Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Wednesday, February 15, 2012

Implications Siri May Cause – Be Aware


Siri has made life of millions a lot easier, and iPhones are now more convenient than ever with iOS5— but they also leave you open to everything from pranks to data loss you may not think of. Below you’ll find several examples on how Siri can drag you into extremely embarrassing or simply undesirable situations.

We all know that Siri is activated by holding down the Home button, but have you ever thought that it also deactivates the Passcode Lock? Although this brilliant personal assistant is restricted to delete contacts or search the web without the lock code being entered, Siri can still perform number of tasks such as calling your contacts or delete your alarms. What we want by this to say is that everyone passing by is enabled to get access to your contacts private data by just knowing the contact’s name, or moreover, just knowing the relationship status between you, by simply asking questions about your “boss”, “sister” or “mom” to get the data. One more hazardous thing is that anyone can prank you by telling Siri to call you some funny or rude name and may embarrass you when you expect it least.

To avoid appearing in such a situation, you can simply go to Settings> General> Passcode Lock and flip the Siri toggle to Off. But note that if you disable Siri’s passcode bypass, the speed and the ease of access to this unique feature will be decreased as you won’t be able to just hold a button and start talking to have Siri perform something for you, for instance when you’re driving. 

One more threat enclosed to Siri is that sharing iPhone 4S contacts also shares Siri relationships you have set. To be more concrete, this means that when you send a contact via your iPhone 4S built in sharing, you send not just a name and a phone number, but EVERYTHING in that contact, including the relationships set up by Siri. To be even more concrete, this means that you may share what you call your girlfriend or a rude nickname you called your boss while you were angry… You may call it a bug or just inattentiveness, but there is no solution to prevent this, but to either text or manually send your contacts. Let’s hope that Apple constrains card sharing to common fields in an upcoming iOS update. But till then, if you do care for privacy, you need to think twice before sharing an entire contact card to avoid future implications… 

Friday, March 18, 2011

A Seriously Good Screen Protector!

We have already mentioned that the boldest problem of iPhones is the screen scratches. Front Glass/ Touchscreen Blemish can hinder you while watching videos or viewing images or simply, you get tired looking at it. Among the array of screen protector providers, Expert Shield comes with a seriously good product. iPhone 4 screen protector, at one glance the tiny transparent cloth secures your iPhone with any kind on scratches, I said ANY kind!

The Expert Shield is a precision cut, perfectly aligned screen protector that applies the screen without bubbles and protects your phone from scratches that would otherwise scrape your screen.  Once fitted, the screen on your device will be protected to the highest level of any screen protector, keeping it scratch free from keys, screws and other sharp objects. There's even a video to show it protects from belt sanders! The very same used to sand down wood and other materials for finishing purposes - but don't try THAT at home, just watch the video...


Feature Highlight:

Lasts longer than any other screen protector - Guaranteed!
Shields your iPhone 4 screen from scratches
Pre-cut to the exact dimensions of your screen
No Air Bubbles
No messy glue, no nasty residue
Straightforward installation
Works perfectly with the iPhone 4 capacitive touch screen
Includes finest lint-free cleaning cloth
Completely washable and reusable
Includes front & back protectors

You can buy the Expert Shield iPhone 4 screen protector or for other devices here.





Tuesday, November 10, 2009

Protection One Released Security Application for iPhone

Protection One, Inc. released eSecure, a free iPhone application. The new app allows users to access their security panels and receives real-time security updates from their iPhone or iPod touch.

By the help of the application, users can confirm that their security system is armed while on vacation or turn off the alarm while at work to let in cleaning crews or other contractors. When armed, the eSecure system will send text or e-mail messages when motion is detected, a particular door is opened, in the event of a flood, if high carbon-monoxide levels are recorded and even when a liquor or medicine cabinet, safe or other sensitive area is accessed.

