Showing posts with label mobile security. Show all posts
Showing posts with label mobile security. Show all posts

Thursday, 7 July 2016

The Future of Mobile Security

Mobility is the new normal for enterprise users. With forecasts from the GSMA predicting that 80 percent of adults on earth will have a smart phone by 2020 these always connected and always on devices are the most popular personal computer in history.

The use of smart mobile devices (smart phones and tablets running mobile platforms such as Apple iOS and Google Android) in the enterprise is rising rapidly each year. Figures from Citrix indicate that the number of smart mobile devices (SMD) managed in the enterprise increased by 72 percent from 2014 to 2015.

What is surprising, however, is that the enterprise is not fully embracing mobile. Whether it is an employee-owned Android smart phone or a company-issued and controlled iPhone productivity-enhancing enterprise services are still relatively scarce within the enterprise. Outside of email and calendar applications there are relatively few examples of enterprise mobile apps. This differs from the current situation with consumer adoption of mobile where it dominates social, financial services, commerce and entertainment.

So why is? In the latest white paper from Goode Intelligence, the issues facing the enterprise in delivering services to mobile is explored. The report discovers that a mixture of technology constraints, security concerns, compliance to regulation and privacy law are having an impact of restricting mobile enterprise services.

Enterprises do face a challenge in enabling productivity enhancing applications to be available through smart mobile devices but there are ways in which they can combine the convenience of mobility and strong security mechanisms that meet company security policy and comply with regulation. In covering mobile security since 2007 I have learnt that next generation mobile security solutions should have these characteristics:
  • They should focus on users
  • Support agile multi-factor authentication (MFA) with a choice of authenticator to match the context 
  • Be able to provide mobile-based single-sign-on (SSO)
  • Must protect the data, both at rest and during transmission
  • Be available in a simple to use and unified security offering
I believe that there are very few solutions that offer a unified solution that supports these characteristics and this is why we have seen limited adoption of full-throttled enterprise services for mobile. Often, an organisation will have to mix and match technology solutions to support this vision and this can be expensive and time-consuming. A solution that combines the functionality and features of a next generation mobile security solution is the Sign&go Mobility Center from Ilex International

This product provides an integrated security solution to solve the enterprise mobility conundrum; mixing convenience and mobile security in a unified product and provides:
  • Strong Multi-Factor Authentication supporting one, two or three factors
  • Mobile SSO
  • Data Protection in a secure container
Without the combination of these features, organisations will remain limited in what productivity-enhancing mobility solutions they can deliver. 



Friday, 16 November 2012

Is mobile banking the most secure way of banking yet?


In the world of security there is often a tendency to accentuate the negative. This can often be justified. Malware can lead to data/identity theft and financial fraud and a DDoS attack can create havoc by denying access to a web site or service etc.

However, security can also be a positive factor – an enabler. For financial services, each time we use our debit or credit cards in an ATM or POS terminal in a retail store or use them on an eCommerce website we have a fair level of assurance that all parties are protected from fraud - where would eCommerce and financial transaction integrity be without cryptography?

Security technology coupled with sound risk management has been at the heart of the financial services industry for many years. This combination of security technology and risk management must be applied to new methods of providing financial services to bank customers including one of the hottest channels for providing financial services – Mobile.

Mobile devices, from feature to smart phones and from tablets to phablets, have become a vital endpoint for accessing banking services. The mobile banking channel is viewed as one of the most important channels for delivering financial services to bank customers. These are the same bank customers that are rapidly adopting these ‘smart mobile devices’ and are using them as their primary digital device – the first screen for consuming work/leisure digital content.

With the rush to mobile by financial institutions for banking and payment services there have been serious questions asked on whether mobile is secure enough? There is no denying that smart mobile devices are increasingly being attacked for financial fraud and identity theft. A combination of platform vulnerabilities and an increased desire from hackers and fraudsters to attack has led to a situation where mobile devices are under threat. Mobile malware is on the rise, especially affecting Android, and banking services, including some mobile-based Two-Factor-authentication (2FA) services, are under targeted attack.

Much has been commented on mobile vulnerabilities and whether security vendors are creating scare stories to make mobile users install their products but my experience tells me that much of this is not FUD but FACT. As money moves onto mobile devices than it is inevitable that the criminals will follow.

