Tag Archive for IOS

Mobile Malware FUD?

Mobile Malware FUD?Just last week, I wondered out loud from my Bach Seat if all the hype around mobile malware was real or just more FUD. Looks like I am not alone, TechCo recently asked a similar question, “Are We Overstating the Threats from Mobile Devices?

mobile threatsThe author cites several recent reports that back up the claim that the actual mobile threats that mobile devices introduce into the enterprise are overstated. The data indicates that the mobile malware threat is statistically small and has even decreased since 2012.

• A McAfee report shows out of all the malware now out there, only 1.9% of it is mobile malware. The author equates the mobile threat to 4 million / 195 million McAfee knows about.
• Another report (PDF) from Verizon (VZ) shows even lower numbers, with only 0.03 percent of smartphones being infected with what is called “higher grade malicious code.”
hit by lighting• But some numbers go even lower than that. Damballa, a mobile security vendor that monitors roughly half of mobile data traffic, recently released a report that claims you have a better chance of getting hit by lightning than by mobile malware. Dramballa found only 9,688 smartphones out of more than 150 million showed signs of malware infection. If you do the math, that comes out to an infection rate of 0.0064 percent.

Even more interesting is that despite the increase in mobile devices, Damballa found the infection rate had declined by half compared to 2012.

Walled gardenThese reports may show mobile threats aren’t as big of a problem as previously thought, but the author asks, why the numbers are so low at all. After all, cybercriminals like to target new platforms and exploit security weaknesses. Why do they seem to be avoiding mobile devices?

The truth of the matter is that mobile users tend to get their apps from high-quality app stores. The stores from Google (GOOG) and Apple (AAPL) work to filter out suspicious apps. If malware is found in apps after they’ve already been on the market for a while, app stores can also execute a kill switch, which takes the app off the store and the devices where they were downloaded. This limits malware’s ability to spread.

remotely wipe devicesThe article concludes that companies that adopt BYOD should just ignore BYOD security; they just don’t have to go all-out as many businesses have done. Most mobile security experts say a mobile device management system remains a good investment to make sure mobile devices are handled appropriately. MDM systems also allow an organization to remotely wipe devices, thus keeping sensitive data safe in the event a device is lost or stolen. But malware really isn’t a factor in those cases, so the overall message from these recent reports is that getting worked up over mobile threats is not necessary. A company can still gain all the benefits of BYOD without having to worry incessantly over what they’re doing to protect every device that connects to their network.

rb-

What do you think?

Is mobile malware over-hyped FUD?

View Results

Loading ... Loading ...

 

Related articles
  • Your BYOD implementation checklist (powermore.dell.com)

 

Ralph Bach has been in IT long enough to know better and has blogged from his Bach Seat about IT, careers, and anything else that catches his attention since 2005. You can follow him on LinkedInFacebook, and Twitter. Email the Bach Seat here.

Scary PII Numbers

Scary PII NumbersAs you may have heard by now, the second-largest health insurer Anthem gave away at least 80 million of their customers’ PII records to hackers. I say at least because these always grow as the experts dig through the wreckage. The WSJ reports the Indianapolis-based insured did not encrypt this data (I covered encryption here and here). That means customers’ social security numbers, phone numbers, and other PII were easy targets for Chinese hackers according to CNBC.

did not encrypt data

Anthem is just the latest. There are even larger targets out there. The Business Insider published some pretty scary numbers. BI reports that somehow the biggest tech companies have done a great job at convincing people that their services for sending/receiving payments and purchasing goods are trustworthy and worthwhile. The article estimates that Apple has somewhere around a billion iTunes accounts (with plenty of PII and credit cards) on file.

This chart from BI IntelligenceApple (AAPL) is nearing a billion iTunes accounts on file, and that number is likely to surge immensely. Customers in China can now link their UnionPay payment cards to their Apple IDs: For context, UnionPay is the largest card network in the world with more cards in circulation than Visa and MasterCard combined.

Amazon (AMZN) has approx. 300 million payment cards on file while PayPal has around 200 million payment cards on record.

Apple, Amazon, PayPal Payment Cards on File - Business Insider

A second BI article indicates that based on leaked Uber data charted analyzed by BI Intelligence, the ride-sharing firm has well over 12 million payment cards on file. Their closest competitor Hailo has 4.4 million payment cards on file.

Ride-Sharing Payment Cards on File - Business Insider

rb-

You have been warned. The next mega data breach could come from a tech firm like Apple or Amazon.

Data theftThe WSJ article argues that companies can use many techniques to secure their data, but those things slow companies down, sometimes to a degree they find unacceptable.

I think most victims of identity theft or credit fraud find that unacceptable.

Related articles

 

Ralph Bach has been in IT long enough to know better and has blogged from his Bach Seat about IT, careers, and anything else that catches his attention since 2005. You can follow him on LinkedInFacebook, and Twitter. Email the Bach Seat here.

Windows 7 Reaches Middle Age

Windows 7 Reaches Middle AgeNow that you have almost eliminated Microsoft (MSFT) Windows XP from your network and settled on Windows 7 it should be time to catch your breath. But NOOO!! Windows 7 has reached the end of mainstream support.  That’s right we are already 5 years into the Windows 7 era. Repeat after me… Windows 7 still has five years left … Windows 7 still has five years left … Windows 7 still has five years left.

