Posts

Showing posts with the label Mobile Security

BYOD, CYOD, COPE and COBO: Mobile Deployment Models Compared

Four acronyms, one question: who owns the device, and how much of it does the organization control? Security+ tests these as a set, and the discriminator in nearly every question is ownership rather than technology. The Four Models BYOD — Bring Your Own Device. The employee owns the device and uses it for work. Lowest cost to the organization, highest support burden, least control. The device may be any model, any operating system version, any patch level, shared with family members. CYOD — Choose Your Own Device. The organization publishes an approved list; the employee picks from it. Ownership varies by implementation — sometimes corporate, sometimes employee with a stipend — but the device is a known, supportable model. This is the compromise position: more predictability than BYOD, more choice than a single issued handset. COPE — Corporate Owned, Personally Enabled. The organization buys and owns the device and permits reasonable personal use...

Mobile Device Attack Surface: Rooting, Sideloading and Debug Interfaces

Mobile operating systems are considerably more locked down than desktops. Applications run in sandboxes, code must be signed, installation goes through a reviewed store, and the system partition is verified at boot. Most mobile compromise involves removing one of those protections rather than defeating it. Security+ tests the vocabulary and the detection story. Both are worth getting precise. Rooting and Jailbreaking Same concept, different platforms. Rooting is gaining administrative privilege on Android; jailbreaking is the equivalent on iOS. Users do it for customization, to remove vendor software, or to run applications the platform does not permit. What it actually removes is the platform's own enforcement: Application sandboxing. A privileged process can read other applications' private storage, including credentials and tokens belonging to the managed work applications. Verified boot. The chain of signatures that guarantees the running system is the one the...

Geofencing Explained: Location-Based Access Control for Security+

Geofencing defines a virtual boundary around a physical area and triggers an action when a device enters or leaves it. On the Security+ exam it appears as a mobile device and conditional access control, and it is distinct from the geographic restrictions covered separately. The three related terms CompTIA uses these together and expects you to separate them. Geolocation is determining where a device is — by GPS, by which cell towers or Wi-Fi networks it can see, or by IP address. It is the input. Geofencing is defining a boundary and acting on crossings of it. It is the rule. Geographic restrictions , sometimes geoblocking, allow or deny access based on the country or region a request comes from, usually by IP. It is a coarse access control applied at the network or application layer. Geofencing is about a specific area and the act of entering or leaving; geographic restrictions are about which country you are in. A rule that unlocks a feature when a phone arrives at the office...

Geolocation Explained: Positioning Methods and Accuracy for Security+

Geolocation is determining where a device is. It is the input that geofencing, geographic restrictions and impossible travel detection all depend on, and understanding how the methods differ explains how far each of those controls can be trusted. The positioning methods Method Typical accuracy Works indoors GNSS / GPS 3–5 m outdoors Poorly Wi-Fi positioning 5–20 m Yes Cell tower 100 m to several km Yes Bluetooth beacons 1–5 m Yes, room level IP address City to country N/A GNSS — the family including GPS, GLONASS, Galileo and BeiDou — works by timing signals from satellites. Four satellites give a three-dimensional fix. It needs sky visibility, so it degrades indoors and in urban canyons, and it takes time and battery to acquire a fix. Wi-Fi positioning compares the networks a device can see against a database of access point locations. Surprisingly accurate, works indoors, and fast — which is why phones use it constantly alongside GPS. Cell tower positioning triangulates...