Showing posts with label mobile. Show all posts
Showing posts with label mobile. Show all posts

Thursday, October 31, 2013

FAA Changing Gadget Rule

It seems I have been complaining for years about the silly requirement of turning off our mobile devices at landing and take off of airplanes. Good news may be just around the corner because we will eventually be able to continue using our mobile devices on takeoff and landing, according to the FAA. The American government organization overseeing air travel today announced that travelers won’t face regulations that are as strict as we have been accustomed to when it comes to electronics on planes.

However this does not mean you can continue playing Candy Crush or in my case Mahjong while waiting for your takeoff just yet. The roll out and specifics of the changes will vary depending on each airline since there are differences between types of planes and how things are run at each different carrier, but the FAA anticipates that most will allow passengers to use their mobile devices “in airplane mode, gate-to-gate, by the end of the year.”

Passengers can use e-book readers, play games and watch videos on devices, and can hold gadgets during both take-off and landing, or else stow them in the seatback pocket. These gadgets need to be in Airplane Mode or have cell service turned off during both landing and taxi/take-off, but you can actually use Wi-Fi during your flight and continue to use Bluetooth accessories connected to your phone.

Soon I will be able to finish watching Star Trek as the plane lands!

My personal  belief on this long time rule is that the FAA simply wanted the passengers to pay attention during take off and landing and that no iPhone has the ability to take down a airplane. I am glad that finally this out dated and unnecessary regulation is about to end. Do you know how many times I had about 10 minutes left on my Star Trek episode when the announcement is made to turn off all electronic devices and my wife starts hitting me in the arm repeatability saying "Turn it off Bill!" 

I will talk about "airplane mode" in more detail in a future article.

Tuesday, September 10, 2013

Our Mobile Security Challanges

Your smartphone is now a much more tempting target for cybercriminals than your desktop computer, and unless you take proper precautions, it is easier to hack as well.

Think of it this way: Your computer might have sensitive work documents, banking information or personal records, but there are only a few ways people can access those files — in person, via a network or over the Internet.

On the other hand your smartphone is almost always on, connected to the Internet, logged into your email and social media, and likely has at least a username stored for your bank account. Your smartphone contains as much sensitive information as your wallet does — more, if you count the contact information for your family and friends.

Smartphones can access the Internet, which puts them at risk for a variety of malware and compromising exploits, but malware can come via almost any phone function. Text messages are easily exploitable, especially since an average text-messaging app takes no security precautions. They open automatically and load as soon as your phone connects to a network; in effect, they can't be blocked.

Hackers also monetize these hacks in very subtle ways. Rather than stealing credit card information to buy themselves expensive things that are extremely easy to track, they often subscribe users to premium texting services, which often cost as little as $3 per month.

Today these scams are much more common in Eastern Europe. This is because there users get charged for premium texts on-the-spot rather than monthly.

Many (but not all) users will catch the extra charge on their phone bills, cancel the service and prevent the cybercriminals from ever getting their money. But an enterprising hacker can nickel-and-dime his or her way into relative richness.

Hackers do not represent the only mobile threat. Leaving your Wi-Fi and Bluetooth functionality activated when you don't need to do so represents another considerable privacy risk. Phones broadcast signals that reveal their model number and location information and now shopping malls are beginning to use this data.

By tracking phones, malls can get a good idea of their shoppers' demographics (even though there's no way to identify users, phone preference varies by age, sex and race), which shops their patrons visit and how the two correspond. If users download retail-specific apps, stores can also track when users enter and leave their premises and communicate accordingly. At least downloading an app at  allows the user to choose whether or not to participate.
               
Retailers are not the only entities interested in aggregating mobile data. Up until recently, recycling bins in London had the same functionality. The City of London wanted to gather data on cellphone usage without any apparent end goal in mind, and walking by a recycling bin (image below) while your cellphone's Wi-Fi is active would transmit your phone's build and location information directly to the British government.



Public outcry put an end to the invasive bins, but while the City of London was the first government entity to try such a tactic, it probably will not be the last.

In order to keep your mobile information private and safe, keep Wi-Fi and Bluetooth turned off unless you need them. This issue is not going to go away and will problem get more complex and confusing before there are any easy answers for the every day mobile user who wants to be mobile, socially active and.... secure.

Tuesday, September 3, 2013

Banking on Mobile Just Became More Secure

Oh how things change radically and quickly in technology. Just a few years ago security experts thought you would be out of your mind to access an online bank account from a mobile phone.

