10.06.2013 Views

Study into the Implications of Smartphone Operating System Security

Study into the Implications of Smartphone Operating System Security

Study into the Implications of Smartphone Operating System Security

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

<strong>Study</strong> <strong>into</strong> <strong>the</strong> implications <strong>of</strong> <strong>Smartphone</strong> operating system security<br />

The FTC complaint revealed specific vulnerabilities that had been found on HTC’s devices<br />

including:<br />

Insecure implementation <strong>of</strong> two logging applications, Carrier IQ and HTC Loggers<br />

Programming flaws that would allow third-party applications to bypass Android’s<br />

permission-based security model<br />

This action by <strong>the</strong> FTC has been considered to be a milestone in <strong>Smartphone</strong> security. A<br />

government body taking legal action against a <strong>Smartphone</strong> manufacturer for poor security<br />

implementation. If <strong>the</strong> FTC has decided to intervene against HTC in its duty to protect USA<br />

consumers against <strong>Smartphone</strong> security threats, <strong>the</strong> question has to be asked “is this just<br />

<strong>the</strong> start <strong>of</strong> legal action and who could be next?” It sends out a clear warning to o<strong>the</strong>r<br />

vendors operating in this sector not to treat security lightly.<br />

As a follow-up to this case <strong>the</strong> FTC is planning to hold a public forum on malware and o<strong>the</strong>r<br />

mobile security threats on 4 June 2013.<br />

Federal Communications Commission (FCC) <strong>Smartphone</strong> Initiatives<br />

Ano<strong>the</strong>r US Government body, <strong>the</strong> Federal Communications Commission (FCC) has<br />

responded to <strong>the</strong> <strong>Smartphone</strong> security threat with a number <strong>of</strong> initiatives that were started in<br />

April 2012. The FCC is Ofcom’s US counterpart who regulates “interstate and international<br />

communications by radio, television, wire, satellite and cable”.<br />

In April 2012, <strong>the</strong> FCC announced new initiatives to “combat massive smartphone and data<br />

<strong>the</strong>ft”. 98 In a joint announcement with US State Police Departments and <strong>the</strong> Mayor <strong>of</strong><br />

Washington D.C., Vincent Gray, <strong>the</strong> FCC highlighted <strong>the</strong> problem <strong>of</strong> <strong>Smartphone</strong> <strong>the</strong>ft<br />

quoting New York City Police figures that “more than 40 percent <strong>of</strong> all robberies in New York<br />

City involve <strong>Smartphone</strong>s”. A new initiative was announced, with <strong>the</strong> support <strong>of</strong> <strong>the</strong> US MNO<br />

(carrier) community, to “implement a database to prevent use <strong>of</strong> stolen <strong>Smartphone</strong>s”. The<br />

central stolen <strong>Smartphone</strong> database was to be rolled out in an 18 month timeframe.<br />

Alongside <strong>the</strong> stolen <strong>Smartphone</strong> database initiative <strong>the</strong> FCC announced a number <strong>of</strong> o<strong>the</strong>r<br />

initiatives that aimed to raise consumer awareness through channels such as <strong>the</strong> US MNO<br />

(carrier) and handset manufacturer communities. These included (and <strong>the</strong> following is a<br />

direct quote from <strong>the</strong> FCC press release):<br />

“Encourage users to lock <strong>the</strong>ir phones with passwords:<br />

o <strong>Smartphone</strong> makers will notify and educate users in <strong>the</strong> most highly visible<br />

ways – through messages on <strong>the</strong> <strong>Smartphone</strong> itself and through “Quick Start”<br />

user guides – about how to use passwords to deter <strong>the</strong>ft and protect <strong>the</strong>ir<br />

data<br />

Educate users in lock/locate/wipe applications:<br />

98 FCC Press Release; “Announcement <strong>of</strong> New Initiatives to Combat <strong>Smartphone</strong> and Data Theft”.<br />

Released 10 April 2012. http://www.fcc.gov/document/announcement-new-initiatives-combatsmartphone-and-data-<strong>the</strong>ft<br />

Goode Intelligence © 2013 P a g e | 104 www.goodeintelligence.com

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!