This has to be one of my favourite quotes (although the quote may in fact be an urban legend) and I apologise for repeating it again here but it is such an important message and provides context for this blog. One of the US’s most prolific bank robbers from the 1920s to the 1950s was a man named Willie Sutton (AKA “Slick Willie”). In his 40-year ‘career’ he robbed over one hundred banks and stole an estimated $2 million (a big number in old money). When asked why he robbed banks he replied “because that’s where the money is”. Why is this important to today’s ever mobile world? Well I think it is pretty obvious. Soon there will be more mobile phones than people on this planet and every one of these devices has the capability of banking (including full transactional banking). From the streets of Nairobi, Kenya, to the avenues of New York, USA, people are accessing their bank accounts and transferring money using mobile devices – be it an old Ericsson ‘brick’ or the latest Apple iPhone; using SMS or a mobile App. Its where the money is…

So, is mobile banking a secure method for banking and is it the most secure yet? I believe that mobile banking has the ‘potential’ to be more secure than traditional online banking and comparable with other banking channels. Whether current deployments of mobile banking are secure enough at the moment is another question. The key word is ‘potential’. Mobile phones and smart mobile devices have the capability to offer very good levels of security for banking purposes. Whether it is leveraging the hardware security capabilities and trusted environment that the Secure Element (SE) offers or adopting strong mobile-based Multi-Factor Verification (MFV), mobile devices can play an important part in ensuring trust between the bank customer and their bank.

In a recently published report from Goode Intelligence written by Ron Condon, Senior Analyst, “Mobile Banking Security Insight Report”, we investigate the risks to mobile banking, how banks are securing the mobile banking and analyse the state of security for this channel.

We have interviewed some of the leading lights in the world of banking security and have asked them to recommend ways in which mobile banking can be a trusted channel for financial institutions – actionable steps that banks can adopt to ensure that their customers are secure when banking on their mobile devices.

I can share some of this advice here. When designing and deploying mobile banking solutions financial institutions should, at a minimum:
  1. Use the power of the mobile phone to create an encrypted communication channel between user and bank
  2. The phone’s “fingerprint” should provide one factor in authenticating the users (the PIN provides another)
  3. Consider using the other facilities on the phone for stronger authentication (biometrics, geolocation)
  4. Monitor apps stores for any rogue apps that purport to represent your company – and kill them quickly
  5. Introduce a plan for updating mobile banking apps
  6. Ensure that mobile banking apps are security tested
  7. Integrate mobile apps with other banking channels, so that security lessons learned in one channel benefit the others
  8.  Educate users about system hygiene when upgrading their handset, and disposing of an old one

I hope this blog has been useful for you? Please feel free to contact me to find out more about mobile banking security and our research. You can follow us on twitter @goodeintel.



Friday, 9 November 2012

A Smart Mobile Identity for our smart mobile lifestyle


I must admit that I didn’t come up with the term Smart Mobile Identity. For that I have to thank Joey Pritikin at AOptix who I was lucky enough to meet at the recent Biometrics exhibition and conference in London during the last week of October 2012. I first came across the term in a presentation that Joey gave at last year’s Biometrics conference where he discussed how standard smart phones can be leveraged for biometric purposes, including user authentication and  identity verification [Presentation: Smart Mobile Identity – Beyond Single Purpose Handheld Biometric Devices].

In my opinion, the term Smart Mobile Identity really sums up the next generation of mobile-based authentication and identity verification solutions – something that I have been involved in for the best part of ten years through various roles including my current one as Managing Director of Goode Intelligence.

To me, Smart Mobile Identity is about leveraging the capabilities of a modern smart mobile device (SMD) to ensure that our identities are proven or verified when identity proof (authentication if you like) is required. Not only for proving identity when accessing digital services through a desktop computer but also for mobile initiated access and even when we present ourselves in the physical world; at a country border or when accessing health or social security services. I also include proving our identity when accessing digital services using other connected devices, such as gaming consoles, automobiles, smart TVs etc; adaptive and agile authentication and identity verification to support the Internet of things. As someone who owns an Xbox 360 Kinect device, the idea of using a voiceprint or a facial scan to access Xbox LIVE is a realistic possibility.

