Chapter 9 – Mobile Device Security
Mobile devices, especially smartphones, are small computers often constantly connected to the Internet. They can have many applications installed, allowing other ways to connect and communicate. Therefore, they should be treated similarly to desktop computers or laptops.
1. Introduction
Mobile devices, especially so-called smartphones, are now small, standalone computers. They are often constantly connected to the Internet via a wireless connection (WiFi) or a data connection from an operator. They also have several applications installed, enabling other connections and communication options (e.g., USB, Bluetooth, NFC). It is, therefore, necessary to treat them similarly to desktop computers and laptops. Their growth has been so rapid and spontaneous that users sometimes do not have time to realize the threats associated with their use.
2. What is a mobile device
A mobile device is generally a device that we can move or have with us at all times without needing permanent power from the distribution network via a cable, and wireless technologies are typically used for communication. The most widespread mobile device is the mobile phone, which experienced perhaps the most significant rise at the turn of the millennium when it was a device that could only make phone calls and transmit short text messages using the GSM network. Over time and with the development of electronics, we now know a mobile phone as a so-called smart device with its own robust processor data storage on a memory card or directly in the internal memory. The device allows communication using modern data networks from the operator or a wireless WiFi network, and it is easy to connect it to other devices such as smartwatches or car radios. Using NFC technology, simulating a payment card and paying at merchants supporting contactless payment transactions is possible. In short, today’s mobile devices are essentially small computers, which must be treated as such.
3. Mobile device software
As stated in the chapter on computer security, we should pay attention to the up-to-date software, i.e., the operating system and all installed applications, both in the case of computers and laptops and in the case of smart mobile phones. It is not as easy to connect an external memory device to a mobile phone as it is in the case of a desktop computer (CD, DVD, USB flash drive), so other applications are installed from the so-called manufacturer’s repositories. In the case of Android, this is Google Play. In the case of Apple, this is AppStore, etc. Although the manufacturer continuously checks these repositories for viruses, it cannot monitor everything, and dangerous applications may be distributed. After installation, it is necessary to configure the application correctly and grant it the correct permissions to use the device’s resources.
What do you think?
Does a simple app to turn on the camera light need permission to use storage, device location, and camera? There is no storage and no device location. Yes, the camera, because the LED bulb serves as a light when taking pictures and is therefore controlled by the camera.
A virus can also enter a smartphone in other ways, such as by opening a dangerous e-mail attachment, visiting a malicious website, or downloading a virus from the Internet. Like desktop computers, smartphones should have an antivirus solution installed to combat viruses.
In addition to the classic threats that we defend against with antivirus, there are also other threats specific to mobile devices, which is why additional components are added to the antivirus solution. Together, they are referred to as endpoint security.
4. Access to the device
We often carry our mobile devices or always have them with us, so there is a higher risk of losing them and thus misuse by an unauthorized person. A screen lock should, therefore, protect the mobile device. There are several ways to unlock the device.
The so-called gesture is quite popular, where it is possible to unlock the device by connecting the displayed dots. This method is challenging to guess, but it has a disadvantage if a thief notices the gesture before stealing it. Sometimes, it is also possible to guess based on fingerprints on the display.
The second option is to replace the gesture with a PIN here, which is more difficult to detect; on the other hand, choosing number combinations that cannot be guessed from knowing the person is necessary. For example, avoid birth number, phone number and simple combinations of the “procedure” type (1 2 3 4 5) or repetition of one digit (1 1 1 1 1).
Another option for unlocking is biometric methods, such as fingerprint verification or facial recognition. Still, they also have disadvantages, for example, that they cannot be changed in case of compromise.
Mobile device protection doesn’t have to be passive
Endpoint Security can, for example, take a photo with the front camera and send it to the owner along with location data if there are several consecutive unsuccessful unlock attempts. If necessary, the phone can also be wiped remotely.
