Thursday, March 27, 2014

Android Security Remains a Glaring Problem: 10 Reasons Why

Android has grabbed an unassailable position in the mobile operating system market. In fact, some estimates put Android's global smartphone market share at 87 percent and rising. Most analysts believe that in a matter of years, Android will be as dominant in mobile as Windows was years ago in the desktop PC market. Google, through its partnerships with vendors, advertisers and application marketplaces, will benefit greatly from that.

But there's another far less positive parallel between Windows and Android that cannot be underestimated. According to the latest data from security firm F-Secure, 97 percent of all mobile malware targeted Android devices in 2013. In 2012 that figure stood at 79 percent. What's worse, the total number of malware signatures is on the rise. In 2012, the mobile firm identified 238 Android threats. Now, that figure stands at 804.

Those statistics, coupled with the ongoing concern among enterprise customers that no single security solution even comes close to solving the mobile world's troubles, should make just about anyone worry about Android security.

Read on to find out why: - See more at: http://www.eweek.com/mobile/slideshows/android-security-remains-a-glaring-problem-10-reasons-why.html?kc=EWKNLEDP03262014A&dni=114199973&rni=23389406#sthash.iJZoqGBT.dpuf

Friday, March 7, 2014

Boeing's Secure Black Smartphone: 10 Cool Features We All Might Want

Boeing, a company that is perhaps best known for its work in aviation and as a highly trusted U.S. government contractor, has unveiled a new smartphone it's calling, simply, Black. The handset, designed for U.S. and presumably allied intelligence agencies, will try to maximize device and data security while still providing agents in the field with reliable mobile connections. Boeing's Black smartphone highlights the impact cyber-security is having on governments around the world. Each day, it's believed that the United States and foreign governments like China are spying on government and corporate networks to gather strategic information. A hidden cyber-war is being waged, and the country that has the strongest tools might succeed in gaining an edge that could prove decisive in the event of conflict. This eWEEK slide show looks at the Boeing Black and what makes it such an interesting and potentially useful tool in the intelligence field. Admittedly, the following information is based only on what's been made publicly available. All of the specifications that make the Boeing Black valuable to the intelligence community will likely never see the light of day—at least not for years to come. - See more at: http://www.eweek.com/mobile/slideshows/boeings-secure-black-smartphone-10-cool-features-we-all-might-want.html? 3 Comments for "Boeing's Secure Black Smartphone: 10 Cool Features We All Might Want" AmericanPrivacysaid on March 5, 2014 03:00 pm NSA proof phone made in the USA? Yea Right. Between the Patriot Act and CISPA don't believe this for a second.And if NSA can tap into Google and others without them knowing it, then what would stop NSA from taking the data from Boeing which lifeline is and will remain government contracts. And Verizon as the carrier? Really they are already participating in the Prism program. Certain government officials here in the states already have a "hack-proof" phone and it is NOT available to the public. Visit www.americansrighttoprivacy.com for real solutions that reside in Switzerland. he Swiss specifically established a rate of privacy in their Constitution and reinforced it in their Data Protection Act which maintains that individuals and companies have a right to privacy in their electronic communications. DDG-12said on March 3, 2014 12:18 pm Right. That makes the game "spot the fed" like a child play - just pay attention on their handset. Agents will be compromised the second they pull it out of the pocket. nrmr44said on February 28, 2014 06:02 pm It is too obviously a Boeing Black. They should have made it look like an indigenous Chinese model.

Wednesday, April 3, 2013

Ameristar Network Inc. Completes Filing for "Current Information Tier" Status on OTC Markets (Pink)

