years although there have been recent news of a ZeuS variant specifically targeting BlackBerry users. As we have said in a recent post, banking Trojans are evolving and more sophisticated attacks involving smartphones are among the most recent developments.

The ZeuS malware specifically targeting the BlackBerry OS is currently detected by Trend Micro as BBOS_ZITMO.B. Just like its desktop counterpart, this ZeuS variant does not display any graphical user interface (GUI) that can prompt users about the infection. Instead, it removes itself from the list of applications, in order to effectively stay under the radar.
Upon successful installation, it sends a confirmation message to the administrator to signal that it is ready to receive commands. It specifically sends the message “App Installed OK” to the U.K. number +447{BLOCKED} as seen in the screenshot below.
Click for larger view

BBOS_ZITMO.B also allows the attacker to remotely change the number to which it forwards SMS messages sent to the affected phone, also known as the administrator number. Thus, in the event that the original administrator number is tracked down and becomes unavailable, the attacker can just send a command to change the administrator number and continue receiving the forwarded messages.

Based on our analysis, BBOS_ZITMO.B is capable of carrying out the following commands:
  • Display SMS: Unmonitored SMS will be treated as a normal SMS and will be displayed on the phone.
  • Delete/Drop SMS: SMS from hacker will not be seen by the user.
  • Forward SMS: Send SMS to hacker without the user’s knowledge.
  • Block Calls
  • Remove Block Calls
  • Set Administrator: Register a new administrator.
  • On/Off
  • Add Sender
  • Remove Sender
  • Set Sender
  • Block/Unblock Phone Numbers
Other smartphone OSs are not immune to this threat either. Variants targeting smartphones running Symbian (SYMBOS_ZBOT.B) and Windows Mobile (WINCE_ZBOT.B) have also been spotted with behaviors that are very similar to those exhibited by BBOS_ZITMO.B.

With the increased popularity of mobile banking goes the increase of mobile threats. Thus users are strongly advised to keep their mobile devices secure, and be cautious in installing applications and clicking links sent by unknown users, as they may lead to the download of malicious applications.

[TrendMicro]