For mobile device-based authentication and identity verification solutions, the simplest scenario is being sent a one-time-password (OTP) via SMS when authenticating ourselves into a network-based service, e.g. Google’s Authenticator or 2-step verification process. However, this is changing rapidly and we are in the midst of an evolution in mobile-based authentication and identity verification solutions; moving away from porting existing, non-mobile centric, services to the mobile to designing solutions specifically for mobile. Using the microphone for voice biometrics, a GPS sensor for Geo-location, a combination of the accelerometer and touchscreen for continuous behavioural assessment, securely storing digital certificates in the SIM or Secure Element (SE) and the camera for facial and eye vein biometrics (take a look at start-up EyeVerify for this). All these examples work with standard SMDs now; no need for any specialist equipment.

In addition to these examples, new opportunities are being presented with the next generation of SMDs that contain new types of embedded sensors, including NFC, embedded fingerprint and voice recognition sensors. You can also adapt existing SMDs with add-on sleeves that enable fingerprint recognition (Precise Biometrics Tactivo sleeve) and can support smart cards and NFC. The need for single-purpose devices to capture and verify biometrics in the field may become obsolete as a result of these developments.

Smart mobile devices offer so many opportunities for authentication and identity verification and this blog can only scratch at the surface of what can and will be offered – some of the solutions even encroach into the realms of science fiction. I was fascinated to come across the iTravel patent from Apple detailing what the Cupertino tech giant believes to be the possibility of using a mobile wallet for travel purposes. Managing the end-to-end travel process from reservation, to ticket receipt/validation, check-in and baggage claim through to identification at border control. I think all but the last scenario achievable now but I believe that we are far off from using our mobile devices as virtual passports.

That said, perhaps we are seeing pieces of the jigsaw that tell us how Apple will integrate the recently acquired fingerprint sensor technology from AuthenTec – an agile, and very personal, way to protect our wallets or in Apple’s case our Passbook. Swiping a finger to lock and unlock our digital wallets.


Every discussion that I have with technology companies involved in this space, and this includes many of the major authentication and biometric vendors, involves how best to utilise the smart mobile device for authentication and identity verification purposes. My recent attendance at the RSA Europe conference and Biometrics Conference, both held in London, was largely occupied with meetings with clients and tech vendors that were investing serious R&D resources into this area of technology.

A number of forward looking organisations and technology vendors are already leveraging the capabilities of the smart mobile device for authentication and identity verification purposes. Through my work at Goode Intelligence I have been exploring the capabilities of mobile devices for authentication and identity verification and this includes the recent publication of two free-to-download white papers; Two-Factor Authentication Goes Mobile and The Case for Mobile MFV.

Goode Intelligence will continue to track this market and you can expect some new publications covering smart mobile identity in the coming months.

Please get in touch if you want to discuss this further or are a technology innovator working in this exciting field. 

Friday, 27 July 2012

What does Apple's acquisition of AuthenTec tell us about biometrics on mobile devices?


I am not surprised with the news that Apple has acquired mobile security and fingerprint sensor vendor AuthenTec in a deal worth $356m. 

I have been following the mobile security market since 2004 and this has included the publication of a report for my research and consultancy company, Goode Intelligence, on mobile biometric security published in June of 2011. Smart Mobile Devices (SMDs), a term that we use to define smart phones and tablets, have become the portable computer of choice for both personal and business use. However, questions remain as to the effectiveness of security controls for these devices with the recent Black Hat conference in Las Vegas being dominated by presentations that detail the vulnerabilities of these devices. 

Apple's acquisition of AuthenTec, who are not just about fingerprint sensors, is a positive move by the Cupertino-based company and could lead to next generation Apple products having embedded security controls, both hardware and software-based. 

As seen in the Goode Intelligence annual mSecurity survey report, Apple iOS has become the number one choice for the enterprise. This position will be well and truly cemented if Apple strengthens its security as a result of the AuthenTec acquisition. 

Will this mean embedded fingerprint sensors in next generation Apple products including the iPhone and the iPad? With the acquisition of AuthenTec this has become more likely. I interviewed AuthenTec as part of my research into the mobile biometric market and back in May 2011 they said this; “the integration of fingerprint sensors into wireless smart phones, feature phones and tablets is in its early stages and will accelerate.” Accelerate as a result of being in every iPhone and iPad? A distinct possibility.