This is because "back in the day" mobile Web browsers hid URLs, making it easy for cybercriminals to impersonate banking sites. The Wireless Application Protocol mobile-Web standard offered limited security. Even after the introduction of smartphones, banks own stand-alone apps were often poorly designed.

"We've seen a few examples where it became clear the mobile finance apps didn't quite receive the same level of security scrutiny as their traditional counterparts," Roel Schouwenberg, a senior researcher at Kaspersky Lab, stated in a TechNewsDaily article as recently as May 2012.

The tide has now turned. Experts now say mobile devices may actually be safer to use than computers for online banking, in part because malicious software can be downloaded to a computer without a user knowing it.

Tuesday, July 23, 2013

SIM Card Security Flaw Discovered

It took a long time but the humble SIM card that sits within your phone, along with at least seven billion others, has finally been hacked. Of the seven billion modern SIM cards in circulation, it is suspected that hundreds of millions (yes, hundreds of millions) are susceptible. What does this mean? The hacks allow a would-be attacker to infect your SIM with a virus that sends premium text messages, or records your phone calls — and, in some cases, access the secure, sandboxed details stored on your SIM by mobile payment apps, giving a hacker access to your bank and credit card details.

SIM cards are not merely a piece of laminated memory that stores the data that your phone needs to connect to a cellular network. In actuality, the SIM card in your phone is actually a small computer, with memory, a processor, and even an operating system. As you can see in the diagram below, there is a chip beneath those gold contacts, and on that chip there is a processor, ROM (firmware that stores the OS and SIM apps), EEPROM (which stores your phone book, settings, patches), and RAM (for use by the SIM’s OS and apps). In the photo below of a disassembled SIM card, you can clearly see that this is quite a complex computer chip.

 
 
 
Unfortunately, like any computer chip that runs an operating system and apps, a SIM card can be hacked. In this case, modern SIM cards run a very simple OS that loads up Java Card — a version of the Java virtual machine for smart cards (of which SIMs are a variety of). Java Card essentially runs small Java applets, and each applet is encapsulated and firewalled (sandboxed) by the Java VM, preventing sensitive data from leaking to other apps. Your phone interacts with these apps via the SIM Application Toolkit (STK) to display information on your screen, and to interact with the outside world. To load apps onto the SIM or to update them, hidden text messages are sent by the carrier, containing over-the-air (OTA) programming in binary form. These messages are signed with a cryptographic key, so that the SIM knows that these messages have originated from a trusted source.

Now, German security researcher Karsten Nohl has discovered a way of finding out that all-important cryptographic key. By sending his own OTA (over the air) SMS's that aren’t signed with the correct key, he discovered that some phones pop up an error message that contains a cryptographic signature. Then, using rainbow tables (a list of plaintext keys/passwords and their encrypted equivalent), Nohl found he could discover the SIM card’s cryptographic key in about one minute. Once he had this key, he could send apps and viruses to the SIM card that can send premium text messages (racking up huge bills), re-route or record calls, collect location data — you name it, with access to the SIM, you can do just about anything.

And if that was not enough Nohl also found a separate bug in Java Card, essentially an out-of-bounds error (asking for the sixth item in a list when the list only contains five items), that can give an app/virus full root access to your SIM card — effectively breaking out of the sandboxing provided by the Java Card VM. With root access, these malicious apps could then obtain any data stored on your SIM, including your address book, or sensitive banking details stored by mobile payment apps.

According to Nohl, he estimates that out of 100 mobile phones, he could gain root access to the SIM card on 13 of them. SIM cards that use newer, stronger encryption (Triple DES), don’t appear to be susceptible to these attack vectors. Verizon and AT&T say they are not vulnerable to the vulnerabilities exposed by Nohl. In essence, mitigation of this attack comes down to the encryption standard used by your SIM card — so if you use a SIM that’s more than a few years old, you should probably get a new one. Most carriers will provide a new SIM if you ask and I would bet especially if you mentioned your knowledge of this new problem.

Monday, July 1, 2013

West Chester Connect Launches July 8, 2013

West Chester Connect officially launches next Monday, July 8. You can read the press release here.

You can also check out our "West Chester Connect - Citizen Guide" here.


West Chester Connect - Press Release
 
 


Friday, April 19, 2013

Cyber Criminals Looks Towards Mobile

Worms Like Mobile Too.
Symantec’s 18th annual Internet Security Threat Report is was issued yesterday. The report reveals that cyber criminals are increasingly scouring the Web for personal details in order to target their attacks. Armed with your information they can exploit security gaps in social networks and other sites to infect your system or steal your details.

