I wouldn't ordinarily do this, but I am currently reading Android Application Security Essentials by Pragati Ogal Rai and published by PackT Publishing.
(you can check out the book here: http://bit.ly/15mnEus)
Seeing as how more and more people are moving the mobile devices (smartphone and tablets) not just as a secondary device but sometimes a primary device, security applications on these devices becomes more and more important. This book aims to address it. I am still reading it, but what I've read it pretty good. Even if your focus is not application development, this will help your understanding of Android security.
Once complete, I hope to do a full review here. In the meantime, check out the publishers other works. I've seen several that have caught my eye.
Showing posts with label Smartphone security. Show all posts
Showing posts with label Smartphone security. Show all posts
Friday, November 1, 2013
The new version of Android- 4.4 Kit Kat
Now that Google has released it, we now more about it. It seems we don't have a lot of new flashy features, but more fundamental improvements.
Wednesday, July 24, 2013
Commentary: Rumination on GUIs
GUI- Graphic User Interface.
Most people who have used computers for the last couple of decades are used to them. To the point that most can't understand that we used to have to do everything from the command line (CLI- Command Line Interface).
I like graphical interfaces too. For a lot of tasks, they make things easy.
But, I'm a bit "old school". When I first got into admining Unix systems, we had X Windows, but we still had to do things on the command line. There were some admin tools, but they were just a layer on top of the command line. They basically put together the commands you would have used. You could still go around them. It could be harder, especially for more tricky tasks or tasks you didn't do to often. But you could do it.
Further, when a system booted up, you got a lot of text on the screen. It should you that the system was coming up smoothly. Or not. There could be some low level problems that could be shown thru that data, and this helped you resolve that.
Then along came Windows NT.
Soon the bootup information was hidden. No idea if there were problems. (you had to hope a system would boot up, and if it didn't, you'd have little info as to why).
Also, all admining was thru graphic interfaces. Again, this was nice, but you couldn't get around it if there was a problem that could only be solved by doing so.
I have a longtime admin friend who had a particular problem recently with a product that couldn't be solved thru the graphical interface. And there was no way to get around it and just enter commands. However, he was able to do so, basically be decompiling the interface. This is something that your average admin would not be able to do. But the GUI got in the way. And the vendor was of little help.
Now, as we move into the "Post-PC" world of smartphones and tablets, I fear we are moving further away from a CLI to a solely GUI world. For the average user that's fine. For "power users", this can be an annoyance. For system administrators (and I include security admins in this), this can be a hindrance if we can't get "under the hood" of what is going on and solve problems.
I worry about the lack of good deep-level tools for our Post-PC world.
Do any share this concern?
Most people who have used computers for the last couple of decades are used to them. To the point that most can't understand that we used to have to do everything from the command line (CLI- Command Line Interface).
I like graphical interfaces too. For a lot of tasks, they make things easy.
But, I'm a bit "old school". When I first got into admining Unix systems, we had X Windows, but we still had to do things on the command line. There were some admin tools, but they were just a layer on top of the command line. They basically put together the commands you would have used. You could still go around them. It could be harder, especially for more tricky tasks or tasks you didn't do to often. But you could do it.
Further, when a system booted up, you got a lot of text on the screen. It should you that the system was coming up smoothly. Or not. There could be some low level problems that could be shown thru that data, and this helped you resolve that.
Then along came Windows NT.
Soon the bootup information was hidden. No idea if there were problems. (you had to hope a system would boot up, and if it didn't, you'd have little info as to why).
Also, all admining was thru graphic interfaces. Again, this was nice, but you couldn't get around it if there was a problem that could only be solved by doing so.
I have a longtime admin friend who had a particular problem recently with a product that couldn't be solved thru the graphical interface. And there was no way to get around it and just enter commands. However, he was able to do so, basically be decompiling the interface. This is something that your average admin would not be able to do. But the GUI got in the way. And the vendor was of little help.
Now, as we move into the "Post-PC" world of smartphones and tablets, I fear we are moving further away from a CLI to a solely GUI world. For the average user that's fine. For "power users", this can be an annoyance. For system administrators (and I include security admins in this), this can be a hindrance if we can't get "under the hood" of what is going on and solve problems.
I worry about the lack of good deep-level tools for our Post-PC world.
Do any share this concern?
Android Malware jumps 6 fold in last few months
Well, I don't think this is a surprise to anyone.
Per a report by Alcatel-Lucent's Kindsight Security Labs (you can read it HERE.), Android malware has increased 6 fold to over 120,000. The bulk of these are Trojans of various sorts (the report gives you a breakout of the top ones).
Yesh.
And, sadly, this also shows the weakness of application signing to weed out the malware. We've already seen issues with Google's Bouncer keeping out the bad stuff, as well as what BlueBox recently found. (see my prior posts on both of these matters).
