Showing posts with label andriod. Show all posts
Showing posts with label andriod. Show all posts

Tuesday, February 4, 2014

Mobile Malware Milestone

Did you celebrate or castigate?

You might not know but last week was the 10 year birthday of Cabir, the first mobile malware. It spread through Bluetooth after infecting the Nokia Series 60 phones running Symbian. Also last week, Kindsight Security Labs (Alcatel-Lucent) released the results of a study (pdf) that found more than 11.6 million mobile devices are infected by mobile malware at any given time and that mobile infections increased 20% globally in 2013.

This, obviously, increases risk for stolen personal and financial information, can lead to bill shock resulting from hijacked data usage, or extortion to regain control of the device along with allowing bad guys to remotely track location, download contact lists, intercept/send messages, record conversations and best of all, take pictures.

About 60% of all mobile infections involved Android devices that downloaded malicious software from the Google Play store and 40% were Android phones that received malicious code while tethered to a Windows laptop. Both Blackberry and iPhone combined to represent less than 1% of all infected devices. 4G LTE devices are the most likely to be infected and the number of mobile malware samples grew 20X in 2013. This will only get worse as new strains are released, like the proof of concept code that is capable of tracking your taps and swipes as you use a smartphone.  That's right, monitor touch events. Say a phone has not been touched in a while and suddenly there is 4 touch events. Well, that's probably a PIN, according to Forbes contributor Tamlin Magee. Add to that a screenshot, now you can overlay the touches with the screenshot and know exactly what is being entered.

You know it and I know it: The more we become one with our mobile devices, the more they become targets. It holds our most precious secrets which can be very valuable to some. We need to use care when operating such a device since, in many ways, our lives depend on it. And it is usually around this point in the article that I chastise mobile users for careless behavior but in this instance, there are certainly times where there is nothing you can do. You can be paranoid, careful and only visit the branded app stores yet the risk is still present.

Ten years in and we're just getting started.

ps

Related:

 

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Tuesday, March 26, 2013

Q. The Safest Mobile Device? A. Depends

Depends?!?  Well, isn't that the answer to a lot of things in this world?  Often our answer depends on the context of the question.  Sometimes the answer depends on who you ask since it may only be an opinion or a feeling.  Sometimes the answer is based on a survey, which is a moment in time, and might change a day later.  I write a lot about secure mobile access, especially to the enterprise, so I'm obviously interested in any stories about the risks of mobile devices.  There were a couple over the last few weeks that really caught my attention since they seemed to completely contradict each other. 

Earlier in the month, SC Magazine had a story titled, RSA 2013: iOS safer than Android due to open app model, patching delays which covered much of what many already feel - due to Apple's controlled ecosystem, the apps that are available are less of a risk to a user.  They made note of the McAfee Threats Report which says Android malware almost doubled from the 2nd to 3rd quarter of 2012.

Then just last week, also from SC Magazine, an article titled, Study finds iOS apps to be riskier than Android appeared.  What?  Wait, I thought they were safer.  Well, no apparently.  But before I go any further, I do need to mention that the author of both articles, Marcos Colon (@turbomarcos)does reference his first article and says, 'Security concerns surrounding the Android platform have always taken a back seat to that of iOS, but a new study challenges that notion,' so slack has been extended.  :-)  Anyway, according to an Appthority report, iOS apps pose a greater risk and has more privacy issues (to users) than Android.  Appthority's 'App Reputation Report' looked at 50 of the top free apps available on both platforms and investigated how their functionality affects user privacy.  They looked for “risky” app etiquette like sending data without encryption, sharing information with 3rd-parties, and gaining access to the users' calendars.  (Chart)

In this particular study, in almost all the cases, iOS gave access to the most info.  Of the 50 apps, all of them (100%) sent unencrypted data via iOS but 'only' 92% sent clear text on Android.  Tracking user location: 60% on iOS verses 42% on Android.  Sharing user data with third-parties: 60% on iOS verses 50% on Android.  When it comes to accessing the user's contacts, something we really do not like, 54% of iOS apps accessed the contact list compared to only 20% on Android.  One of biggest differences, according to the article, is that at least on Andriod users are presented with a list of content the app wants to hook and the user can decide - on iOS, permissions can be changed once the app is installed. 

