Showing posts with label cell phone security. Show all posts
Showing posts with label cell phone security. Show all posts

Monday, June 30, 2008

Mobile phone security awareness: Secure wipe and IPhone 2.0

Mobile phones, particularly smartphones are becoming ubiquitous, and many users are forwarding organizational email to their private devices. With sensitive data potentially accessible on these devices, the ability to wipe them securely has become a necessity. Vendors are starting to make progress - mobile device encryption is becoming more available, and wipe utilities that securely wipe data are being announced. The most recent? Apple's Iphone 2.0 firmware.

AppleInsider reports that the Iphone 2.0 firmware will include the ability to perform a secure wipe of the device. According to AppleInsider, "Unlike today's iPhone software, however, the revised function will wipe data in similar fashion to the "Secure Empty Trash" function of Mac OS X, by which all data is deleted, unlinked, and then overwritten several times to make it irretrievable by even the savviest of recovery tools."

This is far better than the current delete function, which leaves remnant data in place.

Apple will go one step further however, as the new firmware will also include a feature allowing remote wiping of a stolen or lost phone - a feature that both end users and enterprise security staffers will be delighted to have.

Thursday, June 5, 2008

Cell Phones and Privacy: Is Location Data A Risk?

Nature.com's recent coverage of the work done by a team from Northeastern University raises some interesting questions.

By monitoring the signals from 100,000 mobile-phone users sending and receiving calls and text messages, a team from Northeastern University in Boston, Massachusetts, has worked out some apparently universal laws of human motion.
This becomes a bit more scary in context - readers may remember the AOL search data scandal from 2006. As cell data is made available for research, probably without the knowledge of individuals, and without the opportunity to opt out, the same techniques that the New York Times used to hunt down searchers might be used to track down individual cell users. Would cell users turn their cells off if they knew they would be tracked and used for research when they go places they might not want others to know about?

What would you think if you were one of those whose data was used?
Barabási and his colleagues teamed up with a mobile-phone company (unidentified to protect customers' privacy), who provided them with anonymized data on which transmitter towers had handled the calls and texts for 100,000 individuals over the course of 6 months.
Does this protect the users? Or does it protect the company?

Update: CNN's article does a good job of discussing the researcher's take on privacy issues, as well as the ethical and privacy concerns third parties have raised.

Monday, February 4, 2008

How secure are your SMS messages?

A recent scandal in Detroit caused Mike Wendland of the Detroit Free Press to look into how long the major cell companies keep text messages on their servers as part of an article on text messaging security. The responses are interesting:

  • Sprint retains messages for approximately two weeks to ensure delivery
  • AT&T keeps messages for 72 hours
  • Verizon did not provide a timeframe but noted that they keep the messages for a "very short time".
Text messages are still plaintext, and provide no real security - and can be kept on the receiving phone, but these numbers may help alleviate concerns of a history of your text messages being kept to haunt you.

None of these are spelled out in their contracts - so there is a place in the industry for an an MVNO to sell encrypted, secure phone-to-phone communication and secure, encrypted text messaging available to subscribers.