Privacy Digest

News that can impact your privacy.
Login/Register
  • Create new account
  • Request new password
Home Blogs MacRonin's blog
  • FAQ
  • Wishlists
  • Contact
  • Categories/RSS

Bookmark Us

Bookmark Privacy Digest 
Bookmark This Page 

RSS Feed + Site Map

Syndicate content
more

Advertisements

GPS Tracking
Search By Phone Number
Hosting
Home Security Systems Toronto
Mercedes-Benz Luxury Cars News
Disk Encryption
spy camera

Popular content

Last viewed:

  • MIT Coders' Free Speech At Stake
  • NewsFactor Network | Hackers Pull Off Biggest Heist in History
  • Constitution Protects Location Information, CDT Argues
  • New Details Support Tor Spying Theory
  • EFF Challenges Government's 'Back Door Wiretap'
  • Anti-P2P Company Gets Bit by the Torrent
  • Cookies Crumbling: YouTube Takes a Small Step to Increase Privacy of Whitehouse.gov Visitors

tags in Topics

Activists Alert Companies Congress Copyright Court (US) Databases Data Mining Editorial EFF Entertainment Exploits Fourth Amendment Government Hmmm ID Infrastructure Law Enforcement Laws Politics Privacy Remember Reports Rights Security Software Spin Zone Surveillance Telecommunications Tracking
more tags

Performancing Metrics Blog Statistics
EatonWeb Blog Directory
Listed on BlogShares
View blog authority
Congressional Research
Broadcast Flag

European Network & Information Security Agency Releases Paper on Security of Mobile Devices

Submitted by MacRonin on December 3, 2008 - 12:30pm.
  • Activists
  • Editorial
  • Europe
  • Government
  • Hmmm
  • Infrastructure
  • Privacy
  • Reports
  • Security
  • Telecommunications
  • Wireless

European Network & Information Security Agency Releases Paper on Security of Mobile Devices: Via Privacy Lives

The European Network and Information Security Agency (ENISA) has published a new paper (pdf), “Security Issues in the Context of Authentication Using Mobile Devices (Mobile eID).” ENISA is an independent agency issues advice on technology and security issues to European Union governments and private industry. From the executive summary:

Mobile devices, like smart phones and PDAs, will play an increasingly important role in the digital environment. Besides their primary use, these devices offer, based on the security features of their secure elements, the possibility to electronically authenticate their owners to a service. In the near future we might use our phone to pay our taxes, buy metro tickets, elect a president, play the lottery or open bank accounts. With Hong Kong, Singapore and Taipei being ‘the most mobile-penetrated territories on the planet’, the Asian region in particular is experiencing growing demand for these services. A main driver in the Asian market is the consumer’s interest in convenient solutions which are easy-to- use and involve as few devices as possible. In Europe, enhanced security might become a second incentive for these technologies. Mobile devices can act as a user-interface for online applications and in this way act as a secure, secondary authentication channel.

However, as is the case with many new technologies, the pervasive use of mobile devices also brings new security and privacy risks. Persons who make extensive use of mobile devices continuously leave traces of their identities and transactions, sometimes even by just carrying the devices around in their pockets. Statistics show an increase in the theft of mobile device which nowadays store more and more personal information about their users. Although the secure elements (based on smart card technology) are very suitable for storing data, vulnerabilities do exist and new weaknesses might be discovered. Due to the increasing complexity of mobile devices, they are now prone to attacks which previously only applied to desktop PCs. BitDefender lists the exploitation of mobile device vulnerabilities three times among the top ten ’e-Threats’ for 2008. According to the E-Threats Landscape Report, mobile devices are about to be increasingly targeted by new virus generations because of their permanent connectivity. Classical scam methods using SMS are expected to rise in parallel. Therefore the original notion of seeing the mobile device as a personally, trusted and trustworthy device needs to be re-evaluated.

Throughout this paper we will look at different use-cases for electronic authentication using mobile devices. We will identify the security risks which need to be overcome, give an opinion about their relevance, and present mechanisms that help in mitigating these risks. Furthermore, we will look at use-cases where mobile devices even act as a security- enhancing element by providing an out-of-band channel or a trustworthy display.

Mobile devices have an enormous potential. Many new electronic services are currently being developed and tested and many of them are likely to find customer acceptance because of the opportunities and benefits they offer. We strongly believe that, if these new technologies are applied in the right way, they also constitute a big opportunity when it comes to the secure, sophisticated authentication mechanisms needed for future applications.

Read Original Article (Via Privacy Lives.)


Bookmark/Search this post with:
  • Delicious Delicious
  • Digg Digg
  • Reddit Reddit
  • Google Google
  • Yahoo Yahoo
  • Technorati Technorati
  • MacRonin's blog
  • Add new comment

Recent blog posts

  • A Remedy for Every Wrong? Why We Need a Consistent Privacy Act
  • Give Me My Health Data!
  • CDT, EFF and PK File Brief in Ringtones Case
  • Pirate Bay 2.0: Pay Pirates to Become Consumers
  • Judge Acquits Lori Drew in Cyberbullying Case, Overrules Jury
  • Apple patching serious SMS vulnerability on iPhone
  • Enter the Advertisers - self-regulatory principles ?
  • Out of business, Clear may sell customer data
  • TSA asked to ensure safety of customer data after Clear closing
  • Several Facts about Google and HTTPS
more
Compilation © Copyright 1997-2009 Paul Hardwick, with Web Hosting provided by MacRonin.com.