To claim one device is either 'safer,' or 'riskier' is somewhat a moot point these days.  Any time you put your entire life on a device and then rely on that device to run your life, there is risk.  Any time we freely offer up private information, there is a risk.  Any time we rely on others to protect our privacy and provide security, there is a risk.  Any time we allow apps access to personal information, there is risk.  But like any potential vulnerability, individuals and organizations alike, need to understand the potential risk and determine if it something they can live with.  Security is risk management.

To top all this off and really what made me write this, was an @GuyKawasaki tweet titled Love Logo Swaps and among the many twists on brands, was this one:

And it all made sense.

ps

Related:

 

Connect with Peter: Connect with F5:
o_linkedin[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Wednesday, October 17, 2012

BYOD Policies – More than an IT Issue Part 2: Device Choice

#BYOD or Bring Your Own Device has moved from trend to an permanent fixture in today's corporate IT infrastructure. It is not strictly an IT issue however. Many groups within an organization need to be involved as they grapple with the risk of mixing personal devices with sensitive information.  In my opinion, BYOD follows the classic Freedom vs. Control dilemma. The freedom for user to choose and use their desired device of choice verses an organization's responsibility to protect and control access to sensitive resources. While not having all the answers, this mini-series tries to ask many the questions that any organization needs to answer before embarking on a BYOD journey.

Enterprises should plan for rather than inherit BYOD. BYOD policies must span the entire organization but serve two purposes - IT and the employees. The policy must serve IT to secure the corporate data and minimize the cost of implementation and enforcement. At the same time, the policy must serve the employees to preserve the native user experience, keep pace with innovation and respect the user's privacy.  A sustainable policy should include a clear BOYD plan to employees including standards on the acceptable types and mobile operating systems along with a support policy showing the process of how the device is managed and operated.

Some key policy issue areas include: Liability, Device choice, Economics, User Experience & Privacy and a trust Model.  Today we look at Device Choice.

Device Choice

People have become very attached to their mobile devices. They customize and personalize and it's always with them, to the point of even falling asleep with the device. So ultimately, personal preference or the 'consumerization of IT' notion is one of the primary drivers for BYOD. Organizations need to understand, what devices employees prefer and what devices do employees already own. That would could dictate what types of devices might request access. Once organizations get a grasp on potential devices, they then need to understand each device's security posture.

About 10 years ago, RIM was the first technology that really brought the Smartphone into the workplace. It was designed to address the enterprise's needs and for years was the Gold Standard for Enterprise Mobility. Management control was integrated with the device; client certificate authentication was supported; Active Directory/LDAP servers were not exposed to the external internet; the provisioning was simple and secure; organizations could manage both Internet access and intranet access, and IT had end point control.

When Apple's iPhone first hit the market, it was purely a consumer device for personal use and was not business centric, like the BlackBerry. Initially, the iPhone did not have many of the features necessary to be part of the corporate environment. It was not a business capable device. It did not support applications like Exchange, which is deployed in many organizations and is critical to a user's day-to-day activities. Over time, the iPhone has become a truly business capable device with additional mechanisms to protect end users.  Android, very popular with consumers, also offers numerous business apps but is susceptible to malware.

Device selection is also critical to the end user experience. Surveys show that workers are actually more productive when they can use their personal smartphone for work. Productivity increases since we prefer to use our own device. In addition, since many people like to have their device with them all the time, many will answer emails or do work during non-work hours. A recent survey indicated that 80% of Americans work an extra 30 hours a month on their own time with BYOD. But we are much happier.

A few blogs ago, I wrote about Good Technology’s BYOD survey, found that organizations are jumping on the phenomenon since they see real ROI from encouraging BYOD.  The ability to keep employees connected (to information) day and night can ultimately lead to increased productivity and better customer service.  They also found that two of the most highly regulated industries - financial services and health care - are most likely to support BYOD.  This shows that the security issues IT folks often raise as objections are manageable and there's major value in supporting BYOD.  Another ROI discovered through the survey is that since employees are using their own devices, half of Good’s customers don't pay anything for the employees' BYOD devices – essentially, according to Good, getting employees to pay for the productivity boost at work.