Embedded fingerprint sensors on mobile devices are being used to protect the phone (augment standard phone lock as my Motorola Atrix 4G admirably does) and to provide authentication to support NFC-based transactions, including payments, at physical locations. AuthenTec has been doing well in this market since 2004 when it first supplied fingerprint sensors for Fujitsu mobile phones to be used to secure mobile payments for NTT DoCoMo in Japan. With rumours that the next generation iPhone (iPhone 5) will support NFC, will Apple be combining biometric authentication through the use of an embedded fingerprint sensor for mobile payments at the physical point-of-sale?

I was pretty cautious when forecasting the growth of mobile biometric security products and services back in 2011, predicting that the market would grow to 39 million users by 2015. This quote from the report highlights this"The market is currently slow; but pressure is growing. Things could change rapidly, from an interesting concept to a 'must have' for all smart mobile devices."

I did go on to make a conditional statement that is very relevant with this news;

"However, this could all be thrown on its head with the introduction of embedded biometrics on mobile devices by one of the major manufacturers – and not just a single product line but standard on all mobile phone products. The market is always eagerly waiting for the next generation of Apple iPhones and rumours are circulating that Apple iPhone 5 may include some form of biometric technology."

Could this news be the catalyst to accelerate the adoption of biometric security onto smart mobile devices - there is now much more of a chance of this happening. I look forward to seeing how Apple build on AuthenTec's success in the mobile security world.

For news, opinion and analysis on all things mobile security follow me on Twitter - @goodeintel





Friday, 25 May 2012

Lies, damned lies, and statistics… What do statistics tell us about the real risk from mobile malware?


The Evidence
Mobile malware, in particular Android mobile malware, is rising. This is a fact.

It has been rising slowly since 2004, as the figures below from McAfee detail, and the rate has been accelerating since autumn 2011 when a number of high-profile cases of Android mobile malware hit the press. This included Google’s official Android Appstore, then called Market now called Play, being used as a method to distribute Trojanised apps to unwitting customers. GGTracker [1], SuiConFo [2] and RuFraud [3] were all Trojanised Android apps that were attempting to defraud consumers largely by attacking the Premium Rate Service industry through the unauthorised sending of Premium Rate SMS messages.






Mobile Malware Explodes, Increases 1,200% in Q1/2012

Source: McAfee Threats Report: First Quarter 2012


“A comparison between the number of malicious Android application package files (APKs) received in Q1 2011 and in Q1 2012 reveals a more staggering find — an increase from 139 to 3063 counts.” Mobile Threat Report Q12012, F-Secure

Figures from Goode Intelligence’s annual mSecurity survey back this up with a rise in the number of reported mobile malware incidents – read infection – in the workplace from 7% in 2009 to 24% late in 2011; nearly a quarter of all organisations. This figure is alarming.

GI mSecurity Survey: Has your organisation experienced a mobile malware incident?

We are also seeing evidence from other sources including telecommunications regulators. In the UK, the country’s premium rate regulator, PhonepayPlus, has been involved in investigations into premium rate fraud directly caused by mobile malware.



With the assistance of Goode Intelligence, (providing research and analysis into the link between mobile malware and PRS fraud), PhonepayPlus are proactively tracking instances of mobile malware that are attacking PRS.

One of these investigations hit the news recently and resulted in a hefty £50,000 fine for a mobile aggregator, A1 Aggregator Ltd based in Latvia, for managing the SMS shortcodes that were used in the RuFraud malware attack. From late November 2011, after receiving 34 complaints from consumers of unauthorised PSMS charges on their phone bills, including an individual losing around £80, the regulator investigated further and tracked the fraud down to Trojanised versions of Android Apps distributed via Android Market (Play). The fake apps included Trojanised versions of Angry Birds Assassins Creed and Cut the Rope. Consumers had no knowledge of three PSMS messages being sent every time the Trojanised app was started. Each PSMS message was costing the unwitting user £5.00.

In this one case 1,391 mobile numbers in the UK were affected and an estimated £27,850 worth of fraud was attempted. Due to the swift action from the regulator, the shortcode was suspended and none of the £27,850 of UK consumer’s money was able to reach the fraudsters.

