Posts

Showing posts with the label Mobile Security

How Hidden Vulnerabilities will Lead to Mobile Device Compromises

Image
Your mobile device can be hacked very easily without your knowledge. Even if an attacker can’t get into your device they can attempt to gain access to the sensitive information instead that is stored inside such as your places visited, emails and contacts. It's not just consumers who are targeted by cybercriminals, the rise of smartphones and tablets in the workplace and the increase in remote working has resulted in hackers targeting businesses via their mobile device vulnerabilities. Most individuals and organisations with very sensitive information, still do not take basic mobile security measures, even with the rising threats to our smartphones. According to a study by Intertrust on mobile security, the cost of mobile app hacks and violations will hit $1.5 billion by the end of 2021. Yet, network systems or even our desktop computers get more attention, with mobile device security continuing to be ignored by organisations across the globe every day. Three Ways a Mobile Device ...

Trends in IT-Security and IAM in 2021, the “New Normal” and beyond

Article by Dennis Okpara, Chief Security Architect & DPO at IDEE GmbH Yes, there is hope for 2021, but the challenges of the “New Normal” are here to stay. CISOs have to prepare and start acting now, because cybersecurity and the IT-infrastructure will have to face threats that have only just started. The year 2020 was the year working from home lost its oddity status and became normality. Big names like Google and Twitter are planning long-term and hold out the prospect of working from home on a permanent basis. More than 60 percent of companies are trying the same and have implemented home office policies in 2020. But with great flexibility comes great responsibility: Everyone responsible for Cybersecurity and a secure IT infrastructure is now dealing with new challenges closing the last gaps and weak points when it comes to allowing access to company resources. Dennis Okpara, Chief Security Architect & DPO at IDEE GmbH, the specialist for secure identity access managemen...

Six Trends Shaping the 2021 Cybersecurity Outlook

Article by Tom Kellerman, Head of Cybersecurity Strategy, Rick McElroy, Head of Security Strategy and Greg Foss, Senior Cybersecurity Strategist, VMware Carbon Black Everything is different, and yet the same. As we look ahead to the cybersecurity landscape in the next 12 months, it is from a position no one predicted this time last year. Business operations have changed beyond recognition with most employees working from home in a transition that happened almost overnight. Stretched security teams have been challenged to rapidly deploy robust remote working facilities to maintain productivity. Most were writing the ‘pandemic playbook’ as they went along. Ironically, one of the few certainties of the situation was that cybercriminals would take advantage of disruption to escalate campaigns. In that sense, nothing changed, except that the opportunity was suddenly much greater. As a result, nine in ten security professionals surveyed by our Threat Analysis Unit said they were facing ...

iPhone Hacks: What You Need to Know About Mobile Security

Image
Guest Post by Jennifer Bell Learn How Hackers Steal and Exploit Information to Ensure This Doesn’t Happen to You  Cybersecurity is an important topic to know and understand in order to keep your information safe and secure. Even more specifically, it’s important to know and understand mobile security as well. Mobile security, especially with iPhones, is crucial as hackers are becoming smarter and more creative when it comes to iCloud hacks. Apple has partnered with network hardware and insurance companies such as Cisco and Aon to provide security against data breaches; but how can you ensure that even with these Apple partnerships that your iPhone is secure and protected against hackers? Here are the most common ways that hackers get into iPhones to steal or exploit personal information, keep these points in mind to best protect yourself from mobile security hacks. Poor Passwords Often, poor password choices or poor password management allows hackers to easily hack into iPhones ...

Security Threats Facing Modern Mobile Apps

Image
We use mobile apps every day from a number of different developers, but do we ever stop to think about how much thought and effort went into the security of these apps? It is believed that 1 out of every 36 mobile devices has been compromised by a mobile app security breach. And with more than 5 billion mobile devices globally, you do the math. The news that a consumer-facing application or business has experienced a security breach is a story that breaks far too often. As of late, video conferencing apps like Zoom and Houseparty have been the centre of attention in the news cycle. As apps continue to integrate into the everyday life of our users, we cannot wait for a breach to start considering the efficacy of our security measures. When users shop online, update their fitness training log, review a financial statement, or connect with a colleague over video, we are wielding their personal data and must do so responsibly. Let’s cover some of the ways hackers access sensitive informa...

