Kenneth Van Wyk: We need more secure mobile devices
As things stand now, all bets are off if you lose your smartphone
Computerworld - When you combine the words "mobile device" and "security," you get an oxymoron. That's the state of security in the mobile world, and it's been that way since day one.
That has to change. Smartphones and tablets are increasingly doing heavy lifting in the corporate world, and are ever more likely to be repositories of sensitive data. But where do we start in making them more secure?
For now, forget about malware and sophisticated hacking. We first need to close the most gaping hole of all for mobile devices, one that every expert I have talked to over the years has agreed on: If a bad guy gets physical access to a mobile device, all bets are off. A few months ago, the folks at the OWASP Mobile Security Project backed up this assessment. They did a threat modeling exercise of mobile devices and determined that two of the most glaring issues are the loss or theft of the device and insecure communications.
A basic problem is that anyone who gets his hands on someone else's smartphone can access the user's login credentials with ridiculous ease. Mobile apps contribute to this problem. I myself have realized that some of the mobile apps that I use store login credentials and other sensitive data where they shouldn't be, and in the last month or so, I've read about numerous cases of such iOS app weaknesses. Using nothing more than a USB cable, an attacker can in many cases get to login and/or session credentials for many high-profile apps, on both iOS and Android platforms.
That's unacceptable, and we've got to demand better from our app vendors.
For starters, mobile app developers must keep in mind when writing their software that devices can easily be lost or stolen -- and recognize that a lost device shouldn't be a free ticket to valuable data. Most modern mobile platforms provide mechanisms for reasonably protecting things like user login credentials. These mechanisms are generally called keychains. Current versions of both Android and iOS have keychain APIs that app developers can and should be using. While not perfect, they do provide significant protection over simply storing usernames and passwords -- even when hashed -- in plaintext files (e.g., plist or properties files).
Second, other user data on mobile devices should be encrypted. This is something that users have to do themselves, but Android and iOS both provide mechanisms for doing that reasonably securely, and third-party add-ons like SQLcipher for AES encrypting SQLite databases are even better. If you look for strong mobile encryption mechanisms, you can find them.
More by Kenneth van Wyk
- How to avoid Big Brother's gaze
- The true root causes of software security failures
- Kenneth van Wyk: Making safer iOS apps
- Kenneth van Wyk: Staying out of the belly of the Internet beasts
- Should you risk jailbreaking your iPhone?
- There's no magic pill for security
- Kenneth Van Wyk: 'Tis the season to shop with care
- Kenneth van Wyk: The good and bad of Android and iOS
- Kenneth van Wyk: Shutting down security gotchas in iOS 6
- Security can still make or break mobile-payment systems
- 10 Hot Big Data Startups to Watch
- 11 Unique Uses for Google Glass, Demonstrated by Celebs
- How to Export Your Google Reader Account
- How to Better Engage Millennials (and Why They Aren't Really so Different)
- Telltale signs of ATM skimming
- 20 security and privacy apps for Androids and iPhones
- Big screen con artists: 7 great movies about social engineering
- IT Certification Study Tips
- Register for this Computerworld Insider Study Tip guide and gain access to hundreds of premium content articles, cheat sheets, product reviews and more.
- An Interactive eGuide: DDoS Attacks In today's world, Distributed Denial of Service (DDoS) attacks on organizations are becoming more prevalent. The number of attacks are increasingly annually with...
- Cloud Impacts and Outcomes for Business Leaders Learn More
- Wanted: A Trusted Provider for Public Cloud Services Learn how Dell's cloud strategy, built on the highest level of VMware integration and security, is enabling enterprises to get out of the...
- Firewall and IPS Deployment Guide Discover how to quickly deploy a full-service business network that is next-generation threat-ready. This comprehensive guide is based on best-practice design principles that...
- HIPAA Hiccup Solved Data protection priorities rapidly changed after a patient data leak that caused one healthcare provider unexpected expenses, potential reputational risk and possible HIPAA...
- Dell Software This overview of Dell SonicWALL next-generation firewalls showcases how you can increase network security by scanning every packet without any compromises in network... All Security White Papers | Webcasts