PR Newswire NEW YORK, April 3, 2013 NEW YORK, April 3, 2013 /PRNewswire/ -- AmeriStar Network, Inc. (OTC Markets: AMWK)("AmeriStar") has complied with the filing requirements of OTC Markets and has been moved to the Current Information Tier. Since the merger of SecurDigital, Inc. into a subsidiary of the Company in February 2011, the Company has transformed itself into a mobile applications and SaaS provider of Cloud-based software solutions. SecurDigital is in final stages of product development and is undertaking the marketing of its SecurDigital mobile applications. According to CEO Bruce Magown, "Awareness in the marketplace about identity theft, industrial espionage and cyber-attacks has increased exponentially, with wireless mobile devices being particularly vulnerable -- and that's what we help protect by securing the communication." SecurDigital, Inc. with its proprietary technology is poised to protect corporations, governments and even individuals from scanning, hacking and espionage through a major advance in the delivery of secure and interoperable wireless communications. Eliminating the exposure of wireless communication to scanners or hackers, its SecurVoice™ technology can be delivered to subscribers over the Internet using the Software-as-a-Service ("SaaS") model. SecurVoice™ is the world's first totally secure, wireless, digital communications "software only" solution for security and interoperability over wireless and VoIP communications, and it works across multiple carriers, operating systems and hardware, performing wireless "interoperability" for WiMAX and WiFi products globally. The market for mobile security applications in an environment marked by increasingly dangerous and sophisticated hackers and criminal elements has been estimated to exceed a billion dollars worldwide. Statements in this press release may be "forward-looking statements" within the meaning of the Private Securities Litigation Reform Act of 1995. Words such as "optimizing," "potential," "anticipate," "goal," "intend" and similar expressions, as they relate to the company or its management, identify forward-looking statements. These statements are based on current expectations, estimates and projections about the company's business based, in part, on assumptions made by management. These statements are not guarantees of future performance and involve risks, uncertainties and assumptions that are difficult to predict. Actual outcomes and results may, and probably will, differ materially from what is expressed or forecasted in such forward-looking statements due to numerous factors, including those described above and those risks discussed from time to time in Company filings with the Securities and Exchange Commission. These statements and other forward-looking statements are not guarantees of future performance and involve risks and uncertainties. AmeriStar Network, Inc. assumes no responsibility to update any of the forward-looking statements in this news release. Neither the Company nor any other person assumes responsibility for the accuracy or completeness of these forward-looking statements. Nothing in this press release should be construed as either an offer to sell or a solicitation of an offer to buy or sell shares of AmeriStar Network, Inc. in any jurisdiction. SOURCE AmeriStar Network, Inc. The above news release has been provided by the above company via the OTC Disclosure and News Service. Issuers of news releases and not OTC Markets Group Inc. are solely responsible for the accuracy of such news releases.

Army has lost control of its mobile devices, says DOD IG

By Defense Systems StaffApr 02, 2013 The inspector general of the Defense Department reports that the Army’s Chief Information Office/G-6 has, in essence, lost control over commercial mobile devices (CMD) within the Army, and that more than 14,000 smartphones and tablets are untracked. The upshot is that the Army CIO office does not have an effective cybersecurity program that identifies and mitigates risks surrounding CMDs and removable media, according to the DOD IG. “The Army did not implement an effective cybersecurity program for commercial mobile devices,” wrote Alice Carey, assistant DOD inspector general for readiness, operations and support, in a memorandum dated March 26. “If the devices remain unsecure, malicious activities could disrupt Army networks and compromise sensitive DOD information.” According to the IG report, entitled, Improvements Needed With Tracking and Configuring Army Commercial Mobile Devices, the “Army CIO did not implement an effective cybersecurity program for CMDs. Specifically, the Army CIO did not appropriately track CMDs and was unaware of more than 14,000 CMDs used throughout the Army.” (The figure excludes Blackberry devices.) Additionally, the Army CIO did not ensure that commands configured CMDs to protect stored data. According to the DOD IG, the CIOs at the U.S. Military Academy (USMA), West Point, NY, and the Army Corps of Engineers’ Engineer Research and Development Center (ERDC), Vicksburg, MS, did not use a mobile device management application to configure CMDs to protect stored data, which means that they did not have the capability to remotely wipe data stored on CMDs that were transferred, lost, stolen or damaged. Also, the CIOs at USMA and ERDC allowed users to store sensitive data on CMDs that acted as removable media. “These actions occurred because the Army CIO did not develop clear and comprehensive policy for CMDs purchased under pilot and non-pilot programs,” states the IG report. In addition, the Army CIO inappropriately concluded that CMDs were not connecting to Army networks and storing sensitive information. “As a result, critical information assurance controls were not appropriately applied, which left the Army networks more vulnerable to cybersecurity attacks and leakage of sensitive data.” In response, the Army and Defense Information Systems Agency (DISA) agreed to develop a mobile device management (MDM) process to verify that users of CMDs are following Army and DOD information assurance policies and implementing the appropriate security controls to protect CMDs. Establishment of MDM and mobile application store architectures will be designed to make all CMDs managed mobile devices, which would result in the ability to observe every DOD-managed CMD, as well as the applications operating on the devices. Additionally, the Army will gain the ability to wipe or remove a device from the environment, as well as monitor applications used, websites visited, plus data viewed, saved or modified on the mobile devices. To that end, the Army issued a request for proposal for the MDM and mobile application store and expects to make an award this month, with initial operating capability expected by October 2013, with full operating capability available before the end of fiscal year 2014.