Essential applications, such as reading e-mail, mobile banking, etc., should be protected with a unique code, the so-called application lock (PIN, fingerprint, etc.). This is a multi-level protection (see the chapter Basic Principles and Motivations). So, even if the phone lock is bypassed, a vital application cannot be launched.
5. Protecting data on the phone
The above screen lock methods will protect the phone from unauthorized access to its functions and the data stored in it, but unfortunately, that is not all we should protect in the case of a smart mobile phone. A mobile device typically contains a SIM card, which can be easily removed from the phone and inserted into another device. If our device is stolen, for example, we do not want someone to be able to use the SIM card and impersonate us in some way (i.e., use our phone number). It is, therefore, advisable to protect the SIM card with a PIN.
Another removable card that is often found in mobile devices is a memory card, on which photos, backups, etc., are stored. The data on the memory card should be encrypted so that it is unreadable without knowing the key. Endpoint Security can again take care of data encryption. If encryption is not possible, you need to consider this and not store confidential data on the memory card.
Speaking of protection against a possible thief or loss of the device, you also need to think about regularly backing up the stored data, especially contacts and photos. Smart mobile phones can take excellent images today, and we always have them. They are, therefore, ideal for capturing various life situations, taking snapshots, etc. Creating regular backups is necessary so we do not lose this data.
6. Geographic location
A mobile phone can geolocate, i.e. it can determine its actual geographical location. Ordinary mobile phones determined their location by calculating the signal strength and probable distance from the transmitting stations (so-called BTS, Base Station System), whose location is known and unchanging. Using triangulation, it was possible to determine the device’s approximate location.
Smarter mobile devices have a much more accurate GPS receiver (Global Positioning System). GPS is a global satellite positioning system operated by the US Department of Defense. Other similar systems, such as the Russian GLONASS or Galileo, are funded by EU states. How such a system works (significantly simplified):
- For the system to work, at least 24 GPS satellites must orbit the Earth. At any given moment, at least four are visible from any (almost) location on Earth.
- Each satellite constantly transmits a pair of exact data to Earth: its position and time.
- The GPS receiver in a smartphone/tablet can calculate its position on Earth from data from 4 (or more) satellites with an accuracy of approximately 110 meters.
- The entire navigation system is very complex, and the calculations must consider many complications and consequences of physical laws.
Applications can use this location if we allow them in the device’s operating system. Then, the smartphone can be used as a navigation tool; it can provide information about the weather forecast in the current location, geolocation data, and sometimes even azimuth in the photos taken.
7. Two-phase authentication on a mobile device
Two-phase authentication is a process that includes two different independent methods of verifying the user’s identity. The first phase can be entering a password, and the second is copying a code sent via SMS to a preset number. A potential cyber fraudster must guess or otherwise obtain the password and get the device where the verification code is received.
The problem arises if the password is filled in on a mobile device (smartphone) and, at the same time, the second-phase verification code is received on the same device. If the device is stolen or attacked, the positive effect of the second phase of verification disappears.
8. Summary
In this chapter, we described a mobile device as a small computer, i.e. a device with many functions and options, which we can carry from place to place or keep with us at all times. It is necessary to secure a mobile device like any other computer, maintain up-to-date software, and consider the higher risk of loss, damage, or theft. It is, therefore, necessary to lock the screen and enable unlocking after entering a PIN, gesture, fingerprint, or face verification.
We must set up applications installed on the device correctly and grant them only the permissions they need to run. We should protect the data on the phone with encryption because anyone can remove the memory card if the device is stolen and read it on their device. We should also think about regular backups so that we do not lose valuable data if the device is lost. It is also necessary to remember that the phone is capable of geolocation and, therefore, be aware that it is possible to determine the actual geographical location. Some legitimate applications use this, but can also be abused to lose privacy.
The device we use to verify the second phase of two-factor authentication must be independent of the device where we enter our name and password. Therefore, using a single device for these activities is not advisable because the benefit of the second phase is lost.