Showing posts with label mobile apps. Show all posts
Showing posts with label mobile apps. Show all posts

Monday, July 14, 2014

Apps Driving Attention

The mobile platform, meaning tablets and smartphones, now account for 60% of total digital media time spent according to comScore. This is a 10 point jump from 50% just a year ago. On top of that, mobile apps accounted for 51% of all digital media time spent in May 2014. Many of the content categories like radio, photos and maps are becoming almost exclusively mobile. Digital radio and photos both generate 96% of their engagement from mobile while maps and instant messaging get 90% of interaction from mobile devices.

You might be wondering, like I did, where do social networks come in since it seem like almost everyone updates their social feeds through mobile. Social is actually the #1 category for overall digital engagement taking about 20% of overall digital time spent and gets 71% of it's activity from mobile. It, social media engagement on mobile, has grown 55% over the last year and has accounted for 31% of all growth of internet engagements.

Share of Time Spent by Platform Leading Categories

So who is driving the mobile app explosion? Teenagers. About 60% of 12 to 17 year olds had a smartphone in 2013, topping even the 45+ crowd for smartphone ownership, according to Arbitron and Edison Research. The app money makers are not the initial charge for the program but all the in-app purchases along with the ads attached to the app.

Mobile is clearly the new way we consume digital content and continues to grow. We are also interacting with specific apps rather than browsing and those apps are growing at an amazing pace. Today's infrastructure needs to be even more flexible, intelligent and resilient to handle the surge. And ultimately, the apps and the content/experience they provide need to be highly available and delivered quickly and securely to the person...just like any other typical application.

ps

Related:

 

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Thursday, February 27, 2014

RSA 2014: Jeremiah Grossman Interview

We are at it again! For the 4th year in a row, Jeremiah and I chat in our annual RSA video catch up. I get some interesting security insight from WhiteHat Security Founder & CEO Jeremiah Grossman. We touch on web vulnerabilities, mobile apps, why SQLi and XSS is still a problem for organizations, WhiteHat’s Aviator secure browser along with some business advice for those entrepreneurial technologists looking to jump start their start-ups. Always a fun and interesting conversation with Jer.

ps

Related

 

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Tuesday, February 4, 2014

Mobile Malware Milestone

Did you celebrate or castigate?

You might not know but last week was the 10 year birthday of Cabir, the first mobile malware. It spread through Bluetooth after infecting the Nokia Series 60 phones running Symbian. Also last week, Kindsight Security Labs (Alcatel-Lucent) released the results of a study (pdf) that found more than 11.6 million mobile devices are infected by mobile malware at any given time and that mobile infections increased 20% globally in 2013.

This, obviously, increases risk for stolen personal and financial information, can lead to bill shock resulting from hijacked data usage, or extortion to regain control of the device along with allowing bad guys to remotely track location, download contact lists, intercept/send messages, record conversations and best of all, take pictures.

About 60% of all mobile infections involved Android devices that downloaded malicious software from the Google Play store and 40% were Android phones that received malicious code while tethered to a Windows laptop. Both Blackberry and iPhone combined to represent less than 1% of all infected devices. 4G LTE devices are the most likely to be infected and the number of mobile malware samples grew 20X in 2013. This will only get worse as new strains are released, like the proof of concept code that is capable of tracking your taps and swipes as you use a smartphone.  That's right, monitor touch events. Say a phone has not been touched in a while and suddenly there is 4 touch events. Well, that's probably a PIN, according to Forbes contributor Tamlin Magee. Add to that a screenshot, now you can overlay the touches with the screenshot and know exactly what is being entered.

You know it and I know it: The more we become one with our mobile devices, the more they become targets. It holds our most precious secrets which can be very valuable to some. We need to use care when operating such a device since, in many ways, our lives depend on it. And it is usually around this point in the article that I chastise mobile users for careless behavior but in this instance, there are certainly times where there is nothing you can do. You can be paranoid, careful and only visit the branded app stores yet the risk is still present.

Ten years in and we're just getting started.

ps

Related:

 

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Tuesday, October 15, 2013

The One Millionth Mobile Malware

Milestone has been breached according to Trend Micro.  Just a few months ago, they reported in their 2Q Security Roundup that there were 718,000 malicious or risky Andriod mobile apps available (up from 509,000 in Q1) and crystal-ball'd that the million mobile malware milestone would be reached by the end of 2013.  Well, it came a couple months early. 

Contained in that million are straight pieces of malware, those that abuse premium services like sending unauthorized text messages to certain numbers and registering people to costly services along with high-risk apps, those that aggressively serve ads that lead to dubious sites.  They found that 75% perform outright malicious routines, while another 25% exhibit dubious routines, which include adware. 