As part of the BYOD Policy the Device Choice Checklist, while not inclusive, should:

· Survey employees about their preferences and current devices

· Define a baseline of acceptable security and supportability features

· Do homework: Read up on hardware, OS, and regional variances

· Develop a certification program for future devices

· Work with Human Resources on clear communication to employees about which devices are allowed–or not–and why

ps

Related

Technorati Tags: F5, data breach report, threats, Pete Silva, security, malware, technology, smartphone, cyber-threat, social engineering, attacks, virus, vulnerability, web, internet, cybercrime, identity theft, scam, data breach

Connect with Peter:

Connect with F5:

o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Thursday, September 13, 2012

BIG-IP Edge Client 2.0.2 for Android

app logoEarlier this week F5 released our BIG-IP Edge Client for Android with support for the new Amazon Kindle Fire HD.  You can grab it off Amazon instantly for your Android device.  By supporting BIG-IP Edge Client on Kindle Fire products, F5 is helping businesses secure personal devices connecting to the corporate network, and helping end users be more productive so it’s perfect for BYOD deployments.

The BIG-IP® Edge Client™ for all Android 4.x (Ice Cream Sandwich) or later devices secures and accelerates mobile device access to enterprise networks and applications using SSL VPN and optimization technologies. Access is provided as part of an enterprise deployment of F5 BIG-IP® Access Policy Manager™, Edge Gateway™, or FirePass™ SSL-VPN solutions.

BIG-IP® Edge Client™ for all Android 4.x (Ice Cream Sandwich) Devices Features:

  • Provides accelerated mobile access when used with F5 BIG-IP® Edge Gateway
  • Automatically roams between networks to stay connected on the go
  • Full Layer 3 network access to all your enterprise applications and files
  • Supports multi-factor authentication with client certificate
  • You can use a custom URL scheme to create Edge Client configurations, start and stop Edge Client

410esc3NxBL41ThjiC-I8L

BEFORE YOU DOWNLOAD OR USE THIS APPLICATION YOU MUST AGREE TO THE EULA HERE:
http://www.f5.com/apps/android-help-portal/eula.html

BEFORE YOU CONTACT F5 SUPPORT, PLEASE SEE:
http://support.f5.com/kb/en-us/solutions/public/2000/600/sol2633.html

If you have an iOS device, you can get the F5 BIG-IP Edge Client for Apple iOS which supports the iPhone, iPad and iPod Touch.  We are also working on a Windows 8 client which will be ready for the Win8 general availability.

ps

Resources

Technorati Tags: F5, infrastructure 2.0, integration, cloud connect, Pete Silva, security, business, education,technology, application delivery, ipad, cloud, context-aware,infrastructure 2.0, iPhone, web, internet, security,hardware, audio, whitepaper, apple, iTunes

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Thursday, June 28, 2012

Will BYOL Cripple BYOD?

Don’t ya love all the acronyms we have?

So by now, you’ve probably heard that BYOD means Bring Your Own Device – a topic that is getting lots of press these days.  The concept of allowing employees to use their own personal device, often mobile, for work related tasks.  This could reduce the overall expenditure for IT issued devices and many organizations feel users are happier and more productive when they are using the device of their desire.  There could be a snag however when it comes to licensing.  Does BYOD also require Bring Your Own License?  In many instances, this is an area that IT needs to keep an eye on and often the answer is yes.

Some of the most common enterprise software licensing agreements require licensing any device used "for the benefit of the company" under the terms of the enterprise agreement.  That often means that all those BYO devices will require a license to access common corporate applications.  This also means that even if the user already has a particular license, which they purchased on their own or it came with the device, the organization might still need to license that device under their enterprise software agreement.  This could diminish any cost savings from the BYOD initiative. 

There are solutions to such as using alternative products that are not restricted by licensing but, those may not have the key features required by your workforce.  Another idea is to move primarily to virtualization for provisioning apps with restrictive client access licenses.    Some software licenses require one CAL per concurrent connection, some require one CAL for each unique client regardless of concurrency and some do not require CALs at all.  IT needs to understand if their situation is per-user or per-device and what impact that may have on a BYOD policy.

ps

Related:

Technorati Tags: F5, smartphone, integration, byod, Pete Silva, security, business, education, technology, application delivery,ipad,mobile device, context-aware,android, iPhone, web, internet, security

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]