Monday, April 30, 2012

Kenneth Van Wyk: We need more secure mobile devices

As things stand now, all bets are off if you lose your smartphone Computerworld - When you combine the words "mobile device" and "security," you get an oxymoron. That's the state of security in the mobile world, and it's been that way since day one. That has to change. Smartphones and tablets are increasingly doing heavy lifting in the corporate world, and are ever more likely to be repositories of sensitive data. But where do we start in making them more secure? For now, forget about malware and sophisticated hacking. We first need to close the most gaping hole of all for mobile devices, one that every expert I have talked to over the years has agreed on: If a bad guy gets physical access to a mobile device, all bets are off. A few months ago, the folks at the OWASP Mobile Security Project backed up this assessment. They did a threat modeling exercise of mobile devices and determined that two of the most glaring issues are the loss or theft of the device and insecure communications. A basic problem is that anyone who gets his hands on someone else's smartphone can access the user's login credentials with ridiculous ease. Mobile apps contribute to this problem. I myself have realized that some of the mobile apps that I use store login credentials and other sensitive data where they shouldn't be, and in the last month or so, I've read about numerous cases of such iOS app weaknesses. Using nothing more than a USB cable, an attacker can in many cases get to login and/or session credentials for many high-profile apps, on both iOS and Android platforms. For starters, mobile app developers must keep in mind when writing their software that devices can easily be lost or stolen -- and recognize that a lost device shouldn't be a free ticket to valuable data. Most modern mobile platforms provide mechanisms for reasonably protecting things like user login credentials. These mechanisms are generally called keychains. Current versions of both Android and iOS have keychain APIs that app developers can and should be using. While not perfect, they do provide significant protection over simply storing usernames and passwords -- even when hashed -- in plaintext files (e.g., plist or properties files). Second, other user data on mobile devices should be encrypted. This is something that users have to do themselves, but Android and iOS both provide mechanisms for doing that reasonably securely, and third-party add-ons like SQLcipher for AES encrypting SQLite databases are even better. If you look for strong mobile encryption mechanisms, you can find them. Next, we need better default protection settings in our mobile platforms. For example, on Apple iOS devices, sensitive data (including things stored in app keychains) is protected by hardware encryption that is keyed with a combination of a unique 256-bit device key and the user's own device lock code. Since that device key can be obtained by an attacker with physical access to a device, the protection afforded the user by the keychain essentially comes down to how strong his device lock code is. The default setting on iOS is a four-digit PIN, which just isn't up to the task. Usability advocates will argue that strong device passwords on mobile devices are annoying and won't be accepted by users. That's a fair argument -- strong passwords on a smartphone or tablet really are a hassle to work with. (Trust me.) Still, I'd prefer something stronger than four-digit PINs to unlock a device (and the data it holds). For the longer term, device vendors need to be shooting for stronger keying mechanisms -- perhaps a PIN in combination with a biometric like a fingerprint, facial pattern scan or voice recognition. For now, though, what I suggest to people who are serious about the security of their mobile devices is to carefully select the apps they use. It's easy enough to do some cursory static analysis of an app and its files using tools like iExplorer (formerly iPhone Explorer). At the very least, make sure your apps don't store login credentials in properties files and the like. Next, turn on strong passwords and use a reasonably strong one. A PIN just doesn't cut it. The mobile computing world is as vibrant as any tech environment in the world today. To call the growth explosive would be an understatement. It's easy to lose sight of core security principles in such a rapidly moving world. Still, developers should at the very least make use of security APIs when the platform allows. There's just no excuse for not making use of keychains and other secure data storage mechanisms.

