10.06.2013 Views

Study into the Implications of Smartphone Operating System Security

Study into the Implications of Smartphone Operating System Security

Study into the Implications of Smartphone Operating System Security

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

<strong>Study</strong> <strong>into</strong> <strong>the</strong> implications <strong>of</strong> <strong>Smartphone</strong> operating system security<br />

3. App revocation (aka kill-switch): <strong>Smartphone</strong> platforms should support remote<br />

removal <strong>of</strong> installed apps by app stores.<br />

4. Device security: Includes supporting sandboxes to install and run apps “to reduce <strong>the</strong><br />

impact <strong>of</strong> malware”.<br />

5. Jails (or walled gardens): This is closing <strong>the</strong> sideloading feature. ENISA recommends<br />

that “<strong>the</strong> <strong>Smartphone</strong> should ei<strong>the</strong>r be blocked from using untrusted app stores or ,<br />

for expert users, present clear warnings about installing from untrusted sources”.<br />

An investigation and security analysis <strong>into</strong> ‘sideloading’ mobile<br />

apps<br />

Key Findings<br />

The “sideloading” <strong>of</strong> mobile apps is defined as a user installing an app without using <strong>the</strong><br />

<strong>of</strong>ficial platform app store or app market.<br />

The ability to install mobile apps from outside <strong>of</strong> <strong>the</strong> ‘<strong>of</strong>ficial’ platform app stores is only<br />

<strong>of</strong>ficially supported on one <strong>Smartphone</strong> operating system, Google’s Android.<br />

By allowing a user to install an app from any source you break this model and as a result<br />

greatly increase security risk.<br />

Most Android devices will be delivered ‘out-<strong>of</strong>-<strong>the</strong>-box’ with <strong>the</strong> option to sideload turned <strong>of</strong>f.<br />

Recommendations<br />

Educate consumers as to <strong>the</strong> risks <strong>of</strong> sideloading mobile apps onto <strong>the</strong>ir devices<br />

This is also related to Jailbreaking Apple iOS devices and consumers should be<br />

persuaded not to jailbreak <strong>the</strong>ir Apple <strong>Smartphone</strong>s as this removes most <strong>of</strong> <strong>the</strong> inbuilt<br />

security protection that iOS <strong>of</strong>fers<br />

Working with UK MNOs to ensure that sideloading, by default, is switched <strong>of</strong>f<br />

Liaising with Google to determine whe<strong>the</strong>r <strong>the</strong>re are o<strong>the</strong>r workable ways to support thirdparty<br />

Android app stores that improves security and doesn’t impact <strong>the</strong>ir app distribution<br />

business model<br />

Goode Intelligence © 2013 P a g e | 27 www.goodeintelligence.com

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!