Monday 17 November 2014

Security part 5 (Securing your phone)

Security part 5 (Securing your phone)

There were a lot of talk recently on the media about phone hacking. Loads of bad press and a lot of exploitation of unaware users. Some of us do know and understand the risks, but we never really think it can happen to us and to a degree we are complacent. We are used to use defaults, to want the easiest possible.

I Think a certain level of security should be enforced by manufacturers, and not expect users to know how to lock down things. Some of services the default password is: admin or blank or 0000.
Come on, this is like a joke! 
Manufacturers need to take more responsibility and face for the fact that they should know much more than users.

We have to understand a smart phone is pretty much a very powerful, portable PC. Some of these phones are much more powerful than PCs manufactured few years ago, they have better CPU/Processor, they have more memory, even more storage, they are connected to the Internet and guess what where is the firewall?!!!

In this article I am going to try and cover some of the basic security issues we face, and how to try and prevent it from happening, give some tips on what to do in case the worse does happen.

Let's cover the basics
  1. How to prevent unauthorised people from using your phone?
Most phones have a built in mechanism to be enabled and ask for a pass code, PIN number or both.
  • 1. Set your phone to autolock
  • 2. Set a PIN number or pass core
  • 3. Set it for a strong PIN number
These steps will certainly keep most unauthorised users out of your phone.

    2. How to prevent people accessing messages left to you on your voice mail?

Again most phones and network operators allow you to set a password for:
  • Listening to messages
  • Saving messages
  • Deleting messages
Set a password, PIN number for your voice mail. Do not forget to set it..

    3. Set "Restrictions" or "Parental control" for using Apps and placing calls. It is like a second layer of protection in case your PIN number has been compromised.

   4. If you want privacy, disable "Location Services". 
If you have Location services or similar on, any application installed on your smart phone will advertise your location across the Internet to anyone. It will be very easy to track your location as you move from one place to another.

5. Do not even consider Jail breaking your smart phone, you do not know what hidden traps might be left. It is not a good idea for various reasons a) you are violating warranty b)there may be back doors left to allow data leaking.

6. Install an anti virus: Norton, Mcafee, Trendmicro etc.
As I mentioned above, don't treat your smart phone any different from a PC, it is a powerful PC in your pocket.

7. Install a Firewall, there are many different types of Firewalls available for Android and for iPhones IOs.
A Firewall is an application which protects your PC/Phone from unauthorised connections etc.

8. Only install Apps from AppStore and Google store

9. Do no use FREE WIFIs, they are very insecure and sometimes they are set up to collect data, for example: If you read your email using a FREE WIFI, whoever is the owner of the WIFI might be there also reading your messages, they might get hold of your password. SO do not use public FREE WIFI.

10. How to prevent loosing your Phone?
You can buy a dice which will sound a beep if you are distant from it. Something like this:


11. Download and install "Find My iPhone" app for Apple devices or Android. This is an app which if set up correctly and prior to haven lost your smart phone, it can be a very good tool
  • Locate the device
  • Send messages to the lost device
  • Deleting the data off your lost device
12. If you have lost your device
  • Please do notify your Network provider ASAP
  • Do not leave it for the next day, contact Network provider ASAP
  • If the everything above has been followed, then you are in a good proposition
  • Communicate the police
NOTE: Remember if you lost your phone and did not communicate in time to your Network provider, any calls made using your phone you will be the one asked to pay. 

13. Set your phone to auto wipe the data if 10 consecutive attempts to login have failed.

This is not a comprehensive list of security measures you can take, it is only a simple guide to give you some basic protection against many different scenarios.
You can implement other features and security measures, just spend some time researching.

You can use the same advice for many different devices i.e. iPads, Tablets, etc.

I hope this will be helpful to you and will open your eyes to this new world we are living, if we don't protect ourselves, people out there will exploit and take advantage.


By Renato de Oliveira












2 comments:

  1. Interesting post.

    Check this out if you're looking for an Android firewall:
    http://www.redmondpie.com/how-to-enable-firewall-on-android-to-make-your-device-fully-secure/

    ReplyDelete