“No one wants to spend a vacation or business trip worrying about leaving the garage door open or if the security alarm is set,” says Protection One President and CEO Richard Ginsburg. “This application puts security at your fingertips and keeps you connected, even when you’re away.”

The application maintains safety and security with multiple layers of password protection. A standard Protection One keypad code is required for access to the eSecure keypad, which is neither stored on the device nor visible to anyone looking at the screen.

The application is available for download now from Protection One at the iPhone Apps Stor. The app is compatible with all iPhone and iPod touch devices

Reference:
http://cut.io/crA5

Sunday, November 1, 2009

iPhone, Android & Windows Mobile - Protected by Smartphone Protection Managed Security Service

IT Security Experts, a Value Added Reseller for both Hardware and Software in the IT Security Field launched long awaited Smartphone Protection (SPMS) and GuardianEdge Encryption Managed Services (GEMS).

According to the It-Security-Experts, complete managed service protects and encrypts all company data stored and used on Windows Mobiles, I-phones, Palm Treo’s with (Symbian and Android also on their way) whilst also boasting a “remote kill function” for complete control over your companies most valuable asset “Data”.

As mentioned on the official site they experience both in On-Premis and Hosted Services made ITSE a logical choice... to take the “Blackberry” concept and create an affordable non generic, modern alternative.

It is always unpleasant to discover that your device is stolen or lost but nowadays it is less painful as ITSE's Smartphone Managed Service (SPMS) provides with full Smartphone Protection. Equipment disappearance does not mean you lose data.

SPMS (SmartPhone Managed Service) is provided on a per month, per user basis.

SPMS Benefits

• Single "provisioning" Email/SMS to access the System
• We manage the inbuilt Encryption on the new iPhone 3GS
• Fully managed 24x7x365 operations and support
• A central portal for key data recovery, audit logs, reporting and software deployment will be available around the clock through a Web Based Management Console
• Policy administration — adding or deleting users, updating policies or assigning new privileges
• Adjusting policies to comply with security requirements as defined by the organisation, or by local or national legislation
• Software upgrades — deploying software update profiles as new versions become available
• Key recovery administration — maintaining the online automated help system
• Automated Backup and Archiving of Stored Keys

Source:
http://cut.io/pruy

Sunday, July 26, 2009

iPhone 3GS' Built-in Encryption "Sucks"

One of the "missing" functions in iPhone and iPhone 3G has always been encryption capability. This can somewhat be compensated by using third party software, for example a commercial SafeWallet or a decent freeware alternative Keeper. However, if a device has built-in security features and they are good and strong, using built-in features is almost always better. For example, think about TPM-enabled laptops. I'm pretty happy with my HP and I feel quite safe. Even if it is stolen, the sensitive data is protected.

What can be said about iPhone 3GS' built-in encryption functionality? The main purpose for including encryption in iPhone 3GS is to make the device appealing to business users. Unfortunately, if you are a business user like me and depend on iPhone 3GS' built-in encryption, think twice before protecting sensible data with it.

As it turns out, a couple of minutes and a couple of freeware applications is what it takes to crack iPhone 3GS' encryption. At least, this is what an iPhone developer and a hacker Jonathan Zdziarski claims. According to Zdziarski, iPhone's encryption is poorly implemented. The bottom line is that, even though iPhone 3GS includes a built-in encryption, it's totally useless. After all, what's the use of security features that cannot be trusted?

Let's hope that Apple will improve this drawback in the future firmware releases. Meanwhile, third party software is the way to go.

Reference: http://cut.io/fMSV

Friday, May 2, 2008

Bike Mount Holder For iPhone By USB Fever

USB Fever, offers iPhone consumers new portable gadget for bicycles - The iPhone Bike Mount.
One can mount iPhone Bike on a steering wheel, and enjoy a good movie, browse internet or check emails while riding the bike.
Be aware not to front-brake too hard, and protect your iPhone from the elements. iPhone Bike Mount costs only $14.99 and you can order it on the USB Fever Website.