Related, they also show an increase in infected home networks. Again, not a big surprise if you think about it. Most people who setup home networks have little or no IT (much less IT Security) background.
For a good overview article, read THIS from Ziff-Davis.
Again, what I see here could be addressed by a couple of things.
1. Obviously Bouncer needs to be improved. BUT people can't rely upon it solely.
2. People need to be encouraged to install anti-malware apps on their smartphones. Ideally, just as with most PC that come preinstalled with a commercial AV program (usually with a set period of free use), we need to start seeing smartphones come pre-installed with SOME kind of anti-malware app. AND those people writing and putting out books/magazines on smartphones need to include security apps as part of their recommended installs people should have on their smartphones.
Per a report by Alcatel-Lucent's Kindsight Security Labs (you can read it HERE.), Android malware has increased 6 fold to over 120,000. The bulk of these are Trojans of various sorts (the report gives you a breakout of the top ones).
Yesh.
And, sadly, this also shows the weakness of application signing to weed out the malware. We've already seen issues with Google's Bouncer keeping out the bad stuff, as well as what BlueBox recently found. (see my prior posts on both of these matters).
Related, they also show an increase in infected home networks. Again, not a big surprise if you think about it. Most people who setup home networks have little or no IT (much less IT Security) background.
For a good overview article, read THIS from Ziff-Davis.
Again, what I see here could be addressed by a couple of things.
1. Obviously Bouncer needs to be improved. BUT people can't rely upon it solely.
2. People need to be encouraged to install anti-malware apps on their smartphones. Ideally, just as with most PC that come preinstalled with a commercial AV program (usually with a set period of free use), we need to start seeing smartphones come pre-installed with SOME kind of anti-malware app. AND those people writing and putting out books/magazines on smartphones need to include security apps as part of their recommended installs people should have on their smartphones.
Tuesday, July 9, 2013
Motorola Mobility Smartphone Security issue: "Motorola is listening"
I recently learned of an interesting article: "Motorola is listening". Certainly in this times of heightened attitudes about data privacy, I think its important that people be aware of these things.
In a nutshell, the author discovered that his Motorola smartphone (a Droid X2) was sending a LOT of information to Motorola, despite not having Motoblur.
Now, a word about Motoblur. Motorola Mobility rolled out this program as an enhanced UI for their earlier Android phones. You initially couldn't use your phone without signing up with the Motoblur service. You were encouraged to enter all your username and passwords for the various services you used (email accounts, twitter, facebook, etc), and it would give you alerts. What I think most people didn't know was that this information was actually stored on Motorola's servers. It's was kind of a cloud service without you realizing it. I think this was done probably as you moved from phone to phone, you could just log back into your Motoblur account on your new phone and have all your settings there.
But people hated Motoblur, and later versions were less intrusive. AFAIK, in their most recent phones (the newest RAZR line), Motoblur is gone. But they still use Motoblur for some things. (When I was "dogfooding" new versions of Android on a RAZR M, the updates were sent to my phone via Motoblur). I had to deal with Motoblur on my original Atrix 4G. But I don't recall dealing with it on my Droid Bionic, and certainly didn't have it on my RAZR M.
The author's phone, AFAIK, doesn't have Motoblur, BUT it is interesting (and a bit scary) that Motorola Mobility still seems to be gathering information from his phone. He has asked people with different models of Motorola phones to test them (he provides the tool he used) and report back on their results. I recommend people take a look at this article for updates. He has already put up several based on feedback. Will be interesting to see where this goes.
And what about other companies? Are Apple, Samsung, HTC, etc doing something similar?
In a nutshell, the author discovered that his Motorola smartphone (a Droid X2) was sending a LOT of information to Motorola, despite not having Motoblur.
Now, a word about Motoblur. Motorola Mobility rolled out this program as an enhanced UI for their earlier Android phones. You initially couldn't use your phone without signing up with the Motoblur service. You were encouraged to enter all your username and passwords for the various services you used (email accounts, twitter, facebook, etc), and it would give you alerts. What I think most people didn't know was that this information was actually stored on Motorola's servers. It's was kind of a cloud service without you realizing it. I think this was done probably as you moved from phone to phone, you could just log back into your Motoblur account on your new phone and have all your settings there.
But people hated Motoblur, and later versions were less intrusive. AFAIK, in their most recent phones (the newest RAZR line), Motoblur is gone. But they still use Motoblur for some things. (When I was "dogfooding" new versions of Android on a RAZR M, the updates were sent to my phone via Motoblur). I had to deal with Motoblur on my original Atrix 4G. But I don't recall dealing with it on my Droid Bionic, and certainly didn't have it on my RAZR M.
