<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Sekiur My Thoughts &#187; smartphone</title>
	<atom:link href="http://blog.sekiur.com/tag/smartphone/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.sekiur.com</link>
	<description>VoIP, Mobility, Security, Open Source, Science, Politics, and Technology.</description>
	<lastBuildDate>Wed, 24 Aug 2011 19:46:24 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
		<item>
		<title>Mobile Forensics</title>
		<link>http://blog.sekiur.com/2010/03/mobile-forensics/</link>
		<comments>http://blog.sekiur.com/2010/03/mobile-forensics/#comments</comments>
		<pubDate>Sun, 07 Mar 2010 21:39:04 +0000</pubDate>
		<dc:creator>Jose Vicente Ortega</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Android]]></category>
		<category><![CDATA[AT&T]]></category>
		<category><![CDATA[blackberry]]></category>
		<category><![CDATA[forensics]]></category>
		<category><![CDATA[Handhelds]]></category>
		<category><![CDATA[IPhone]]></category>
		<category><![CDATA[Mobile device]]></category>
		<category><![CDATA[smartphone]]></category>

		<guid isPermaLink="false">http://blog.sekiur.com/?p=863</guid>
		<description><![CDATA[<p>With the explosion of mobile devices there is little doubt that the number of security incidents were a <a class="zem_slink" title="Mobile device" rel="wikipedia" href="http://en.wikipedia.org/wiki/Mobile_device">mobile device</a> is involved will also increase exponentially.</p> <p>My next couple of posts will look at what is takes to perform forensics on mobile devices targeting specifically the <a class="zem_slink" title="iPhone" rel="homepage" [...]]]></description>
			<content:encoded><![CDATA[<p>With the explosion of mobile devices there is little doubt that the number of security incidents were a <a class="zem_slink" title="Mobile device" rel="wikipedia" href="http://en.wikipedia.org/wiki/Mobile_device">mobile device</a> is involved will also increase exponentially.</p>
<p>My next couple of posts will look at what is takes to perform forensics on mobile devices targeting specifically the <a class="zem_slink" title="iPhone" rel="homepage" href="http://www.iphone.com/">iPhone</a>, the <a class="zem_slink" title="BlackBerry" rel="homepage" href="http://www.blackberry.com/">Blackberry</a> and the <a class="zem_slink" title="Android" rel="homepage" href="http://code.google.com/android/">Android</a> platforms.</p>
<p>Some interesting statistics on the iPhone in particular and the number of them that <a class="zem_slink" title="AT&amp;T" rel="homepage" href="http://www.att.com/">AT&amp;T</a> activated in the last couple of years. As can be seen below the number of iPhones activated in the 3rd quarter 2009 was 3.2 millions devices in the US alone.</p>
<p style="text-align: center;"><a href="http://blog.sekiur.com/wp-content/uploads/2010/03/att_activations.jpg"><img class="aligncenter size-full wp-image-882" title="att_activations" src="http://blog.sekiur.com/wp-content/uploads/2010/03/att_activations.jpg" alt="" width="400" height="248" /></a></p>
<p style="text-align: left;">This doesn&#8217;t equate to iPhone&#8217;s sold because activations would also count dad&#8217;s giving their iPhone to their daughter and buying a new one for themselves, which would mean 2 activations but just one iPhone bought.</p>
<p style="text-align: left;">According to AT&amp;T they added 2 million subscribers to that quarter. Nevertheless the evidence is there on an upward trend.</p>
<p style="text-align: left;">The graph below shows the how activations for the 1st quarter of 2010 rose by 50% over the previous quarter.</p>
<p style="text-align: left;"><a href="http://blog.sekiur.com/wp-content/uploads/2010/03/att_q1_2010.jpg"><img class="aligncenter size-full wp-image-883" title="att_q1_2010" src="http://blog.sekiur.com/wp-content/uploads/2010/03/att_q1_2010.jpg" alt="" width="500" height="458" /></a></p>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/08628cdd-9bdb-4841-ab75-d6bf879ff5f0/"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=08628cdd-9bdb-4841-ab75-d6bf879ff5f0" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related pretty-attribution"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>
]]></content:encoded>
			<wfw:commentRss>http://blog.sekiur.com/2010/03/mobile-forensics/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Locking Down The Blackberry Network</title>
		<link>http://blog.sekiur.com/2009/01/locking-down-the-blackberry-network/</link>
		<comments>http://blog.sekiur.com/2009/01/locking-down-the-blackberry-network/#comments</comments>
		<pubDate>Sun, 11 Jan 2009 09:02:08 +0000</pubDate>
		<dc:creator>Jose Vicente Ortega</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[audit]]></category>
		<category><![CDATA[bes]]></category>
		<category><![CDATA[blackberry]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[rim]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[risk management]]></category>
		<category><![CDATA[smartphone]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://blog.sekiur.com/?p=683</guid>