First step to order an item on the USB Fever is to register on the website the system is developed for all major browsers (e.g. Firefox, IE...), then find items if you know the exact address, you may simply type it and go and the last step you should do is just to click the icon "Buy". After making the payment, you will receive an order confirmation email from USB Fever .com and PayPal for reference.


How and when do orders to be shipped? To receive your order (by Standard International Air Mail):


  • For US/Canada, it usually takes 2-3 weeks;
  • For Europe and other countries, it usually takes 2-3 weeks;
  • For Italy, Spain and Portugal, it usually takes 2-4 weeks;
  • For South America, it usually takes 2-6 weeks;
  • For South East Asia countries, it usually takes 10~14 days;
  • For other destinations, it usually takes from 2 - 6 weeks;
  • During Peak seasons (e.g. Christmas, New Year, and Easter) or some special occasions ... it may take 1-2 weeks longer.

Security after ordering and paying for an item is important, regardless if you use credit, debit or PayPal none of your information is stored with usbfever.com. All transactions go through PayPal.


References:


http://www.slipperybrick.com/2008/04/iphone-bike-mount-watch-movies-from-your
-ambulance/

http://www.usbfever.com/index_topic.php?did=5&didpath=/5

Monday, November 19, 2007

From iPhone to iSecurityRisk

Soon after launching iPhone, I remember Steve explaining why Apple did not put Flash or Java support into the wonder device. If I'm not mistaken, stability and security were the factors why the Cupertino company said no to these extremely widespread technologies.

iPhone is a really cool device but how secure is it? It turns out that iPhone is a huge security risk. FastCompany has made an experiment in collaboration with a security expert Rik Farrow and unfortunately Mr. Farrow was able to do "amazing" (to be short, the attacker can take a full control on the device by accessing messages, emails, even conversations and much more) things with the wonder device. If you are "lucky" owner of iPhone you may wish to at least turn off your WLAN functionality and watch this video.

Saturday, September 29, 2007

Bluetooth - The Weakest Link

Security researchers attention goes to the Bluetooth bug in iPhone. On Friday, Symantec's DeepSight threat network team pointed out the vulnerability in an advisory to customers.

According to the security team, the Bluetooth flaw occurs when malicious SDP (Service Discovery Protocol) packets are handled. Thus, any attacker within Bluetooth range can exploit the vulnerability remotely and execute arbitrary code on the device.

In order to exploit the iPhone Bluetooth vulnerability, the Bluetooth MAC must be known. However, with iPhone this is extremely easy. The iPhone Bluetooth MAC address is always one less than the Wi-Fi interface's MAC address. So, a standard WiFi sniffer does the job here.

According to Apple's security advisory, the Bluetooth vulnerability was discovered and reported by Kevin Mahaffey and John Hering of Flexillis Inc., a Los Angeles-based company that specializes in mobile security development and consulting.

Most people do not consider Bluetooth vulnerabilities seriously. This can be attributed to the belief that Bluetooth is not a long-range wireless technology. However, possible working range of Bluetooth is far longer than most people believe. With specialized antennas it is possible to achieve 200-300 meters, sometimes even more.

Friday, August 3, 2007

Old Code Problems in a New iPhone

Charlie Miller of Independent Security Evaluators was the first person to crack Apple's much hyped iPhone. The vulnerability was found in an old, buggy part of the Safari browser, in the old Perl Regular Expression Library (PRCE) in Webkit. The regular Mac OS X Safari as well as the Windows beta version of the browser were also at risk.

I have been using the Windows beta since its release. While I had noticed a number of bugs, I could not assume the software had such a severe problem. So if you use the Safari browser - whether on a Mac, PC, or iPhone - be sure you update it with Apple's just-released patches.

This incident with iPhone once again makes me think that in computers there is no such a thing as absolute security. All systems are vulnerable and all systems have bugs. However, it is important that the developer quickly reacts to eliminate security problems (Apple was very quick indeed).

This post has been featured on BLOGVASION.COM