PhonepayPlus found evidence of the RuFraud Trojan operating in 18 countries.  Thankfully the UK has a regulator that is well advised and has put into place procedures to ensure that this emerging area of PRS fraud is actively monitored. What about the other 17 countries that were targeted by this malware? How many consumers have been affected and how much financial damage has been done in regions where regulation is not so proactive?

The Risk
There is evidence from multiple sources, including our own, that mobile malware is rising and it is targeting consumers for, amongst other reasons, financial fraud.

On the face of it, it seems that the risk of malware infection is getting stronger and both consumer and enterprise mobile users should take preventative measure to counteract that threat. These preventative measures include being cautious when downloading Android apps from appstores, including Google Play and from third-parties, and checking the permissions carefully. There is also the option of protecting your mobile device with a mobile security product that is proven to be effective in preventing mobile malware.

Android is being targeted as it has a more open platform for downloading and installing apps and it is becoming the number one mobile platform around the world. This makes it the number one target for malware in today’s mobile market.

However, we should also be cautious in assessing the current risk to both consumers and enterprise users from the threat of mobile malware. Apple’s iOS has been free of malware and there have been very small numbers of malware that have been known to affect BlackBerry devices. 

Additionally, Google should be applauded in acknowledging the threat from Trojanised apps in Play by deploying a solution, Bouncer [4], which attempts to detect mobile malware on upload. Bouncer was announced early in 2012, although it has been running during 2011, and it is probably too early to state how effective the solution is in preventing mobile malware on Play [5].

There is also an acknowledgement from third-party Android appstores that security is important as a business differentiator. Goode Intelligence surveyed a number of the third-party appstores and was pleased that over two-thirds of the respondents (68 percent) replied with a ‘yes’ to the question “Do you think there is a commercial benefit for an app store to offer malware detection and prevention technology?” The tools are available for these third-party Android appstores with AVG [6] amongst the vendors offering specific security solutions aimed at preventing the spread of malware from these appstores.

Yes the statistics do tell us of double and triple digit growth in mobile malware, mainly targeting the Android platform. However, the risk is still relatively low and the financial fraud that is being committed as a result of mobile malware is currently low in value. These are still early days in the history of malware targeting mobile platforms and indications are that the business drivers for attacking these platforms is growing which could result in the situation getting worse – especially in the short-to-medium term.

And in answer to the question of attacks on Apple iOS, will this happen? You betcha! As the famous US bank robber, Willie Sutton, said in response to the question why he robbed banks; "because that's where the money is." Whether they will succeed is another matter and the topic for another blog.

Alan Goode
May 2012









[2] Although this article from Andy Greenberg on Forbes questions how effective Bouncer is: http://www.forbes.com/sites/andygreenberg/2012/05/23/researchers-say-they-snuck-malware-app-past-googles-bouncer-android-market-scanner/
[3] Press release in the partnership between AVG and Livewire: http://www.avg.com.au/news/Livewire-Mobile-partnership/

[5] Covered by Denis Maslennikov of Kaspersky Labs in this blog: http://www.securelist.com/en/blog/208193261/SMS_Trojans_all_around_the_world
[6] Covered by Lookout Mobile Security in this blog: http://blog.mylookout.com/blog/2011/12/11/european-premium-sms-fraud/

Tuesday, 6 March 2012


Back from MWC#1: The time is right for mobile biometric security

My feet have just about recovered from the many miles walked during the recent Mobile World Congress in Barcelona – I even had to dodge the barricades put up to contain the student protesters (I counted twenty protestors and a couple of hundred Police) to congratulate Alan Giles and the team at Fiberlink after picking up a GSMA 2012 Mobile Award for “Best Enterprise Mobile Solution” for their MaaS360 MDM solution. A very worthy winner.


As a GSMA 2012 judge myself, I was honoured to be chosen to judge the "Best Technology Product or Solution for Safeguarding and Empowering Customers". This was won by Cloudmark for their Mobile Messaging Security Suite. 

