Subscribe to Windows IT Pro

 

Get Newsletters

  • Get the Latest News
  • Product Updates
  • Helpful Tricks
  • Productivity Tips

Subscribe Now!

June 23, 2004 12:00 AM

Mobile Computing Security Through Obscurity

Windows IT Pro
InstantDoc ID #43071
Rating: (0)

I wonder if part of your job as security administrator or manager includes handling mobile phone security? Someone at your company should be tending to that responsibility, especially if employees are storing company information on their phones.

Last week, Kaspersky Labs announced the discovery of the first virus to infect mobile phones. The virus, which Kaspersky named Cabir, affects mobile phones that use the Symbian OS. The virus is relatively harmless--its only purpose is to propagate itself, and it does so only to other phones that have Bluetooth enabled and are broadcasting their presence. However, Denis Zenkin, head of Corporate Communications at Kaspersky Labs, said that sooner or later, more malicious forms of mobile phone malware that will possibly destroy or steal data will begin to spread.

http://www.viruslist.com/eng/viruslist.html?id=1689517

Since Cabir spreads to mobile phones that broadcast their presence via Bluetooth wireless technology, you might want to configure Symbian to use Bluetooth in an invisible mode that doesn't broadcast the phone's presence. Configure other mobile phone OSs too to prevent any future attacks against them. Using invisible mode is similar to configuring wireless Access Points (APs) to not broadcast their SSID. If an AP broadcasts its SSID, intruders can detect it and use it as a starting point for penetrating your network. Bluetooth invisible mode is also similar to using a firewall, which makes your internal networks invisible to connected networks.

These security measures are probably common sense for you, but they might not be for mobile phone users in your organization. You could explain the security needs to users by comparing their Bluetooth-broadcasting mobile phone to a wallet or purse left lying on a car seat while they're out of the car. The wallet or purse is essentially begging somebody to break into the car and steal it. A little security through obscurity might save a lot of frustration sooner or later. Some people might disagree, but I think you can gain a fair amount of security by obscuring the presence of anything, whether it be a wallet, purse, or wireless network.

Of course, you can gain plenty of security by adding device protection, such as antivirus software for mobile phones, which is available from many antivirus software vendors. And, as I mentioned earlier, you might also consider some configuration changes to your mobile phone OS, particularly disabling Bluebooth broadcasts to make the devices somewhat invisible.

If you're interested in other problems with Bluetooth and mobile phones, you might want to read about a few other related vulnerabilities, which are mentioned in a recent Integralis press release.

http://www.integralis.co.uk/about_us/press_releases/2004/150604PR.html

Related Content:

ARTICLE TOOLS

Comments
    There are no comments to display. Be the first one!
You must log on before posting a comment.

Are you a new visitor? Register Here

advertisement

advertisement

White Papers

Get your Windows 7 deployment off to the right start by implementing PC lockdown. A locked-down environment is easier and cheaper to support since users are less likely to make unnecessary changes to the core system configuration - read more here!

Essential Guides

Is your iSCSI "lossy"? The reality is that most off-the-shelf Ethernet hardware deployed for iSCSI can lose packets, resulting in slow performance or application downtime. Learn how to assess your current iSCSI infrastructure and engineer an advanced iSCSI SAN infrastructure.

Web Seminars

What's the best way to keep your network safe from malware? In this web seminar, security expert Greg Shields suggests an alternative method to the traditional blacklisting approach that is common with anti-virus and anti-malware solutions.

eLearning Series

We bring the experts direct to you to share their real-world perspective and expertise. During each event, three sessions stream in real time, so you can learn, ask questions, and get solutions.
Upcoming event: Getting the Most with Exchange 2010 with Paul Robichaux

Subscribe to Windows IT Pro!

Windows is a trademark of the Microsoft group of companies. Windows IT Pro is used by Penton Media Inc. under license from owner.