Tuesday, March 29, 2011

Network Nightmare? Personal Phones on Agency Networks

March 28, 2011 By Hilton Collins

Elayne Starkey, Delaware’s chief security officer, was worried. In 2010, she was concerned about state employees accessing the government network with personal smartphones despite the availability of state-issued BlackBerrys. The Department of Technology and Information gave employees BlackBerrys that were secured to the government’s liking. Employees’ personal smartphones, however, were a different story. Owners may have had security controls on them; they may not have.

The idea of employees using unsecured devices to access the state network didn’t make the state’s security chief happy. And employees voiced concerns of their own: The current standardization model wasn’t working.

“They were carrying around their personally owned smartphone anyway, thinking, ‘Why can’t we just combine all this access into a single device? Why do I have a BlackBerry on one hip and my personal smartphone on the other?’” Starkey said.

So on Nov. 15, 2010, Delaware state employees no longer had wholesale access to the state network on personal devices. If someone wanted to use a personal device for government business, he or she needed a manager’s approval. And the phone in question had to meet specific security standards to get the green light.

“I’m sleeping easier at night because I know that, as of Nov. 15, we have closed a significant vulnerability,” Starkey said. “Before Nov. 15, there was unfettered access to state data.”

Mobile security in general has caused quite a few headaches. The National Association of State Chief Information Officers (NASCIO) cited numerous laptop breaches in a two-part report, Security at the Edge — Protecting Mobile Computing Devices, including 2007 Ponemon Institute data claiming that more than 42 percent of all U. S. data breaches — public and private — came from lost or stolen laptops. The estimated average cost of each breach was nearly $50,000.

With smartphones entering the picture, the possibilities for data loss and corruption dramatically increase. Kevin Murray, vice president of product marketing at iPass, a network and mobility services company, said mobile devices — and their dangers — are here to stay. “In 2010 and before, mobile workers were essentially the exception, not the rule, and what we’re seeing in IT in general is that the mobile worker is really setting the rules now.”

The iPass Mobile Workforce Report, released in November 2010, found that 22 percent of employees surveyed breached corporate policy by using an unauthorized smartphone for work even when their companies had a strict policy against it.
Shifting Demands
Delaware changed its mobile device strategy to meet employee demands, but not without setting rules. If employees want to use their personal mobile phones for work, their managers must agree that there’s a need for it. And even after approval, some smartphones may not make the cut.

Delaware still distributes state-issued BlackBerrys, but non-state-issued mobile devices must meet seven controls that include strong passwords that expire, inactivity time-outs, encryption, lockouts after seven failed password attempts and remote wiping capabilities in case of loss or theft.

The Department of Technology and Information also created a list of devices that support the security controls, and supplied information to employees on what to tell their providers if they need assistance.

Starkey would like her department to be even more helpful, but that’s not feasible. “As much as I’d love to be an expert on every single mobile device out there and every single operating system version that’s available on those devices, we just can’t do it,” she said. “It’s really impractical for them to look at the state help desk as their hotline for their personally owned smartphone questions.”

Many would likely agree that it’s unwise to lay security responsibilities mainly in the hands of the employee. Murray is one of them. “It can’t be, ‘Here’s your phone,’ or, ‘Here’s the instructions on what phone to buy. Good luck,’” he said. “The critical thing is, IT still has to be involved with enforcing the policy on that device, even if it’s user liable.”

Charles Robb, a NASCIO senior policy analyst, wrote in part two of the Security at the Edge series that of 36 surveyed states, 14 had policies allowing the use of personally owned smartphones for work, 10 prohibited their use, six were reviewing state policy on the matter, and six left the decision to individual state agencies rather than central IT.

Theresa A. Masse, Oregon’s chief information security officer, agrees with others about the impending threats smartphones pose, especially when government IT doesn’t own or control them. “Now you potentially have state information on a personally owned device, so we don’t know what’s on it,” she said. “We don’t know who else is using it. We don’t know how it’s stored. It’s a huge issue. Are people patching it? Where are they wandering around on their own personal device? What are they looking at?”

Masse’s department, the Enterprise Information Strategy and Policy Division, doesn’t issue government mobile devices en masse. The state leaves it up to individual agencies to decide how they’ll approach smartphone use on the job.