The IT Security Expert Blog is 10 Years Old

Image
Ten years ago today I published my first ever blog post about a BBC news story titled " Home Network Security Scrutinised ". A decade ago it was rare to see an IT security or hacking story make the news media, and back then the term 'Cyber Security' would conjure images of Dr.Who's metallically clad arch-villains in most people's minds in the UK. The Face of Cyber Security in 2007 Fast forward ten years, IT security has long been rebadged as 'Cyber Security' and on Friday the top ten news stories  on Sky News were all Cyber Security related, albeit about the same global attack , but how times have changed. 'I found the following article on the BBC news website, which happens to be exactly what I had been talking about in my presentations this week. None of the findings is surprising to me, but I find many people I talk with are in the dark about digital security. Anyway, I thought I'd write this post about it and start my own blog...

Stay Safe from Cyber Crime - Top Ten Tips InfoGraphic

Image
Given I am regularly asked to explain cyber attacks and then advise on how to protect against them, particularly to home users of late, I thought I would try my hand at creating a simple InfoGraphic to help. It was a challenge to create due to the limitation to the amount of space for text, which means you can't cover everything and you can't go into much detail. However concise messaging is kind of the point of infographics, especially when using them as awareness tools.  This InfoGraphic is squarely aimed at the average "home user", it highlights what the bad guys are after, their most popular and most successful attack methods, and then provides 10 tips to help avoid and detect home user cyber attacks, simples. If this InfoGraphic proves popular I'll create some more, starting with one covering home IoT Security advice, another subject I'm regularly asked about at the moment. Download full version here

How to Protect Against Mobile Malware

Image
IBM Security recently released a white paper on the mobile malware threat, which included general guidance on managing the mobile threat and an overview of IBM’s MaaS360 Mobile Threat Management tool, I thought it was good advice and well worth sharing. Mobile is the New Playground for Thieves: How to Protect against Mobile Malware According to Arxan Technologies. 97% and 87%t of the top paid Android and iOS apps, respectively, have been hacked and posted to third-party app stores. Mobile Security Guidance (by IBM Security) Educate Employees about Application Security: Educate employees about the dangers of downloading third-party applications and the potential dangers that can result from weak device permissioning . Protect BYOD devices: Apply enterprise mobility management capabilities to enable employees to use their own devices while maintaining organisational security. Permit Employees to download from Authorised App Stores Only : Allow employees to download ap...

UK Information Security Threat Horizon 2014

I was asked for my views on the Threat Horizon, specifically what attacks and trends do I expect to impact UK businesses in 2014, so I thought I'd share my thoughts.  The following are my own views, and they are not based on any specific studies or reports, but on what I've generally read, discussed and trends I have seen affecting UK businesses in the last couple of years. Cloud Data Protection UK businesses continue the 'Cloud Rush', meaning more and more confidential data is going into the cloud. I don't think this is so much a Snowden privacy revelation issue with government spying, but I see the problem is that UK businesses are being  taken in by the marketing cost saving glitz, and so  are blindly trusting cloud service providers. At the end of the day a cloud service provider is a third party service provider. A cloud service purchased by a business, where the third party is charged with adequately  protecting confidential info...

iPhone 5S "Touch ID" Fingerprint Security

Image
Apple announced the new iPhone 5S today, the introduction of a new fingerprint recognition access system on the smartphone, called "Touch ID", grabs the security attention. Fingerprint reader is the main button Security of the Fingerprint Reader The fingerprint reader is not like the traditional readers you see on laptops, and is actually part of the main button on the phone. The reader is no security gimmick as it is not a outdated optical reader, which works by taking and comparing a picture of your fingerprint, it is a capacitance reader,which is a more advanced and secure technology. Capacitance readers uses an electrical current to map your fingerprint, measures the minuscule differences in conductivity caused by the raised parts of your fingerprint, which makes it very difficult to defeat. I don't like to advocate the security of anything without inspecting, researching and testing a device myself, but I will say this reader has certainly been designed ...

