Friday, September 27, 2013

Filling the void of Blackberry

By now, I think more people are aware of what's going on with RIM/Blackberry.  For most people, it was a matter of who they would be bought out by and when.

When RIM rolled out the Blackberry many years back, its focus was on the business user.  This user needed something relayable and SECURE.  But when the iPhone hit (and later Android), even tho these devices were less secure than Blackberry, they had features that Blackberry lacked and was hard to catch up: the array of applications.

Now, some tried to bring iPhones and Androids up to the level of Blackberry, to be able to compete for the business user.  For a period of time, Motorola Mobility had an array of products that made their phones more acceptable to the business user.  They had bought out 3LM (mentioned in a prior posting) to make Android more secure.  Their "webtop" on their high end phones was another addition aimed at the business user.  This was a stripped down Linux OS with added features that would turn the phone into a "laptop" if connected to an HDMI device and keyboard (say thru one of their docking stations) or plugged into one of their "lapdocks" which gave a netbook-sized screen and keyboard.  Sadly, when Google bought Motorola Mobility, all that would be dropped as Google wanted the new division to instead focus on the larger consumer market.

Thus, it was left to others to step into the field.  Samsung has already done so to a degree with their Knox security add-on to Android (again, see my prior posting).  Now they seem to have extended this with their SAFE (Samsung for Enterprise) effort.  As higher security for such devices is important, this bearing watching.

See article HERE.

Sunday, August 18, 2013

New Security features of Android 4.3

The new version of Android rolled out, 4.3 Jelly Bean, also brings new security features.

By most count, it seems there are 7 security features rolled out.

1.  First off, we have Restricted Profiles.  This is a feature ONLY for tablets, as these are devices that are often shared among people, especially family members.  This allows for different profiles to be setup, some with restrictions, for, say, children.   More on this HERE.

2.  Next there is strengthening of encryption.  This includes tools to make sure neither hackers or other malicious entities can access the keys.  There are a new set of APIs for this, known as the Keychain/Keystore system API.

3.  There is a Nousid command that makes sure no program can obtain root privileges by setting the setuid bit.  The /system partition is also better secured as part of this.

4.  The new Find My Phone app (Android Device Manager) can be used to find/locate a lost or stolen device.  And the user can use this to remotely manage, lock, or wipe clean the device.  This I find interesting, as this is a service that many obtain thru MDM systems.  For a corporate user, this is usually part of such a corporate MDM system, run by their company admins.  For the individual user, one can obtain their own such service from third parties.  So I would think this would compete against that more so then the corporate MDM.  But could this be a competition for the corporate MDM systems?  Here is more info on this feature.

5.  Again, something that is not actually in Android, there is the Verify Apps feature that is part of Google Play.  I already blogged about this in a previous posting.  This should extend the protection of Bouncer, but we've already see Bouncer failing (see my previous postings).  So while Google seems to feel that such things (Bouncer and probably Verify Apps) negates the need for anti-malware apps on Android, I am a bit skeptical of this.

6.  They have activited within Android SELinux.  Now, many may not realize that Android is actually built on Linux.  SELinux is "Security Enhanced Linux", which adds mandatory access controls (MAC) to the Linux kernal.  For more on SELinux, go to the project page HERE.

7.  Finally, there is new WPA2 Wi-Fi security capabilities.  This isn't something the end user can use, but only programmers.  It allows for the use of the new WPA2 (Wi-Fi Protected Access 2) features of Wi-Fi.

These are pretty nice set of additions.  I would like to see how the security of Android 4.3 compares to the latest versions of iOS and Windows Phone.  Not seen a side-by-side comparison.  If any know of one, I'd like to know.

On a related note, I came across THIS article at the Official Google blog on securing your Android phone. They basically give 3 tips:  1) screen lock, 2) be secure on apps you install, but Bouncer & Verify Apps will protect you, and 3) used Find My Phone to be able to find and/or wipe your phone.


I used this article for the source of this posting: HERE  Another good resource I found is HERE.

Friday, August 16, 2013

Security in the "Internet of Things"

During the recent round of IT Security/Hacker conferences in Las Vegas (Defcon, Black Hat, BSides), a variety of interesting security issues have been revealed in various "non-computer" devices that are networks.