The most infamous malware families included FAKEINST at 34% and OPFAKE at 30%.  FAKEINST is typically disguised as a legitimate app and was responsible for the fake Bad Piggies versions, which were found right after the game’s release.  They can also register users for costly services by sending unauthorized text messages to those services for enrollment.    in its ability to wolf legitimate apps clothing but it was also able to launch a web page that asks the person to download a potentially malicious file.  Those are the primary risks but there are many others with this type of malware.  Such fun.

For the high risk apps, ARPUSH came in at 33% and LEADBLT garnered 27% of the total.  These are known to steal data like GPS location and OS information along with delivering malware.   

The threats don't stop with these gems.  Crooks are also looking to hijack mobile banking transactions with FAKEBANK and FAKETOKEN malware variants.  They like to spoof legitimate financial apps along with the ever popular phishing notices enticing people to enter personal info.

And I thought mobile devices were supposed to make our lives easier.  Hmm.  The dedicated circuit of a couple cans with high speed twine (HST) sounds a lot more secure these days. 

ps

Related:

 

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Tuesday, October 1, 2013

Bring Your Own A-Z

The #BYO craze has taken the world by storm and now infiltrates every sector of out lives.  Here is a partial list, in alpha-order, of various bring your owns.

BYO Apple: For the teacher in your life, the princess you'd like to put to sleep or to keep the doctor away for a day.

BYO Beer: The original classic, college style.  And BYO Booze for when you're out of college and got a little cash.

BYO Candy: With Halloween approaching this could see a surge over the next 30 days.

BYO Device: Or danger, destruction, demolition, detonator or any other dastardly 'D' word to represent risk.

BYO Everything: When Internet of Things takes over our lives.  Chocolate Chips have a whole new meaning.

BYO Food: The newest Potluck Parties.

BYO Game: Actually sitting at a table playing the physical versions of Monopoly, Life, Candy Land, Scrabble, or any other favorite.

BYO Hacker: Bodyguards in the 21st Century.

BYO Intelligence: Actually using your brain to figure out something...or when AI robots take over the world.

BYO Jump Drive: A whistleblower's favorite.

BYO Kittens: For making that irresistible, can't-stop-watching, almost viral video.

BYO Litigation: The new term for Small Claims Court.

BYO Money: What Cash with be called 10 years from now.

BYO N: BYO's maximum amount.  As far as BYOingly possible.

BYO OMG: The Surprise Party.

BYO Presents: What you take to the BYO OMG.

BYO Quarrel: The updated version of an older brother's favorite 'Stop Hitting Yourself.'

BYO Raven: Quoth he.

BYO Sushi: The new 'Gone Fishing' Bumper sticker.

BYO Time: It's all relative anyway.

BYO Utopia: Happiness comes from within.

BYO Vacation: The latest Griswold adventure this time with a Hybrid LTD Country Squire.

BYO Warnings: Wouldn't be cool if everyone had to announce the hazards of interacting with them? 

BYO X: Half of a Tic-Tac-Toe game or how Hawaiians greet each other.

BYO Yawn: What you did right now when you read this entry.

BYO Zombie: Pretty much anyone walking around fully engaged with their BYOD.

Well that was fun.  C'mon play along - it's easy and works with almost any word!

ps

Related:

 

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Tuesday, September 10, 2013

The Malware Mess

A couple weeks ago McAfee Labs released the McAfee Threats Report: Second Quarter 2013, which found that Android-based malware marked a 35% growth rate not seen since early 2012.  They also found twice as many new ransomware offerings in Q2 as in Q1, bringing the 2013 ransomware count higher than the total found in all previous periods combined.  Everything was in play - SMS stealing bank malware, infected legitimate apps, malicious apps in sheep's clothing, along with fake dating and entertainments apps.  A lot of areas that we spend a good portion of our mobile time.

In addition to mobile threats, Q2 also saw a 16% uptick in suspicious URLs and a 50% increase in digitally-signed malware samples.  Attackers are showing that they can adapt to the criminal opportunities and continue to infiltrate the ever changing infrastructure.  Ransomware, a very popular and profitable scheme, where pop-ups or other messages threaten the user unless they pay a ransom, doubled from Q1 to Q2.  Hey, if it works, might as well.  Malware signed with legitimate certificates increased 50% to 1.2 million samples.  You think you're getting the safe code due to the certificate's authentication but that cozy blanket gets cold quick.  Malware also continues to find life with infected URLs according to McAfee.  The total number of suspect URLs found reached 74.7 million or a 16% increase over Q1.  The Indexed Web is at least 3.82 billion pages so around 2% of the web but still.  I might suggest, 'watch what you type, don't click suspicious links, avoid porn sites,' and other rather obvious actions but these days it could be delivered through an ad loading on a popular news site.  Almost no one is immune.  SPAM continues to hog email servers accounting for almost 70% of all global email volume.  That's nuts.  Think about it all the legitimate email we send over a month and it only accounts for 30% of all email?!?  What a waste of resources.  Other highlights included cyber espionage campaigns and attacks on digital currency.