Global Bilgi for Turkcell Voice Verification
I was very impressed by all of the nominees in this category and was delighted that one of the nominees that made it to the shortlist was from a mobile network operator that had deployed a biometric security solution that supported mobile devices; Turkcell’s Global Bilgi for Turkcell Voice Verification voice biometric service, powered by PerSay’s VocalPassword technology provided by Nuance Communications. The solution uses a biometric speaker verification system that verifies a speaker’s identity using acquired voice samples. Samples of the caller’s voice are converted into voiceprints, or unique algorithms based on the specific characteristics of the voice that are used to authenticate and prove identity of Turkcell customers calling into their call centre. The solution replaces a 4-digit PIN-based authentication solution and has proved to be very successful with a reported four million enrolled voiceprints.[1]

My research at Goode Intelligence into the market for mobile biometric security products and services concluded that voice recognition services would be one of the biometric modalities that would be successful in what are, the pioneering stages of biometric security adoption on smart mobile devices (SMD).

VoiceVault
Another technology vendor that has developed a very interesting voice recognition product is the UK-based technology vendor VoiceVault. I was speaking with their Director of Product Marketing recently, Nik Stanbridge, who was starting to see a change in the market with “significant opportunities being turned into contracts”. Both Nik and I agree that we are seeing positive signs of growth in the mobile biometric security market, largely driven by SMDs becoming the “key entry points” for much of our personal and business lives. This trend is being accelerated by mobile voice-based solutions including Apple’s SIRI that according to Stanbridge, makes “people less reluctant / embarrassed at the thought of speaking into a mobile device”.

VoiceVault’s solutions are focussed on identity verification and transaction authorisation for two main use-cases:
  1. On the device itself (phone lock / unlock)
  2. As part of a device-based app’s mechanism for logging onto a website - a high-security replacement for a password

Mobbeel
Another vendor that was showcasing their mobile biometric security solutions during MWC was Spanish-based vendor Mobbeel. I have been following their progress for some time now and was pleased to catch up with Rodrigo Sanchez Gonzalez, CTO, and Abraham Holgado Garcia, Research and Development Director, on their stand in the Spanish area of La Fira Courtyard.

Mobbeel are a relatively young company that have become pioneers in the world of mobile biometric security. Their strength is to use the standard features of a modern mobile device; touchscreen, camera and speaker, fast processor, to support a variety of biometric modalities including signature, iris, facial, hand and voice recognition.  Unlike one of the other, much talked about, mobile technologies, Near Field Communication (NFC), their solutions are not reliant on an OEM to embed specific hardware, such as a fingerprint sensor.

I really like this company as they are not just developing ground-breaking technology but developing use-cases and stories to educate the market. Market education is sometimes extremely useful in emerging technologies such as this. Take a look at their video channel to see what I mean.

Fujitsu
Just across the courtyard area where Mobbeel were showcasing their technology was the Japanese based OEM, Fujitsu that used MWC to launch a new range of SMDs to the European market. As well as being able to take these devices into the shower or swimming with you (their waterproof capabilities were ably demonstrated by an army of suitable wet-weather attired exhibitors) these quad-core powered mobiles include embedded fingerprint sensors.

Using the same AuthenTec supplied fingerprint sensors that have been powering NFC-based physical payments in Japan through mobile network operator NTT DoCoMO, Fujitsu aims to differentiate its devices from the crowd.

As someone who regularly uses a fingerprint sensor on his Motorola Atrix 4G (another example of an AuthenTec supplied fingerprint sensor) to protect a device from unauthorised access I can definitely see the advantages of such a technology. However, Fujitsu, needs to release APIs and SDKs into the developer community to enable these devices to support other authentication and identification features. This will ensure that this technology becomes a must-have and not a maybe technology.

The time is right for mobile biometric security
One of my roles as MD of Goode Intelligence is to track emerging technologies in mobile security and to predict whether these technologies will succeed and enter the mainstream.

My research into this sector started over one year ago and resulted in the publication of an analyst report in June 2011, “mobile phone security – analysis and forecasts 2011-2015”. In the report I predicted that a biometric groundswell is building for Smart Mobile Devices. The market is currently slow; but pressure is growing.

My subsequent tracking of this market and the buzz that was surrounding this technology at this year’s MWC in Barcelona reconfirms my view that that conditions are ripe for rapid change; for biometrics to move from an ‘interesting concept’ to a 'must have' for all SMDs. 




[1] case study: Turkcell Global Bilgi Nuance VocalPassword™ Deployment Achieves Industry-Leading Adoption Rates (December 2011)