We have all heard that the phones we carry around have more computing power than was used in the Apollo moon mission. Breaking news: these powerful devices in our pockets are vulnerable to attacks of which we cannot dream.
We can just pick up our phones and read the headlines. Brian Krebs reports federal charges against SMS attacks, Salt Typhoon getting into our phone systems, even the FBI telling us to use encryption on our phones.
Today, we sat down with Jim Coyle from Lookout to unpack the concept of mobile threats. He begins with some startling facts. For example, Jim Coyle states that over half the mobile devices in a under their purview did not have an up-to-date operating system.
"When you think about the number of zero days that are being identified in both Android as well as Apple, and being able to do remote code execution . . that ultimately turn your phone into a mobile spy . . "
Jim Coyle, Lookout Tweet
One simple proof-of-concept is with a
malicious URL. On a desktop, one can hoover over a URL to see where it is
taking you; a credible URL will be clicked on a phone device with no questions
asked.
There are other entries as well. For
example, what happens when a company with a legitimate app gets bought out by a
malicious actor? It is possible for them to have an open door to your phone.
The good news – a lot of mobile
malwares will not survive a reboot. The lesson: every night plug in your phone,
turn it off and on.
If you enjoyed this episode, then you may want to listen to
EP-249: Securing Endpoints in Federal Systems Amid Constant Change
Why: Deep dive into endpoint security complements the mobile device threat narrative.EP-250: Can Your Agency Withstand a DDoS Attack? How Radware Is Raising the Bar
Why: Expands on threat vectors, specifically network-level attacks that could relate to mobile access points.
