Privacy Digest

News that can impact your privacy.
Login/Register
What is OpenID?
  • Log in using OpenID
  • Cancel OpenID login
  • Create new account
  • Request new password
Home Blogs MacRonin's blog
    • FAQ
    • Wishlists
    • Contact
    • Categories/RSS

Bookmark Us

Bookmark Privacy Digest 
Bookmark This Page 

Syndicate

Syndicate content
more

Advertisements

Tracking System
Tracking System
Private Detectives
Quality Security Services in California
Fleet Management
Hosting

Popular content

Last viewed:

  • Telling Friends Where You Are (or Not) - NYT
  • NY Times Slams NSA Spying Legislation
  • Supremes Won't Hear Warrantless Wiretapping Case
  • Redefining privacy in the era of personal genomics
  • Last Major Label Gives Up DRM
  • Judge Throws Wrinkle Into Plastic Surgery Trademark Claim
  • Net Neutrality Debate Crosses the Atlantic

tags in Topics

Activists Alert Anonymity Companies Congress Copyright Court (US) Databases Data Mining Editorial EFF Entertainment Exploits Fourth Amendment Government Hmmm ID Infrastructure Law Enforcement Laws Politics Privacy Remember Reports Rights Security Spin Zone Surveillance Telecommunications Tracking
more tags

View blog authority
Congressional Research
Broadcast Flag

European Network & Information Security Agency Releases Paper on Security of Mobile Devices

Submitted by MacRonin on December 3, 2008 - 12:30pm
  • Activists
  • Editorial
  • Europe
  • Government
  • Hmmm
  • Infrastructure
  • Privacy
  • Reports
  • Security
  • Telecommunications
  • Wireless

European Network & Information Security Agency Releases Paper on Security of Mobile Devices: Via Privacy Lives

The European Network and Information Security Agency (ENISA) has published a new paper (pdf), “Security Issues in the Context of Authentication Using Mobile Devices (Mobile eID).” ENISA is an independent agency issues advice on technology and security issues to European Union governments and private industry. From the executive summary:

Mobile devices, like smart phones and PDAs, will play an increasingly important role in the digital environment. Besides their primary use, these devices offer, based on the security features of their secure elements, the possibility to electronically authenticate their owners to a service. In the near future we might use our phone to pay our taxes, buy metro tickets, elect a president, play the lottery or open bank accounts. With Hong Kong, Singapore and Taipei being ‘the most mobile-penetrated territories on the planet’, the Asian region in particular is experiencing growing demand for these services. A main driver in the Asian market is the consumer’s interest in convenient solutions which are easy-to- use and involve as few devices as possible. In Europe, enhanced security might become a second incentive for these technologies. Mobile devices can act as a user-interface for online applications and in this way act as a secure, secondary authentication channel.

However, as is the case with many new technologies, the pervasive use of mobile devices also brings new security and privacy risks. Persons who make extensive use of mobile devices continuously leave traces of their identities and transactions, sometimes even by just carrying the devices around in their pockets. Statistics show an increase in the theft of mobile device which nowadays store more and more personal information about their users. Although the secure elements (based on smart card technology) are very suitable for storing data, vulnerabilities do exist and new weaknesses might be discovered. Due to the increasing complexity of mobile devices, they are now prone to attacks which previously only applied to desktop PCs. BitDefender lists the exploitation of mobile device vulnerabilities three times among the top ten ’e-Threats’ for 2008. According to the E-Threats Landscape Report, mobile devices are about to be increasingly targeted by new virus generations because of their permanent connectivity. Classical scam methods using SMS are expected to rise in parallel. Therefore the original notion of seeing the mobile device as a personally, trusted and trustworthy device needs to be re-evaluated.

Throughout this paper we will look at different use-cases for electronic authentication using mobile devices. We will identify the security risks which need to be overcome, give an opinion about their relevance, and present mechanisms that help in mitigating these risks. Furthermore, we will look at use-cases where mobile devices even act as a security- enhancing element by providing an out-of-band channel or a trustworthy display.

Mobile devices have an enormous potential. Many new electronic services are currently being developed and tested and many of them are likely to find customer acceptance because of the opportunities and benefits they offer. We strongly believe that, if these new technologies are applied in the right way, they also constitute a big opportunity when it comes to the secure, sophisticated authentication mechanisms needed for future applications.

Read Original Article (Via Privacy Lives.)

Bookmark/Search this post with:
  • Twitter Twitter
  • Digg Digg
  • StumbleUpon StumbleUpon
  • Technorati Technorati
  • del.icio.us del.icio.us
  • Facebook Facebook
  • Furl Furl
  • LinkedIn LinkedIn
  • Yahoo Yahoo
  • MacRonin's blog
  • Add new comment

Recent blog posts

  • In Bid to Sway Sales, Cameras Track Shoppers
  • Unprecedented 25-Year Sentence Sought for TJX Hacker
  • EFF Appeals Dismissal of Warrantless Wiretapping Case
  • Viacom Makes Its Case Against Yesterday's YouTube
  • Obama supports Senators draft plan to rework U.S. immigration policy - Includes National Biometric ID card for all.
  • Domain Names Can't Defend Themselves
  • Hacker Disables More Than 100 Cars Remotely
  • Judges Approves $9.5 Million Facebook ‘Beacon’ Accord
  • Hooking Up The Big Brother Machine... And Fighting It
  • Court: State Can Dump Non-Sex Offenders Into Registry
more

Performancing Metrics

Compilation © Copyright 1997-2010 Paul Hardwick, with Web Hosting provided by MacRonin.com.