Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
1 In 10 US Smartphone Users Victims of Theft
Newest First  |  Oldest First  |  Threaded View
Page 1 / 2   >   >>
Jeffrub1
Jeffrub1,
User Rank: Apprentice
5/13/2014 | 8:53:48 PM
The proposed "Kill Switch" in California
I'm surprised that the national theft rate is actually that low! Here in my hometown of San Francisco, law enforcement authorities say that 2/3 of all thefts are smartphones (replacing laptops and bicycles on the "most stolen" leader board). This highly opportunistic crime epidemic (which is often accompanied by violence) has grown large enough statewide that California's Senate just passed legislation (SB962) requiring all new cellphones to have anti-theft technology – a kill switch – that wipes and permanently disables the device in the hopes that widespread adoption will spoil the theft incentive.  How much this law would help secure corporate information compromised in stolen BYOD phones is unclear, but it certainly won't have an effect for a little longer since it still requires Assembly approval. But my guess is that it's just a matter of time before it's the standard. A question though, is whether hackers will quickly find workarounds, or worse still, find ways to obliterate broad numbers of phones remotely?
Randy Naramore
Randy Naramore,
User Rank: Ninja
5/12/2014 | 10:41:44 AM
Re: second factor risk?
Exactly, not sure the answer but the device is essentially a paper weight at this point. Encryption and multi-factor are the way to go to secure mobile devices.
MrTibbs
MrTibbs,
User Rank: Apprentice
5/12/2014 | 10:19:33 AM
second factor risk?
Why is it a "major risk is when a smartphone that's set up as a second factor of authentication gets stolen"?

The thief won't know the first factor (username/password). And if the device has encrypted storage and a lock screen, that should thwart them even more.

 
Marilyn Cohodas
Marilyn Cohodas,
User Rank: Strategist
5/9/2014 | 4:12:18 PM
Re: Losing your phone
Good point. In my own case, my cell phone is for work and play -- and I pay for the insurance. So I'm covered...
Randy Naramore
Randy Naramore,
User Rank: Ninja
5/9/2014 | 4:03:47 PM
Re: Losing your phone
Exactly, but might be easier to get some kind of supplemental coverage so you are not responsible for the whole thing. 
Marilyn Cohodas
Marilyn Cohodas,
User Rank: Strategist
5/9/2014 | 3:45:50 PM
Re: Losing your phone
It is like ransom but it makes me wonder how prevalent it is for corporate America to hold individual employees totally responsible when their company-owned devices get stolen. Seems like the company should buy the insurance....
Randy Naramore
Randy Naramore,
User Rank: Ninja
5/9/2014 | 3:31:59 PM
Re: Losing your phone
There are a couple different ways of looking at this, first it is the data you want back, back up the data peridically and then have the ability to wipe remotely. Secondly, get the insurance from your carrier and get it replaced. You would be out of pocket some but not $800.00. This is almost like ransom.
Marilyn Cohodas
Marilyn Cohodas,
User Rank: Strategist
5/9/2014 | 9:29:10 AM
Re: Losing your phone
I have a friend who works for a hospital in L.A. Someone grabbed her work iPhone from her purse while she was walking through a shopping mall. She had to pay $800 (retail) out of her own pocket to replace it 
Kelly Jackson Higgins
Kelly Jackson Higgins,
User Rank: Strategist
5/9/2014 | 7:27:22 AM
Re: Losing your phone
Agreed, @Bprince. It's like they would pay ransom for their family...photos. 
securityaffairs
securityaffairs,
User Rank: Ninja
5/9/2014 | 3:55:22 AM
Re: Losing your phone
The data resented are congruent to the current mobile security scenario, we have an increasing number of new malware families designed for mobile platforms and the penetration level of mobile is surpassing the one of desktop PCs.

Wrong habits, poorly designed applications, lack adoption of defense solution and no awareness of principal cyber threats make mobile users very exposed.

That's life ... let's start to think to security by design
Page 1 / 2   >   >>


Edge-DRsplash-10-edge-articles
I Smell a RAT! New Cybersecurity Threats for the Crypto Industry
David Trepp, Partner, IT Assurance with accounting and advisory firm BPM LLP,  7/9/2021
News
Attacks on Kaseya Servers Led to Ransomware in Less Than 2 Hours
Robert Lemos, Contributing Writer,  7/7/2021
Commentary
It's in the Game (but It Shouldn't Be)
Tal Memran, Cybersecurity Expert, CYE,  7/9/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Black Hat USA 2022 Attendee Report
Black Hat attendees are not sleeping well. Between concerns about attacks against cloud services, ransomware, and the growing risks to the global supply chain, these security pros have a lot to be worried about. Read our 2022 report to hear what they're concerned about now.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2022-2390
PUBLISHED: 2022-08-12
Apps developed with Google Play Services SDK incorrectly had the mutability flag set to PendingIntents that were passed to the Notification service. As Google Play services SDK is so widely used, this bug affects many applications. For an application affected, this bug will let the attacker, gain th...
CVE-2022-2503
PUBLISHED: 2022-08-12
Dm-verity is used for extending root-of-trust to root filesystems. LoadPin builds on this property to restrict module/firmware loads to just the trusted root filesystem. Device-mapper table reloads currently allow users with root privileges to switch out the target with an equivalent dm-linear targe...
CVE-2022-2779
PUBLISHED: 2022-08-12
A vulnerability classified as critical was found in SourceCodester Gas Agency Management System. Affected by this vulnerability is an unknown functionality of the file /gasmark/assets/myimages/oneWord.php. The manipulation of the argument shell leads to unrestricted upload. The attack can be launche...
CVE-2022-38179
PUBLISHED: 2022-08-12
JetBrains Ktor before 2.1.0 was vulnerable to the Reflect File Download attack
CVE-2022-38180
PUBLISHED: 2022-08-12
In JetBrains Ktor before 2.1.0 the wrong authentication provider could be selected in some cases