Latest Podcast



Featured Articles

Ofcom says mobile contracts should ditch inflation-related price rises

Ofcom says mobile contracts should ditch inflation-related price rises

UK telecoms regulator Ofcom wants to ban inflation-related rises in phone and broadband contracts. Instead, it says any potential mid-contract price rises should be set out in pounds and pence.
Author: The Fonecast
0 Comments
Article rating: No rating

Global smartphone market is set for recovery, says new forecast

A new forecast from research specialists Canalys shows the smartphone market is set to recover next year. Worldwide shipments declined by 12% last year but that decline is expected to slow to 5% this year.
Author: The Fonecast
0 Comments
Article rating: No rating
Vodafone and Three plan to merge their UK businesses

Vodafone and Three plan to merge their UK businesses

New Hutchison/Vodafone network would be biggest UK operator

Vodafone Group plc and CK Hutchison Group Telecom Holdings Limited have agreed to combine their UK telecommunication businesses, respectively Vodafone UK and Three UK. The merger will create a large new network operator to compete with Virgin Media O2 and EE.
Author: The Fonecast
0 Comments
Article rating: No rating

UK mobile payment service Paym to close in March 2023

UK mobile payment service Paym will close on 7th March 2023. The service, which allowed users to make and receive payments using their mobile phone numbers, was launched in 2014.
Author: The Fonecast
0 Comments
Article rating: No rating
Qualcomm legal action moves forward in the UK

Qualcomm legal action moves forward in the UK

Which? seeks payout for Samsung and Apple smartphone owners

Consumer protection organisation Which? has been given permission by the UK's Competition Appeal Tribunal to represent Apple and Samsung smartphone buyers in a legal case against chip manufacturer Qualcomm.
Author: The Fonecast
0 Comments
Article rating: No rating
RSS

Opinion Articles

Tuesday, September 27, 2011

Are smartphones endangering security?

Ian Kilpatrick, chairman of IP security specialists Wick Hill Group, writes:

Smartphones are spreading throughout the business world. Their use is growing across organisations and at all levels.

According to Gartner, sales of mobile devices in the second quarter of 2011 grew 16.5% year-on-year. Smartphone sales grew 74% year-on-year and accounted for 25% of overall sales in the second quarter of 2011, up from 17% in the second quarter of 2010.

Not only are the numbers of smartphones growing, their versatility is increasing. Where staff used to carry laptops when they went out of the office, to retrieve email and use other applications on the move, they can now carry just a smartphone.

This potentially allows them to send and receive emails, use a variety of applications, link to the company network to access data and use network-based applications, access social networking sites, and carry out online e-commerce and banking transactions.

A smartphone raises key security issues, which many organisations have not fully realised yet or, if they have, they may not have taken appropriate measures to ensure network safety.

The dangers
The biggest danger, of course, is that smartphones go missing. Many of us will have lost a mobile phone in the past or know someone who has. Research by getsafeonline shows that about one in five owners of smartphone devices can expect to lose or have them stolen at some point.  Surveys show the level of phone loss in London taxis is at a world-leading, and fairly consistent, 10,000 per month. Yes, that’s right, 10,000 per month!

Smartphones are often used for both business and personal reasons and if they are lost, both sensitive company data and personal data stored on the phone may be exposed. Email exchanges could be seen. Personal data relating to online purchasing or banking might be viewed.

If the phone is connected via a VPN, company networks are exposed to malware or could be hacked. Philippe Winthrop, an analyst at consultancy Strategy Analytics Inc., commented: "If I take your device and muck around with it, what if the VPN is set up on it? It's a huge risk not being dealt with enough today."

Getsafeonline’s Tony Neate says: "Users must remember that they are essentially carrying around a tiny laptop with a wealth of personal information that is very attractive to fraudsters."

Smartphones are now at the stage that PCs were at around 1999. Many people didn’t think security was necessary then, hardly anyone had firewalls, but security concerns were beginning to be a focus. It’s a similar situation now with smartphones.

For example, last year the MMS Bomber virus affected millions of mobile users in China, costing them significant sums dialling out on their phones.

It doesn't take long for criminals to think of ways of stealing and using information fraudulently. Some security experts have pointed out that targeting smartphones could potentially be more profitable for criminals than aiming at computers.

Security policies
With the rapid proliferation of smartphones and the very real security risks, organisations now need to factor smartphone use into their security policies and make sure they are managed centrally.

Smartphones have also extended the network boundary even further. Employees may use devices for both company and personal use, bringing dangers to the company network, in the same way that remote workers created new and different security issues for the IT department.

In addition, these devices cross the divide between voice and data, so that companies using them are taking a strategic direction into convergence, perhaps without realising it, and probably without planning for it. They are at the cutting edge of fixed and mobile convergence and users are only rarely required to connect over secure VPNs and even less required to use secure authentication to connect to the network.

Fixed/mobile convergence creates other security and financial threats. Unsecured access to PBX systems (traditional and IP) exposes organisations to an increased risk of toll fraud, as well as risks such as DOS attacks, backdoor attacks on the data network, and call recording.

Security tips
There are a number of basic security procedures which organisations and individuals can take to increase security.

* Use the PIN or passcode function to secure the phone. Don’t rely on the default factory settings.

* Install data wiping facilities so critical information can be destroyed if it’s thought the phone has fallen into the wrong hands. This might happen, if for example, a password is entered wrongly a certain number of times, or when a device has been off the network for a certain period of time.

