Showing posts with label spyware. Show all posts
Showing posts with label spyware. Show all posts

Thursday, July 10, 2014

Top 10 forgotten mobile threats revealed

Do you have a smartphone? Of course you have. Let's say you even use some encryption for your mobile calls. Do you know what threats you are exposed to when using it? Keep reading...

Just for you. Really?

1. Spyware
Spyware run on smartphone and can record all communication. It can send the recorded communication later or broadcast it live. Spyware is hidden and difficult to detect.

2. Record microphone
A malware can record the microphone of your smartphone can send or broadcast the communication it captures.

3. Man-in-the-middle attack
A malicious outsider inserts him or herself into a conversation between you and your party and gains access to your private information.

4. Stealing encryption keys
The encryption keys can be stolen before or during the communication. It is a common problem of encryption software. However it is possible to physically protect encryption keys with cryptochip or TPM technology. It requires a hardware piece in your smartphone, typically integrated into a micro SD card.

5. Cracking encryption keys
Cracking the keys can be easier if you use public key encryption. Since public keys are sent over the Internet and define the key space, they make cracking a lot easier. You can find a nice explanation of the mathematical background here: https://www.udacity.com/course/cs387.

6 to 10
Find the rest in the infographic below. Just click on it. Hover or tap the threats.

 Mobile Security Threats Skycraper


Please share and like :-) Thank you!



Sunday, November 24, 2013

Cryptohip, security card or trustchip


As mobile communication encryption is getting more and more important, several companies announce their solutions build around micro SD security cards. You get this special micro SD card (security card, cryptocard or trust chip, several names for the very same hardware piece), put it into your smart phone's micro SD slot, and your communication is secured. Or not?

With this new development a myth arose, namely that all micro SD security card based solution provides eavesdrop-proof mobile communication. These systems are more secure than purely software based solutions, that's no question. However using a micro SD security card in a mobile encryption solution does not guarantee eavesdrop-proof communication.

Anyone who thinks it over comes to this conclusion. What happens if a smart phone has a micro SD card with an integrated trust chip or security chip in its micro SD card slot, but a spy ware running on the phone reaches the phone's microphone during calls? The spyware records the conversation, and the conversation is tapped before it even gets to the trust chip. Or what if the trust chip uses standard public key (PKI) encryption, and sends out keys needed to encrypt messages? Well, it is a big help for anyone who tries to crack into the system. Knowing the encryption key significantly reduces the time to figure out the decryption key, therefore to get the message.

Encrypted mobile communication solution has to be chosen based on technical implementation of the encryption system, not based on marketing buzzwords. 100% percent security can be reached only with triple level protection, when a hardware - micro SD cryptocard - protects the encryption keys, a software - an app running on the smart phone - protects against malware and spyware, and a unique encryption solution, that provides eavesdrop-proof communication.

If a company does not take this into consideration, choosing a wrong solution will hurt badly sooner or later.