Here is a high level overview of several:


  • Hacking of the "Smart Home":  HERE  and HERE   and HERE
  • Hacking of the "Smart Car":   HERE   and longer commentary on the issue HERE
  • Hacking of the "Smart Toilet":   HERE  and HERE
  • Hacking of a baby monitor:   HERE  and HERE  (Updated)
  • Hacking of networked lightbulbs:  HERE

Saturday, July 27, 2013

Google's new "Verify Apps" service makes Android more secure

Along with the recent release of a new version of Android, 4.3, Google also rolled out a new service that promises to make Android more secure.

The Verify Apps service was originally rolled out as part of Android 4.2.  But now its been pulled out of Android itself and made part of the Google Play Store service, along side the already existing Bouncer service.  By doing so, all versions of Android can take advantage of this.

I learned about this thru THIS posting at Computerworld.

So, what DOES this new service do?  Its a universal app-scanning system.  It watches for new apps on your system, even those loaded directly from outside the Google Play Store ("sideloaded"), and instantly checks that app for malicious or potentially harmful code.

While I think this is great, I'm not sure I buy into the views of this writer of the blog posting that this somehow eliminates the need of anti-malware apps on Android.  While, yes, there is a bit of fear mongering on the part of the anti-malware field (true of a lot within the security field), the fact is we've seen an increase in Android malware.  Plus, one can get a large number of free anti-malware apps, so its not like you have to pay a lot of money to protect yourself.

On a practice point, we've seen failures with Bouncer.  Who's to say that similar issues won't been seen with Verify Apps?  Plus, like I think most security professionals, I prefer multi-level security measures.  It's a mistake to rely on one or a limited number of tools to protect our systems.  It would be like a company thinking that since they have firewalls, they need not worry about anti-virus or the like.

I do like the idea of "Android deconstruction" mentioned by the writer (further covered in THIS posting), with Google pulling out certain elements from Android itself, and making them available as separate apps, thus avoiding the issue of Android upgrading.  There are limits to this, as not everything can be an app, but maybe this will help make Android be a more core OS, that can be more easily upgraded.


Thursday, July 25, 2013

New version of Android out

I don't think I will surprise anyone by saying that there is a new version of Android out there:  4.3.

And so, we will have everyone all worked up about it, and wondering when they will get this on their phones.  (which I can understand.  Both my phone and tablet are still at 4.1.2).

I guess its a good idea to perhaps review all this.

UPDATE II: Android "Master Key" Security issue

Well, a further update on the Android "Master Key" issue.  See my first posting HERE.

Per THIS article at the BBC, Symantec has found someone using it in the wild.  Here is their ITEM on it, with all the technical details.

Kind of funny when the attitude of some was that there wasn't much chance of it being used.

Right.

Wednesday, July 24, 2013

Commentary: Rumination on GUIs

GUI- Graphic User Interface.

Most people who have used computers for the last couple of decades are used to them.  To the point that most can't understand that we used to have to do everything from the command line (CLI- Command Line Interface).

I like graphical interfaces too.  For a lot of tasks, they make things easy. 

But, I'm a bit "old school".  When I first got into admining Unix systems, we had X Windows, but we still had to do things on the command line.  There were some admin tools, but they were just a layer on top of the command line.  They basically put together the commands you would have used.  You could still go around them.  It could be harder, especially for more tricky tasks or tasks you didn't do to often.  But you could do it.

Further, when a system booted up, you got a lot of text on the screen.  It should you that the system was coming up smoothly.  Or not.  There could be some low level problems that could be shown thru that data, and this helped you resolve that.

Then along came Windows NT.

Soon the bootup information was hidden.  No idea if there were problems.  (you had to hope a system would boot up, and if it didn't, you'd have little info as to why).

Also, all admining was thru graphic interfaces.  Again, this was nice, but you couldn't get around it if there was a problem that could only be solved by doing so.

I have a longtime admin friend who had a particular problem recently with a product that couldn't be solved thru the graphical interface.  And there was no way to get around it and just enter commands.  However, he was able to do so, basically be decompiling the interface.  This is something that your average admin would not be able to do.  But the GUI got in the way.  And the vendor was of little help.

Now, as we move into the "Post-PC" world of smartphones and tablets, I fear we are moving further away from a CLI to a solely GUI world.  For the average user that's fine.  For "power users", this can be an annoyance.  For system administrators (and I include security admins in this), this can be a hindrance if we can't get "under the hood" of what is going on and solve problems. 

I worry about the lack of good deep-level tools for our Post-PC world.

Do any share this concern?