The author's phone, AFAIK, doesn't have Motoblur, BUT it is interesting (and a bit scary) that Motorola Mobility still seems to be gathering information from his phone. He has asked people with different models of Motorola phones to test them (he provides the tool he used) and report back on their results. I recommend people take a look at this article for updates. He has already put up several based on feedback. Will be interesting to see where this goes.
And what about other companies? Are Apple, Samsung, HTC, etc doing something similar?
Monday, June 3, 2013
GeorgiaTech Researchers can hack your iPhone via charger
The use of small hardware devices (Arduino, Raspberry Pi, BeagleBone) to hack systems is one I've touched on before. At the recent HackMiami Conference there was a very good presentation on this. I think this is a vector that not too many security professionals are aware of, to their detriment.
HERE is a recent article on some researchers at the Georgia Tech who say they can infect an iPhone via a charger. They will be showing how they did it at the upcoming Black Hat conference.
Apparently it's done with a BeagleBoard, which is a sizable device. A BeagleBone would have been smaller, and easier to fit into a surge protector/power strip then a BeagleBoard. But maybe they were looking for more proof of concept.
HERE is a recent article on some researchers at the Georgia Tech who say they can infect an iPhone via a charger. They will be showing how they did it at the upcoming Black Hat conference.
Apparently it's done with a BeagleBoard, which is a sizable device. A BeagleBone would have been smaller, and easier to fit into a surge protector/power strip then a BeagleBoard. But maybe they were looking for more proof of concept.
Wednesday, May 29, 2013
Failure of Bouncer
In a previous posting, I mentioned Bouncer, Google's service within the Google Play Store that is supposed to keep out malware. This is important, because the Play Store does not vet new apps to the level that Apple's App Store does, meaning that Google Play becomes one of the biggest vectors for malware to get into Android phones.
Well, per a recent article at ArsTechnica, someone figured out how to get around this. I discovered this thru an article at TechRepublic.
Apparently how they did it was upload an app to Google that was ok, which was checked by Bouncer. Then they uploaded a new version of that app, this one with the malware. Now, I have to wonder why Bouncer didn't re-check it. Wouldn't that malware app be different (different size, atleast a new update date), and thus Bouncer would re-examine it? Seems its not setup that way. Certainly a new upload, if its not a new size, should trigger a recheck.
Apparently some 9 million user got it. Upsy.
Check out the article at TechRepublic. I thought it had some pretty good points, similar to what I've been saying, on the need for better security stance when it comes to Android. A big part is that we need to get more people to install AV software (ok, they are really anti-malware, but still) on their phones. Stop giving people the impression these devices are totally secure, and take practical security in mind.
Well, per a recent article at ArsTechnica, someone figured out how to get around this. I discovered this thru an article at TechRepublic.
Apparently how they did it was upload an app to Google that was ok, which was checked by Bouncer. Then they uploaded a new version of that app, this one with the malware. Now, I have to wonder why Bouncer didn't re-check it. Wouldn't that malware app be different (different size, atleast a new update date), and thus Bouncer would re-examine it? Seems its not setup that way. Certainly a new upload, if its not a new size, should trigger a recheck.
Apparently some 9 million user got it. Upsy.
Check out the article at TechRepublic. I thought it had some pretty good points, similar to what I've been saying, on the need for better security stance when it comes to Android. A big part is that we need to get more people to install AV software (ok, they are really anti-malware, but still) on their phones. Stop giving people the impression these devices are totally secure, and take practical security in mind.
Monday, May 20, 2013
The importance of smartphone security awareness
I have posted prior on the issue of smartphone security. And one of the biggest issues related to this is how many people who have smartphones are sadly not aware of the need to be secure. I guess we could say there is a lack of security awareness when it comes to smartphones. This issue is made more difficult by people making the claim that smartphones are "more secure" then PCs (whatever that means), and that somehow people don't need to be as security minded about their smartphones like they are with their PCs, especially if its a personal phone.
I'm sorry, but I find that an irresponsible attitude.
I'm sorry, but I find that an irresponsible attitude.
Friday, May 3, 2013
Smartphone as bank account
In 2012 I made a presentation at our local security conference (South Florida ISSA Chapter) on smartphone security. Part of what I presented was the trends I was seeing at the time, based on reports. Some most people are aware of: smartphones overtaking "feature phones", smartphones overtaking laptop/PCs in sales, etc.
Another trend I point out I think is not so well known, at least here in the "developed world". That of smartphones becoming the first, maybe only computing device of people in the "developing world", but of also becoming for them the equivalent of a credit card or bank account (checking account).
Another trend I point out I think is not so well known, at least here in the "developed world". That of smartphones becoming the first, maybe only computing device of people in the "developing world", but of also becoming for them the equivalent of a credit card or bank account (checking account).
Subscribe to:
Posts (Atom)