Mobile

6/27/2018
10:06 PM
50%
50%

10 Tips for More Secure Mobile Devices

Mobile devices can be more secure than traditional desktop machines - but only if the proper policies and practices are in place and in use.
Previous
1 of 11
Next

(Image: oneinchpunch)

(Image: oneinchpunch)

Computing and mobile computing are, to an ever-growing degree, the same thing. According to research by StoneTemple, at the beginning of 2018, 63% of Web traffic comes from mobile devices; they expect the number to pass 2/3 of all traffic by the end of the year.

Most users, and most security professionals, seem to think that mobile platforms are inherently more secure than traditional desktop and laptop computers. In many circumstances that's correct, but that assumption can lead to behaviors that carry significant risks.

Fortunately, there are steps a security team can take secure mobile devices: Some of these are actions that the security team should take, while others are actions that should be taught to users. Many of these steps fall squarely in the "it just makes common sense" category of things. That doesn't mean that security pros and users alike don't need a reminder to check for each of these to be on their list of positive behaviors — and on the list of results to be enforced by policy on all devices.

There are many behaviors that can contribute to mobile device security or risk. We'd be interested in hearing about the behaviors that you see as important — but that didn't make our list. Use the comment section to let us know what we missed.

 

Curtis Franklin Jr. is Senior Editor at Dark Reading. In this role he focuses on product and technology coverage for the publication. In addition he works on audio and video programming for Dark Reading and contributes to activities at Interop ITX, Black Hat, INsecurity, and ... View Full Bio

Previous
1 of 11
Next
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
burntpuppy
50%
50%
burntpuppy,
User Rank: Apprentice
8/7/2018 | 10:14:15 PM
Re: OS updates
Another issue with the update treadmill is each update I've seen contains more bloatware, that can't be removed without root access. I don't want m$ products, ESPN and a bunch of other crap on my device. I treat every app as a potential security hole, and if the app is not on my device it can't be exploited!
HPERPER
50%
50%
HPERPER,
User Rank: Apprentice
7/3/2018 | 3:04:27 PM
Mobile Device Security NIST NCCoE
The NIST National Cybersecurity Center of Excellence has publihsed guidance and best practices to secure mobile devicse.   Chek it our at nccoe[dot]nist[dot]gov
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
6/27/2018 | 11:06:04 PM
OS updates
I have a bone to pick about OS updates. Vital for good security? Sure. But it's a self-created issue because the vendor then begins to treat the old OS as good as abandonware.

Which wouldn't be so bad except that so many OS updates are more feature driven than security driven such that, in my experience, they tend to be progressively worse.

Which then causes people to want to update less -- which leads to bad security.

Mobile OS teams: Want to improve security on your products? Fire all the elitist, desperate-to-win-an-award UX/UI jerks.
New Cold Boot Attack Gives Hackers the Keys to PCs, Macs
Kelly Sheridan, Staff Editor, Dark Reading,  9/13/2018
Yahoo Class-Action Suits Set for Settlement
Dark Reading Staff 9/17/2018
RDP Ports Prove Hot Commodities on the Dark Web
Kelly Sheridan, Staff Editor, Dark Reading,  9/17/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
Flash Poll
How Data Breaches Affect the Enterprise
How Data Breaches Affect the Enterprise
This report, offers new data on the frequency of data breaches, the losses they cause, and the steps that organizations are taking to prevent them in the future. Read the report today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-17182
PUBLISHED: 2018-09-19
An issue was discovered in the Linux kernel through 4.18.8. The vmacache_flush_all function in mm/vmacache.c mishandles sequence number overflows. An attacker can trigger a use-after-free (and possibly gain privileges) via certain thread creation, map, unmap, invalidation, and dereference operations...
CVE-2018-17144
PUBLISHED: 2018-09-19
Bitcoin Core 0.14.x before 0.14.3, 0.15.x before 0.15.2, and 0.16.x before 0.16.3 and Bitcoin Knots 0.14.x through 0.16.x before 0.16.3 allow a remote denial of service (application crash) exploitable by miners via duplicate input. An attacker can make bitcoind or Bitcoin-Qt crash.
CVE-2017-3912
PUBLISHED: 2018-09-18
Bypassing password security vulnerability in McAfee Application and Change Control (MACC) 7.0.1 and 6.2.0 allows authenticated users to perform arbitrary command execution via a command-line utility.
CVE-2018-6690
PUBLISHED: 2018-09-18
Accessing, modifying, or executing executable files vulnerability in Microsoft Windows client in McAfee Application and Change Control (MACC) 8.0.0 Hotfix 4 and earlier allows authenticated users to execute arbitrary code via file transfer from external system.
CVE-2018-6693
PUBLISHED: 2018-09-18
An unprivileged user can delete arbitrary files on a Linux system running ENSLTP 10.5.1, 10.5.0, and 10.2.3 Hotfix 1246778 and earlier. By exploiting a time of check to time of use (TOCTOU) race condition during a specific scanning sequence, the unprivileged user is able to perform a privilege escal...