“We ask them to make it as a business decision and to consider the risk,” Masse said. If agencies decide to go mobile, they must develop internal policy on network access and information storage. Oregon’s policies on acceptable use and controlling portable and removable storage devices were implemented in 2007.

Nebraska’s stance is tougher: Employees aren’t allowed to use personal devices if they can access confidential information. The risks are too great. “If they have information that could walk away from state government, we have no ability to make sure that we are protecting the state against what that personal device could introduce to our networks,” said Nebraska CIO Brenda Decker.

The Mobile Lockdown
The first Security at the Edge paper cites 2008 National Institute of Standards and Technology (NIST) recommendations on cell phone and PDA security, which may not be as up-to-date as some might like, but it’s certain that people from the organization have some insight on the issue.

For starters, anyone assuming that federal information would be more attractive to cyber-criminals than state or local information should think again. “It depends,” said Tom Karygiannis, a senior researcher at NIST. “Los Angeles, how big is that economy, right? Or California, for example — the state of California is huge.”

Government users can download unsafe apps onto their smartphones just as they can with laptops or PCs. And losing a smartphone could be a recipe for disaster even if it has nothing to do with a traditional hacker-victim breach. “Let’s say you’re drafting some memo in the public sector and it’s just a draft,” Karygiannis said. “It’s meant for internal use and just discussion. This thing gets out and then people start writing articles on it. It’s not even true.”

He said users could compromise security out of device confusion. If a lab employee has a personal phone and a corporate one, it’s possible he may accidentally take a top-secret photo with a personal device instead of with the corporate phone. It’s an honest mistake, but now a top-secret image is on a personal network. “That’s just a goofy example, but you could be in an area where there are privacy issues and people shouldn’t be taking pictures,” Karygiannis said. NIST publishes guidelines and recommendations for various technologies at http://csrc.nist.gov.

The iPass report recommends that enterprise IT look beyond the laptop when it comes to IT security — rising smartphone and tablet adoption demand a more holistic approach. And managers should ensure that employee devices meet established security criteria before they’re approved.

http://www.govtech.com/security/Personal-Phones-on-Agency-Networks.html

Saturday, March 5, 2011

AmeriStar Network Inc. Completes 1-for-2 Reverse Stock Split and the Merger of SecurDigital Inc.

NEW YORK, NY -- (MARKET WIRE) -- 02/28/11 -- AmeriStar Network Inc. (PINKSHEETS: AMWKD) announced today that FINRA has put the 1-for-2 Reverse Stock Split on the FINRA Daily List. In addition, the merger of SecurDigital Inc. into a wholly-owned subsidiary of AmeriStar became effective.

The Company is also pleased to announce that Mr. Bruce Magown, the co-founder, President and CEO of SecurDigital Inc., was elected to the Board of Directors. Mr. Magown will continue to manage the day to day operations of SecurDigital.

SecurDigital Inc. developed proprietary technology to protect corporations, governments and even individuals from scanning, hacking and espionage that constitutes a major advance in the delivery of secure and interoperable wireless communications. Eliminating the exposure of wireless communication to scanners or hackers, its SecurVoice™ technology is delivered to subscribers over the Internet using the Software-as-a-Service ("SaaS") model.

SecurVoice™ is the world's first totally secure, wireless, digital communications "software only" solution for security and interoperability over wireless and VoIP communications and works across multiple carriers, operating systems and hardware, performing "wireless interoperability for WiMAX and WiFi products globally.

Statements in this press release may be "forward-looking statements" within the meaning of the Private Securities Litigation Reform Act of 1995. Words such as "optimizing," "potential," "anticipate," "goal," "intend" and similar expressions, as they relate to the company or its management, identify forward-looking statements. These statements are based on current expectations, estimates and projections about the company's business based, in part, on assumptions made by management. These statements are not guarantees of future performance and involve risks, uncertainties and assumptions that are difficult to predict. Actual outcomes and results may, and probably will, differ materially from what is expressed or forecasted in such forward-looking statements due to numerous factors, including those described above and those risks discussed from time to time in Compnay filings with the Securities and Exchange Commission.

Contact:

O. Russell Crandall
Chairman
AmeriStar
Email: Email Contact
Phone (435) 229-1955

Source: AmeriStar Network Inc.