It is no longer just your PC that’s at risk either; the report shows an alarming 58 percent increase in attacks on mobile devices with just under a third of these aimed at stealing data without the user’s knowledge. Android is the most targeted mobile platform as its open source nature makes it easier to hide malware in apps. Apple users receives a bas news as well because the report notes more than 600,000 Mac systems were infected by a single attack last April.

When it comes to the types of threat, the growth of ransomware continues with infections becoming more aggressive and harder to undo. I have written articles many times regarding ransomware threats and sadly I believe this trend will continue.

Another very scary statistic is that 61 percent of malicious sites are actually legitimate websites that have been compromised so you may be at risk even if you think you’re practising safe surfing.

Another alarming piece of information is the news this week issued by Microsoft that they believe 24 percent of all PCs are not protected by virus software today. This is bad for everyone because users who do not protect their PCs are the first ones to get infected and often complicate and threaten even PCs that are protected. I have written several articles in the past regarding free anti virus solutions so there is really no excuse for this.  You can learn about Microsoft's free anti-virus solution in my early article dated October 3, 2012.

Tuesday, January 8, 2013

Use PIN Protection On Your Mobile Devices

Protect Your Personal Data on Your Mobile Devices

Smartphones and tablets are mini computers, and if they get lost or stolen, others may be able to access your email and social networks, browse through your photos, files, and text messages, and access other accounts that you’ve downloaded apps for.

You can protect yourself by enabling the lock screen with a PIN number requiring a PIN or password before accessing your device in permitted.

Turning on PIN protection varies between devices, but you should be able to find it in your phone or tablet's settings app. A password or PIN isn't perfect, but it's a good first line of defense if your phone is lost, misplaced or ends up in the hands of a would be data thief. 

Thursday, January 3, 2013

Windows 8 Phone - Day 1

First let me apologize about my abscence from the "West Chester Tech Blog" for the past couple of weeks. The end of the year was very busy in my office and then of course the holidays were upon us and much of my time was consumed by Christmas & New Years. Anyway with all of that in the past and 2013finally here this fine blog is active again.

Thanks for sticking with me.

First on my agenda was switching from my iphone to a Windows 8 phone this week. I had read and continue to read many good reviews of Microsoft's new mobile OS. Therefore as 2012 was closing I knew that a month long demo was called for in early 2013.

I will say that I have high hopes for Microsoft's new mobile OS. With the integration of Microsoft Office, Sharepoint and SkyDrive there is a real possibility that the void left by RIM can finally be filled for those of us looking for an excellent mobile platform to fullfill our mobile needs both at work and play.

Today I switched to the Nokia Lumia 822 running Windows 8. I am going to end today's post there but do not fear because I will continue the adventure of switching from Apple's to Microsoft's OS tomorrow. As with most things in life it was not as easy to switch as it should have been. Today I was lucky enough to speak with tech support at Verizon Wireless, Nokia and even Apple.

Tomorrow I will report on the experience I had today when switching from the iphone to the Windows phone. During upcoming articles you will be able to follow me as I continue to make the transition from the very hip iphone to Windows 8.

Wednesday, January 12, 2011

Apple Takes a Swing at Android


At one point ATT’s iPhone was obviously the favorite and best Smartphone on the market. One has to only look back to earlier last year when Windows Mobile was struggling to compete and Android was learning the mobile game. Anyway things have surely changed during the past year or so in the mobile world. Windows Mobile 7 is actually getting some rave reviews and Android seems to get more functional and fun with each software upgrade.

Yesterday’s announcement from Verizon has the entire mobile market a flutter with activity and excitement. I admit, at one point yesterday I even felt of momentary shiver run down my spine (at least thats what I think that was). However after reading up on this new Verizon iPhone I have some serious concerns that anyone thinking about moving from an existing Smartphone should consider first.

1. Unfortunately, the iPhone 4 will only run on Verizon’s 3G CDMA network and not on its newly-launched 4G LTE network. There are Smartphones on the market now that take advantage of the new 4G network.

2. Has Apple fixed the antenna problem in this new iteration of the iPhone 4 for Verizon? Naturally, Apple hasn’t said that it has changed anything with the iPhone antenna. Why can’t Apple simply answer the question?

3. Once again you have 2 choices, 16gb or 32gb of storage. No room to upgrade the memory on your own. If you enjoy music and video on your Smartphone why should Apple decide (and limit) your local storage capability?

4. Of course the new iPhone5 is reportedly going to be hitting the market in June 2011. Does this not seem strange to you?

I think it is great news that the iPhone is finally available on another carrier but the world is a dark and scary place and things like this just don’t happen by accident. A strong possibility is that Apple’s strategy was to do this now simply to try and stem the growing tide of the Android wave.