		<description><![CDATA[<p><a href="http://blog.sekiur.com/wp-content/uploads/2009/01/lockdown.jpg"></a>Early last year India threatened to discontinue Blackberry service if Research In Motion (RIM), the company behind the Blackberry did not allow the Indian Government to monitor the Blackberry network traffic raising serious security concerns. Here are a few articles from <a href="http://www.pcworld.com/article/143351/india_scrutinizes_blackberry_security.html" target="_blank">PCWorld</a>, <a href="http://www.infoworld.com/article/08/03/12/BlackBerry-under-security-scrutiny-in-India_1.html" target="_blank">InfoWorld</a>, and <a href="http://news.cnet.com/8301-10784_3-9953395-7.html" target="_blank">CNet</a>.</p> <p>Now president-elect Barack [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://blog.sekiur.com/wp-content/uploads/2009/01/lockdown.jpg"><img class="alignleft size-medium wp-image-689" title="lockdown" src="http://blog.sekiur.com/wp-content/uploads/2009/01/lockdown-300x190.jpg" alt="" width="300" height="190" /></a>Early last year India threatened to discontinue Blackberry service if Research In Motion (RIM), the company behind the Blackberry did not allow the Indian Government to monitor the Blackberry network traffic raising serious security concerns. Here are a few articles from <a href="http://www.pcworld.com/article/143351/india_scrutinizes_blackberry_security.html" target="_blank">PCWorld</a>, <a href="http://www.infoworld.com/article/08/03/12/BlackBerry-under-security-scrutiny-in-India_1.html" target="_blank">InfoWorld</a>, and <a href="http://news.cnet.com/8301-10784_3-9953395-7.html" target="_blank">CNet</a>.</p>
<p>Now president-elect Barack Obama <a href="http://www.telegraph.co.uk/news/worldnews/northamerica/usa/barackobama/4174298/Barack-Obama-vows-to-keep-Blackberry-despite-hacking-fears.html" target="_blank">vows to keep his Blackberry</a> despite hacking fears and concerns by the Secret Service.</p>
<p>This will not only be a headache for the Secret Service but its pretty likely that hacking attempts towards the RIM network will increase exponentially.</p>
<p>Generally people just don&#8217;t think about the risk that a smart-phone poses, specially if its connected to a Blackberry Enterprise Server. How could my phone be a risk to anyone? Well a smartphone is not just a phone, but rather a miniature computer that is not just capable of making calls but it also an un-metered gateway into the corporate network.</p>
<p>In order to understand what actions to take to protect a smart-phone, in particular the Blackberry you have to understand how it works and how it interacts with the Blackberry Enterprise Server.</p>
<p><strong>Vulnerabilities:</strong></p>
<ul>
<li>Lack of authentication</li>
<li>Lack of encryption</li>
<li>Lack of mobile code execution controls</li>
<li>Difficult to enforce controls</li>
<li>Peripheral devices introduce additional vulnerabilities</li>
<li>Infrastructure vulnerabilities service specific operating systems, platforms, applications, etc.</li>
<li>Small size is prone to theft and loss</li>
<li>All devices may not be corporate owned</li>
<li>Multiple configurations of the Blackberry Enterprise Server (BES) architecture</li>
<li>Limited centralized update mechanisms</li>
<li>Limited IT/CIO Control</li>
</ul>
<p><a href="http://blog.sekiur.com/wp-content/uploads/2009/01/bes.png"><img class="aligncenter size-full wp-image-684" title="bes" src="http://blog.sekiur.com/wp-content/uploads/2009/01/bes.png" alt="" width="466" height="257" /></a></p>
<p><strong>Sources of Recommended Controls and Security Guidelines:</strong></p>
<ul>
<li>The Vendor  (Microsoft, Treo, RIM, etc.)</li>
<li>SANS (www.sans.org)</li>
<li>NIST has a great publication</li>
<li>Other existing guidelines</li>
<li>3rd Party Solutions often fill the gaps</li>
</ul>
<p>Once the vulnerabilities have been identified we proceed to implement controls and audits.</p>
<p><strong>Controls:</strong></p>
<p>Controls will include policies, standards, practices, procedures, guidelines, awareness, authentication, encryption, and asset management.</p>
<p><strong>Audits:</strong></p>
<p>Once the scope has been defined, allow to review the implementation of policies between the BES, servers, Blackberry devices, and Blackberry desktop agents. Audits also allow the review of configuration and options to ensure that security is not just available but implemented. Additionally configurations pushed down to end devices need to be audited as well.</p>
<p>The infrastructure design and configuration of network components (firewalls, routers, switches, VLANs, etc.) will need to be audited as they play an intricate part of the overall security of the system.</p>
<p><strong>Risk Assessment:</strong></p>
<p>Although this requires additional resources and expertise, its a must in certain environments like corporate or government. A risk assessment will identity security vulnerabilities and provide a 2nd chance to identify all &#8220;assets&#8221;.</p>
<p>Once this has been completed, validating the risk by performing an &#8220;ethical hack&#8221; will remove any uncertainty by proving the vulnerabilities identified actually exist.</p>
<p><strong>Conclusion:</strong></p>
<p>Providing documentation on the findings is vital. The documentation required will contain an executive summary, action items and details for system administrators, and a clear and concise report with both the good and the bad findings.</p>
<p>A couple of things that should not fall through the cracks are ensuring that the corrective actions are implementable within the organization and the next audit scheduled.</p>
<p><strong>Sample Policy:</strong></p>
<p><a rel="bookmark" href="../2009/01/sample-blackberry-enterprise-server-policy/">Sample Blackberry Enterprise Server Policy</a></p>
<p style="text-align: center;"><script type="text/javascript"><!--
google_ad_client = "pub-3340920433757461";
google_ui_features = "rc:10";
google_ad_width = 468;
google_ad_height = 60;
google_ad_format = "468x60_as";
google_ad_type = "text_image";
google_color_border = "FFFFFF";
google_color_bg = "FFFFFF";
google_color_link = "0000FF";
google_color_text = "000000";
google_color_url = "008000";

//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.sekiur.com/2009/01/locking-down-the-blackberry-network/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