* Employ time out policies, to prevent further use of the phone, if it is inactive for a certain period of time. This should be initiated from a central management console.

* Install GPS tracking so the phone can be located if stolen.

* Install SIM watch. This reports the new number back to you if the SIM is removed and replaced

* Take a note of your International Mobile Equipment Identity number. The IMEI number is used by the GSM network to identify valid devices and therefore can be used for stopping a stolen phone from accessing the network in that country. It’s easy to find on most phones by typing *#06# into the keypad.

* Take similar data leakage protection measures as with a PC.

- treat the phone like it’s a PC. Beware of phishing emails, don’t follow links you’re not sure of, don’t download anything suspect, recognise the risks of unsecured WiFi connections, etc.

- stipulate that sensitive, critical information should be made available to users of smartphones on a ‘need to know’ basis

- use two factor authentication (with challenge response) to validate access to the smartphone

- encrypt sensitive data, as many smartphones and security suppliers provide facilities to enforce this.  

There is often as much data on a smartphone, as on a laptop, but it is more vulnerable to loss or theft. The ICO (Information Commissioner’s Office) has now started fining organisations which lose unencrypted data that should have been secured.

- run anti-virus. The impact of a virus, both in terms of data loss and financial cost, is considerable

Solutions
Commercial security solutions for smartphones are available from a number of vendors such as Kaspersky Lab, CRYPTOCard and Check Point.

Kaspersky Lab’s Mobile Security 9, for example, helps users to safely browse the web and communicate via social networks. Features include inbuilt GPS to locate a lost or stolen smartphone, protection from malware and network attacks with real-time anti-malware scans, automatic updates and blocking of dangerous network connections.

Conclusion
Smartphones are an incredible tool for a whole range of people and their use will proliferate. However, smartphone security is lagging ten years behind the growth curve, especially as they are so easily lost or stolen.

Smartphones carry with them the risks of any computer on a network and at the same time cross the divide between voice and data, which brings security risks of its own. For an organisation to remain secure, smartphones need to come within the sphere of the security policy, their use needs to be regulated and active steps should be taken to employ them securely.

Print
Author: The Fonecast
0 Comments
Rate this article:
No rating

Categories: OpinionNumber of views: 4018

Tags:

Leave a comment

This form collects your name, email, IP address and content so that we can keep track of the comments placed on the website. For more info check our Privacy Policy and Terms Of Use where you will get more info on where, how and why we store your data.
Add comment

Recent Podcasts

A week of mobile industry news, including the latest security and privacy concerns

Podcast - 16th April 2014

We begin this week's podcast with a discussion about the Heartbleed bug, the effect it's having on the mobile industry and the wider issues for all internet users.

We're also talking about the future of BlackBerry, UK 4G coverage, new CEOs, Bluetooth connectivity, privacy concerns and the next generation of mobile processors.

Author: The Fonecast
0 Comments
Article rating: No rating

A new mobile move from Microsoft, a roaming revolution in Europe... and much more

Podcast - 9th April 2014

This week's podcast starts with news from Microsoft about an update to its Windows Phone platform and a cost-free OS offer to hardware manufacturers.

There's also a new flagship smartphone from Nokia, a roaming announcement from the European Parliament, a UK virtual mobile network from The Co-operative Group, a change at the top for Mozilla, retail expansion for Vodafone and an awkward end to BlackBerry's relationship with T-Mobile in the USA.

Author: The Fonecast
0 Comments
Article rating: No rating

Acquisitions, banking, complaints... and the rest of the week's mobile industry news

Podcast - 2nd April 2014

Acquisition announcements from Facebook and Intel are the first stories in this week's look at the latest UK mobile industry headlines.

They're followed by news about mobile payments, mobile banking, a phone with an invisible solar panel, customer complaints, low-cost 4G smartphones, productivity apps and an intriguing case of WhatsApp-itis.

Author: The Fonecast
0 Comments
Article rating: No rating

Smartphones, smart watches and SMS spam: all the week's mobile industry news headlines

Podcast - 26th March 2014

Iain Graham, James Rosewell and Mark Bridge are reunited for their regular weekly look at the latest UK mobile industry headlines.

Today they're talking about smart watches, an Apple iPhone announcement, the new HTC One M8, the closure of Ovivo Mobile, text spam, peer-to-peer messaging, government hacking and mergers.

Author: The Fonecast
0 Comments
Article rating: No rating

Designing mobile phones for seniors: we talk to Doro and Emporia Telecom

Podcast - 21st March 2014

Producing mobile phones for older customers requires much more than big buttons and a simple interface. At Mobile World Congress last month we spoke to two major players in this growing sector: Swedish company Doro and Austria's Emporia Telecom.

Our first conversation was with Harald Obereder, Chief Technology Officer at Emporia, who spoke to Mark Bridge about handset design and user interface design. This was followed by an interview with Chris Millington, Managing Director for Doro UK and Ireland, about research and development in the 'senior tech' market.

Author: The Fonecast
0 Comments
Article rating: No rating
RSS
First45679111213Last

Follow thefonecast.com

Twitter @TheFonecast RSS podcast feed
Find us on Facebook Subscribe free via iTunes

Archive Calendar

«September 2024»
MonTueWedThuFriSatSun
2627282930311
2345678
9101112131415
16171819202122
23242526272829
30123456

Archive

Terms Of Use | Privacy Statement