Mobile

6/27/2018
10:06 PM
50%
50%

10 Tips for More Secure Mobile Devices

Mobile devices can be more secure than traditional desktop machines - but only if the proper policies and practices are in place and in use.
Previous
1 of 11
Next

(Image: oneinchpunch)

(Image: oneinchpunch)

Computing and mobile computing are, to an ever-growing degree, the same thing. According to research by StoneTemple, at the beginning of 2018, 63% of Web traffic comes from mobile devices; they expect the number to pass 2/3 of all traffic by the end of the year.

Most users, and most security professionals, seem to think that mobile platforms are inherently more secure than traditional desktop and laptop computers. In many circumstances that's correct, but that assumption can lead to behaviors that carry significant risks.

Fortunately, there are steps a security team can take secure mobile devices: Some of these are actions that the security team should take, while others are actions that should be taught to users. Many of these steps fall squarely in the "it just makes common sense" category of things. That doesn't mean that security pros and users alike don't need a reminder to check for each of these to be on their list of positive behaviors — and on the list of results to be enforced by policy on all devices.

There are many behaviors that can contribute to mobile device security or risk. We'd be interested in hearing about the behaviors that you see as important — but that didn't make our list. Use the comment section to let us know what we missed.

 

Curtis Franklin Jr. is Senior Editor at Dark Reading. In this role he focuses on product and technology coverage for the publication. In addition he works on audio and video programming for Dark Reading and contributes to activities at Interop ITX, Black Hat, INsecurity, and ... View Full Bio

Previous
1 of 11
Next
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
burntpuppy
50%
50%
burntpuppy,
User Rank: Apprentice
8/7/2018 | 10:14:15 PM
Re: OS updates
Another issue with the update treadmill is each update I've seen contains more bloatware, that can't be removed without root access. I don't want m$ products, ESPN and a bunch of other crap on my device. I treat every app as a potential security hole, and if the app is not on my device it can't be exploited!
HPERPER
50%
50%
HPERPER,
User Rank: Strategist
7/3/2018 | 3:04:27 PM
Mobile Device Security NIST NCCoE
The NIST National Cybersecurity Center of Excellence has publihsed guidance and best practices to secure mobile devicse.   Chek it our at nccoe[dot]nist[dot]gov
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
6/27/2018 | 11:06:04 PM
OS updates
I have a bone to pick about OS updates. Vital for good security? Sure. But it's a self-created issue because the vendor then begins to treat the old OS as good as abandonware.

Which wouldn't be so bad except that so many OS updates are more feature driven than security driven such that, in my experience, they tend to be progressively worse.

Which then causes people to want to update less -- which leads to bad security.

Mobile OS teams: Want to improve security on your products? Fire all the elitist, desperate-to-win-an-award UX/UI jerks.
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
The Year in Security 2018
This Dark Reading Tech Digest explores the biggest news stories of 2018 that shaped the cybersecurity landscape.
Flash Poll
How Enterprises Are Attacking the Cybersecurity Problem
How Enterprises Are Attacking the Cybersecurity Problem
Data breach fears and the need to comply with regulations such as GDPR are two major drivers increased spending on security products and technologies. But other factors are contributing to the trend as well. Find out more about how enterprises are attacking the cybersecurity problem by reading our report today.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-6499
PUBLISHED: 2019-01-21
Teradata Viewpoint before 14.0 and 16.20.00.02-b80 contains a hardcoded password of TDv1i2e3w4 for the viewpoint database account (in viewpoint-portal\conf\server.xml) that could potentially be exploited by malicious users to compromise the affected system.
CVE-2019-6500
PUBLISHED: 2019-01-21
In Axway File Transfer Direct 2.7.1, an unauthenticated Directory Traversal vulnerability can be exploited by issuing a specially crafted HTTP GET request with %2e instead of '.' characters, as demonstrated by an initial /h2hdocumentation//%2e%2e/ substring.
CVE-2019-6498
PUBLISHED: 2019-01-21
GattLib 0.2 has a stack-based buffer over-read in gattlib_connect in dbus/gattlib.c because strncpy is misused.
CVE-2019-6497
PUBLISHED: 2019-01-20
Hotels_Server through 2018-11-05 has SQL Injection via the controller/fetchpwd.php username parameter.
CVE-2018-18908
PUBLISHED: 2019-01-20
The Sky Go Desktop application 1.0.19-1 through 1.0.23-1 for Windows performs several requests over cleartext HTTP. This makes the data submitted in these requests prone to Man in The Middle (MiTM) attacks, whereby an attacker would be able to obtain the data sent in these requests. Some of the requ...