These threats come at a time where there seems to be a disconnect between executives and their technical teams. 

The Ponemon Institute's most recent research shows that when it comes to locking down enterprise infrastructure, the application layer is responsible for more than 90% of all security vulnerabilities, yet more than 80% of IT security spending continues to be at the network and endpoint layer.  According to Ponemon, 'Most Organizations are Woefully Behind in Application Security.'  For it's 'Current State of Application Security Report' , they asked 642 IT professionals (both executive & engineering) 20 questions concerning tools usage, development team knowledge and security best practices to better understand the maturity of an organization’s application security program in comparison to the core competencies of high-performing organizations.  They found that a much higher percentage of executive-level respondents believe their organizations are following security procedures through the lifecycle of application development than do the engineers who are closest to executing the security processes.  For instance, 71% of executives interviewed believe that application security training is available and up to date but only 20% of technical staff felt the same.  Around 67% of execs feel they have a mature application security program, compared to 33% of technical staff and 75% of executives believe that a secure architecture exists in their organization verses 23% of technical staff.  Someone is either not communicating or many organizations do not yet consider the need to proactively do something about application security or even attempt to understand application security risks.

What is troublesome is that even with all the media attention and the afore mentioned malware stats, most organizations are not building nor testing their applications for security. According to the Ponemon report, only 43% of respondents say they have a process in place to test for vulnerabilities prior to release, and only 41% are using automated scanning tools to test applications during development. And just to pile on, only 42% push their applications to manual penetration testing by internal teams or from a third party. 

So, threats are increasing (I feel like I say this multiple times a year) and it seems that organizations' response to them are decreasing...or at least not taking them seriously enough.  In many ways, it is kinda like the real world.  We think, feel, believe that we're safe until something happens...then we take all the precautions.  Many organizations need to do that yesterday. 

Today's technologies are awesome but every once in a while I do miss 4 TV stations (including PBS), typewriters, rotary phones, mimeograph machines, S&H Green Stamps and the hard wires of yesteryear.

ps

Related:

 

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Thursday, September 5, 2013

Are You Ready For Some...Technology!!

Every year around this time football fans are drafting their fantasy leagues, wearing their favorite team's jerseys, stocking tailgate items and experiencing the new technologies that have become part of the game.  From Second Screen apps to Catapult, technology is not only changing the game but also how fans experience the contest.

As more fans engage with mobile devices, the TV broadcast is being regulated as the Second Screen.  Usually the mobile device is used to access information that compliments the program but with NFL fans, particularly those who play fantasy leagues, it is the reverse.  They are locked in to their mobile app, following multiple games, tracking stats, clicking on-demand videos and even watching teams not associated with their local market.  The NFL sees a huge opportunity to reach and engage fans even more.

Australia-based Catapult is being used by many NFL teams to track athlete performance among other metrics.  A 3.5-ounce monitor situated between the player's shoulder blades monitors player movements within 15 centimeters and gives coaches acceleration, distance covered, speed, explosion times, exertion, hitting force and every other imaginable piece of data on a player's specific movements.  It is changing the manner in which teams practice, recover from injuries and even plan for games.

The San Francisco 49ers’ new Levi’s Stadium is touted as the most technologically advanced stadium in the league.  With their stadium app, fans can check bathroom, food and beer lines along with streaming replays (with your choice of camera angle) and streaming NFL Redzone.  There is plenty of WiFi capacity, which is actually uncommon at NFL stadiums.  There is only a handful of teams with WiFi service in their football stadiums but Roger Goodell (NFL commissioner) wants to make wireless internet a standard in NFL stadiums in the coming years.

There are many other advances like safer helmets with a chip that monitors the force of a hit, 2100-inch HDTVs, retractable grass and sustainable stadiums all making an impact.  The best place to watch football is in the comfort of your own living room and teams are looking at ways of creating a living room atmosphere for 80,000 fans. 

And as you're waiting for tonight's kickoff, check out what this dad did for his kids.

ps

Related:

 

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]