GCHQ Cracks SmartPhone Codes, Privacy Outrage or Lifesaver?

The Edward Snowden fallout continues with the steady trickle of classified revelations released by the media.   The latest appears to be confirmation of GCHQ ability to crack or bypassed the encryption on Blackberry and Android smartphones. This news isn't really that shocking given cracking encryption is a core part of what GCHQ has done for decades. It is also important to understand that nowhere does the released documentation say GCHQ have been breaking into everyone’s smartphones and harvesting our private data on mass, I doubt they’ll have resource and funding in the UK to do that. My assumption is breaking smartphone encryption is a necessary GCHQ tool for gathering information on specifically targeted bad guys, for example suspected and known terrorists.  Several terrorist plots have been foiled since the 7/7 atrocities, so what if GCHQ's ability to access encrypted smartphone electronic messaging and call information, had played a key par...

PayPal's 'Pay with your face' Creepy Privacy Concern

PayPal launched a new smartphone payment service in the UK, where the customer pays using their smartphone. The merchant (shopkeeper) receives the customer's name and a photo of the customer's face, and then verifies the customer is the owner of the smartphone and PayPal account, by comparing the PayPal sent photo of the customer on the shop's smartphone, with the face of the person stood in front of the till.  This is a passport control type facial recognition authentication, in other words biometric verification. There is a video of it in action on the BBC website -  http://www.bbc.co.uk/news/business-23605025 The fly in the ointment which the BBC report neglected to mention is privacy. A lot of people who value their right to privacy and personal information, will simply not want to have a photo of their face together with their full name sent to shopkeepers mobile phones. There is also the age old problem with any biometric verification, it just...

The problem of Securing the New iPad 3 within Business

Image
Apple announced the latest edition of their fantastic iPad today, not only is this device irresistible for consumers, but it has become irresistible for business.  This presents a new challenge for information security professionals, as the iPad has been bred for consumerization not for business usage, yet the business application capability of tablets are undeniable. Within main stream businesses up and down the land a change is afoot, it is no longer about giving the odd few magpie like senior executes the latest shinny new toys, as there is an unquenchable thirst for Apple’s latest tablet gadget emanating across entire businesses. This is not a time to have heads buried in the sand and wishing for risk aspects of business usage of tablets to go away, the tablet is coming to a business near you. In a few years from now they will be as common place on office desks as laptops, and will be smugly grasped by the majority of attendees within meeting rooms. But let us not forget, a ...

SmartPhone App Security Advice

Image
Smartphones really are a fraudster’s paradise, there are so many opportunities for fraudsters to monetise from them. From Rogue Malicious Apps sending premium rate text messages costing up to £6 a text, to stealing the personal information and passwords held on them. And there are even further fraud opportunities with smarphones being increasingly used for making Payments and with Online Banking. These factors together with a general smartphone user security naivety, are a major incentive for the bad guys to target these little handheld cash cows. So it is no surprise cyber attacks targeting smartphones are rapidly increasing in the UK, "800% increase in cyber attacks on smartphones" (Nov 11)  http://www.mirror.co.uk/news/top-stories/2011/11/07/800-increase-in-cyber-attacks-on-smartphones-115875-23543307/ .    In this post we will look at how to go about protecting against one of the most commonly successful attacks a...

Securely Wiping your Personal Data from the iPhone

Image
It seems like every year Apple release a better 'must have' version of the amazing iPhone, sparking a rush to upgrade by the masses. Ensuring all your precious personal information is securely removed from your old iPhone is an essential step to take before trading in or selling your old iPhone on eBay. Like any smartphone, the iPhone hoards all types of sensitive information about you, not just your embarrassing ABBA playlist and dodgy drunken pictures from the weekend, but all your Emails including access to future mails, username and passwords for websites and social media, and even sensitive financial information such as bank account and credit card details are often stored. So unless you are putting your iPhone through an industrial crusher, you really need to ensure you erase all the data from it before passing it on, this post explains how. This data erasing advice and method also applies to the iPad and iPod Touch If your old iPhone is a 3GS or an above model, then se...