ps
Related
- Mobile World Congress 2015 - The Preview Video
- MWC 2015 - Find F5
- MWC 2015 – NFV for Service Providers (feat Yue)
- F5 at #MWC15
- F5 YouTube Channel
| Connect with Peter: | Connect with F5: |
| |
Peter Silva covers security for F5’s Technical Marketing Team. Bringing the slightly theatrical and fairly technical together, he covers training, writing, speaking, along with overall product direction and evangelism for F5’s security line.
| Connect with Peter: | Connect with F5: |
| |
Andrew Berenato, AirWatch Business Development Manager, does a great job explaining the many enterprise mobile device management challenges that the BIG-IP & AirWatch integration solves. BYOD, secure corporate apps, maintain compliance and employee privacy are all covered. True enterprise mobility management.
AirWatch by VMware simplifies mobility for organizations, while empowering end users. With AirWatch, organizations can easily deploy, configure, secure, manage and support smartphones, tablets, laptops and other devices across multiple mobile platforms and operating systems.
ps
Related
| Connect with Peter: | Connect with F5: |
| |
Do you avoid stores that have had a credit card breach?
You are not alone. About 52% of people avoid merchants who have had a data breach according to a recent Lowcards survey. They surveyed over 400 random consumers to better understand the impact of identity theft on consumer behavior. 17% said they or a family member was a victim of identity theft over the last year with half the cases being credit card theft. 94% said they are more concerned or equally concerned about ID theft. They estimate that there were 13.5 million cases of credit card identity theft in the United States over the last 12 months.
These concerns are also changing the way some people shop.
Over half (56%) are taking extra measures to protect themselves from identity theft. Some of these behaviors include using a debit card less (28%), using cash more (25%), ordering online less (26%) and checking their credit report more (38%). These are all reasonable responses to the ever challenging game of protecting your identity and is important since 89% of security breaches and data loss incidents could have been prevented last year, according to the Online Trust Alliance's 2014 Data and Breach Protection Readiness Guide.
The game is changing however, and mobile is the new stadium. Let's check that scoreboard.
Most of the security reports released thus far in 2014, like the Cisco 2014 Annual Security Report and the Kaspersky Security Bulletin 2013 show that threats to mobile devices are increasing. We are using them more and using them for sensitive activities like shopping, banking and storing personally identifiable information. It is no wonder that the thieves are targeting mobile and getting very good at it. Kaspersky's report talks about the rise of mobile botnets and the effectiveness since we never shut off our phones. They are always ready to accept new tasks either from us or, a foreign remotely controlled server with SMS trojans leading the pack. Mobile trojans can even check on the victim's bank balance to ensure the heist is profitable and some will even infect your PC when you USB the phone to it.
Distribution of exploits in cyber-attacks by type of attacked application
I guess the good news is that people are becoming much more aware of the overall risks surrounding identity theft and breaches but will the convenience and availability of mobile put us right back in that dark alley? Mobile threats are starting to reach PC proportions with online banking being a major target and many of the potential infections are delivered via SMS messages. Sound familiar?
Maybe we can simply cut and replace 'PC' with 'Mobile' on all those decade old warnings of:
Watch what you click!
ps
Related
| Connect with Peter: | Connect with F5: |
| |
Did you celebrate or castigate?
You might not know but last week was the 10 year birthday of Cabir, the first mobile malware. It spread through Bluetooth after infecting the Nokia Series 60 phones running Symbian. Also last week, Kindsight Security Labs (Alcatel-Lucent) released the results of a study (pdf) that found more than 11.6 million mobile devices are infected by mobile malware at any given time and that mobile infections increased 20% globally in 2013.
This, obviously, increases risk for stolen personal and financial information, can lead to bill shock resulting from hijacked data usage, or extortion to regain control of the device along with allowing bad guys to remotely track location, download contact lists, intercept/send messages, record conversations and best of all, take pictures.
About 60% of all mobile infections involved Android devices that downloaded malicious software from the Google Play store and 40% were Android phones that received malicious code while tethered to a Windows laptop. Both Blackberry and iPhone combined to represent less than 1% of all infected devices. 4G LTE devices are the most likely to be infected and the number of mobile malware samples grew 20X in 2013. This will only get worse as new strains are released, like the proof of concept code that is capable of tracking your taps and swipes as you use a smartphone. That's right, monitor touch events. Say a phone has not been touched in a while and suddenly there is 4 touch events. Well, that's probably a PIN, according to Forbes contributor Tamlin Magee. Add to that a screenshot, now you can overlay the touches with the screenshot and know exactly what is being entered.
You know it and I know it: The more we become one with our mobile devices, the more they become targets. It holds our most precious secrets which can be very valuable to some. We need to use care when operating such a device since, in many ways, our lives depend on it. And it is usually around this point in the article that I chastise mobile users for careless behavior but in this instance, there are certainly times where there is nothing you can do. You can be paranoid, careful and only visit the branded app stores yet the risk is still present.
Ten years in and we're just getting started.
ps
Related:
| Connect with Peter: | Connect with F5: |
| |
A few weeks ago, I went to my usual haircut place and after the trim at the register I presented my loyalty card. You know the heavy paper ones that either get stamped or hole-punched for each purchase. After a certain number of paid visits, you receive a free haircut. I presented the card, still in the early stages of completion, for validation and the manager said I could convert the partially filled card to their new system. I just had to enter my email address (and some other info) in the little kiosk thingy. I declined saying, 'Ah, no thanks, enough people have my email already and don't need yet another daily digest.' He continued, 'well, we are doing away with the cards and moving all electronic so...' 'That's ok,' I replied, 'I'll pay for that extra/free haircut to keep my name off a mailing list.'
This event, of course, got me thinking about human nature and how we will often give up some privacy for either convenience or something free. Imagine a stranger walking up to you and asking for your name, address, email, birthday, income level, favorite color and shopping habits. Most of us would tell them to 'fill in the blank'-off. Yet, when a Brand asks for the same info but includes something in return - free birthday dinner, discounted tickets, coupons, personalized service - we typically spill the beans.
Infosys recently conducted a survey which showed that consumers worldwide will certainly share personal information to get better service from their doctors, bank and retailers; yet, they are very sensitive about how they share. Today’s digital consumers are complicated and sometimes suspicious about how institutions use their data, according to the global study of 5,000 digitally savvy consumers. They also created an infographic based on their findings.
Overall they found:
...and specific to retail:
Your data is valuable and comes with a price. While many data miners are looking to capitalize on our unique info, you can always decline. Yes, it is still probably already gathered up somewhere else; Yes, you will probably miss out on some free or discounted something; Yes, you will probably see annoying pop-up ads on that free mobile app/game and; Yes, you might feel out of the loop.
But, it was still fun to be in some control over my own info leaks.
ps
Related:
| Connect with Peter: | Connect with F5: |
| |
Milestone has been breached according to Trend Micro. Just a few months ago, they reported in their 2Q Security Roundup that there were 718,000 malicious or risky Andriod mobile apps available (up from 509,000 in Q1) and crystal-ball'd that the million mobile malware milestone would be reached by the end of 2013. Well, it came a couple months early.
Contained in that million are straight pieces of malware, those that abuse premium services like sending unauthorized text messages to certain numbers and registering people to costly services along with high-risk apps, those that aggressively serve ads that lead to dubious sites. They found that 75% perform outright malicious routines, while another 25% exhibit dubious routines, which include adware.
The most infamous malware families included FAKEINST at 34% and OPFAKE at 30%. FAKEINST is typically disguised as a legitimate app and was responsible for the fake Bad Piggies versions, which were found right after the game’s release. They can also register users for costly services by sending unauthorized text messages to those services for enrollment. in its ability to wolf legitimate apps clothing but it was also able to launch a web page that asks the person to download a potentially malicious file. Those are the primary risks but there are many others with this type of malware. Such fun.
For the high risk apps, ARPUSH came in at 33% and LEADBLT garnered 27% of the total. These are known to steal data like GPS location and OS information along with delivering malware.
The threats don't stop with these gems. Crooks are also looking to hijack mobile banking transactions with FAKEBANK and FAKETOKEN malware variants. They like to spoof legitimate financial apps along with the ever popular phishing notices enticing people to enter personal info.
And I thought mobile devices were supposed to make our lives easier. Hmm. The dedicated circuit of a couple cans with high speed twine (HST) sounds a lot more secure these days.
ps
Related:
| Connect with Peter: | Connect with F5: |
| |
More than 1.8 million medical ID theft victims in 2013
That's a 19% increase over last year according to the 2013 Survey on Medical Identity Theft. More than 300,000 new medical identity theft cases were reported during the one-year period, the study found. The 4th annual survey, conducted by the Ponemon Institute, defined medical identity theft as a person using an individual's name or personal identity “to fraudulently receive medical service, prescription drugs and goods, including attempts to commit fraudulent billing.”
One of the biggest contributors to the increase was fake or spoofed medical websites and spam emails. Medical identity theft victims who reported that a cyber schemes caused their troubles doubled from 4% in 2012 to 8% in 2013. It is clear that the amount and frequency of spear phishing specifically targeting medical ID theft has gone up. This is not the simple 'Buy this personal enhancement drug here' emails but authentic looking emails from a provider. You click the malicious link and either malware is installed to your computer or you are directed to a website that looks exactly like your medical provider's and you enter (give away) your credentials there. You might even be able to log into something that will request you update your personal information. Perfect, I get your credentials along with some additional Rx information or mailing address or SSN or date of birth anything that I can use to impersonate you.
As far as data breaches as a cause, only 7% (up 1 tick from last year) felt a data breach by their insurer, health care provider or related was linked to the fraud.
A separate but related survey, a new Deloitte report says healthcare organizations are in various stages of mitigating the security risks of medical devices. These include patient monitors, infusion pumps, ventilators, pacemakers and imaging devices. Deloitte interviewed the medical device security leaders at nine large hospital systems and they indicated that their organizations have a long way to go and that they need more cooperation from device manufacturers.
The Food and Drug Administration (FDA) recently released a guidance on the "content of premarket submissions for management of cyber security in medical devices." The guidance suggested that device makers incorporate security features into their products to limit access to only trusted users, trusted content, and use fail-safe and recovery devices. They want manufacturers to consider threats like hacking, malware and other vulnerabilities of the device's software and to work with providers on addressable scenarios. This is certainly an area of importance for both providers and the device manufactures. Remember all the wrangling with PCI and those payment devices? Granted, the FDA guidance is a recommendation and not a regulation like PCI so there is reluctance to include security measures in purchasing contracts.
The other issue healthcare organizations face is trying to secure older proprietary devices. These closed systems make it almost impossible to scan for vulnerabilities but they are still in widespread use. For other devices that run on well know commercial operating systems, they are vulnerable to the same threats that any device with that software has.
Deloitte also asked the medical device security heads where their organizations stood in several areas of cyber security. These included: organizational leadership, risk framework, identification and evaluation, data flow, vulnerability management, vendor agreements and manufacturer engagement. Ken Terry over at Information Week goes into detail of each.
So far there have been no documented instances of "intentional threats" to medical devices, according to the report but healthcare providers are not required to report security incidents to the FDA or the device manufacturer unless a death or serious injury has occurred.
ps
Related:
| Connect with Peter: | Connect with F5: |
| |