MMicrosoft Windows 7 logoicrosoft commits to 10 years of security fixes and 5 years of feature enhancements and bug fixes for each major OS release. Windows 7 has moved from mainstream support – free help for everyone – to extended support, which means Microsoft will charge for help with the software. That will end in 2020 when Microsoft turns out the lights on Windows 7 for good.

The recent techno-flops from the boys and girls in Redmond, Vista, and Windows 8 have taught enterprises to plan for a new desktop OS every other release. This puts businesses in a bind. MSFT’s track record prevents forward-looking firms from organically growing their desktop fleet into the next cycle. There are those that argue that until Microsoft separates consumer from commercial desktops, Microsoft commercial customers will continue to skip one or more iterations of Windows, their only real answer to the high costs and disruption of upgrading.

Gregg KeizerMirosoft update cycle at ComputerWorld cites research from Gartner (IT) which prognosticates that many enterprises cannot change their processes. Many organizations will go through the same machinations they did with XP. Or maybe even balk at dumping Windows 7 at the same pace as the venerable Windows XP, making things worse. Michael Silver of Gartner told ComputerWorld that having a plan could help organizations avoid a repeat of XP’s expensive end-of-support scramble. Gartner believes that the same EOL mad-scramble we saw with XP will occur again when time is up on Windows 7. Mr. Silver claims:

[A repeat of Windows XP] is certainly likely to happen … One of the big differences that’s been under-considered is that because Vista took five years to come out [after XP], there were eight years between XP and Windows 7. So Windows XP felt pretty old. … Windows 7 won’t feel that old to people…” 

Microsoft Windows 10 logoMr. Keizer argues that the failure of Windows 8 to win enterprise hearts and minds has created an oddity: Even though Windows 7 has made middle age, Microsoft continues to let OEMs sell PCs running the Windows 7 business edition.  Microsoft has yet to name an end date for OEM sales of machines powered by Windows 7 Professional. But because it has promised a 12-month notice, those PCs can still be sold at least until early January 2016, when the OS has but four years of life left.

But if you are just finishing your last migration, then you don’t have all that much time to start planning the next one.

rb-

If you don’t like the Redmond hamster wheel, consider your alternatives. Sophos compares the Windows upgrade schedule to some other options. 10 years might be the best option out there. For example:

  • Apple’s (AAPL) OS X is supported for mystery years,
  • Apple’s mobile iOS is supported for mystery years (3?)
  • Android seems to leave it up to you, but don’t expect Google (GOOG) to commit to securing it.
  • Ubuntu LTS is supported for around 5 years, and
  • Red Hat Enterprise 13 years (with extended support).
Related articles

 

Ralph Bach has been in IT long enough to know better and has blogged from his Bach Seat about IT, careers, and anything else that catches his attention since 2005. You can follow him on LinkedInFacebook, and Twitter. Email the Bach Seat here.

Tablet Trouble

Tablet TroubleThere has been a shocking long-term trend in Apple (AAPL) iPad tablet sales. Despite the much bally hoed launch of the new iPad Air 2 and iPad mini 3, sales of Apple’s iPad have sunk to their lowest level since the 2011 introduction of the iDevice.This chart from Business Insider shows the decline of iPad sales.

Apple CEO Tim Cook was unfazed about the iPad’s plunging sales. During Apple’s latest earnings call Apple’s Cook said, “I’m very bullish on where we can take iPad over time.”Apple Quarterly Revenue

Users don’t want a tablet

Despite CEO Cook’s optimism, research from Kantar Worldpanel Comtech is not so sure. In an analysis of the tablet market, they found that consumers believe that they need the latest iPad. Or any tablet for that matter.

Their conclusion is based on research which found:

  • A majority of U.S. non-tablet owners said they would not buy a tablet in the next 12 months.
  • Of those who will not buy a tablet, 725 said that their PC or laptop was “good enough” as the reason why they are not buying a tablet in the next year.
  • Tablets are not seen as an alternative to smartphones.

Carolina Milanesi, chief of research at Kantar Worldpanel laid out four reasons why tablets sales are not growing at the rate many had expected.

  1. current tablet owners plan to keep their tablets even after upgrading to a new oneReplacement cycles are longer for tablets than smartphones. Ms. Milanesi explains,”Software upgrades help refresh the devices, and carriers do not provide incentives/subsidies to encourage replacements every two years, as they do with smartphones.
  2. Tablets are not as personal as smartphones.While there is no question that tablets are more personal than PCs, if less personal than smartphones, they still land in between the two,” the Kantar chief of research says.
  3. Tablet owners hang on to their old tablet when they get a new one. Smartphone users tend to turn in their old smartphone when they upgrade to a newer one according to Kantar Worldpanel data:
    • 36% of current tablet owners plan to keep their tablets even after upgrading to a new one.
    • 18% plan to pass their old ones on to a friend or relative, according to Kantar Worldpanel data.
  4. Finally, the value proposition of tablets remains weak.They report that only 3% of U.S. non-tablet owners said they will definitely buy a tablet in the next 12 months.

rb-

I thought that tablets were going to take over the world.

So what is the use case for tablets?

If the Apple fanboyz and gurls aren’t buying new iPads why should anyone else?

Related articles

 

Ralph Bach has been in IT long enough to know better and has blogged from his Bach Seat about IT, careers, and anything else that catches his attention since 2005. You can follow him on LinkedInFacebook, and Twitter. Email the Bach Seat here.

Will iOS 8 Crush Your Network?

– Updated 09-09-14 – At their presser today, Apple announced that iOS 8 will be publicly available on Wednesday, September 17. The update is free and compatible with 10 current products:

iPhone 5S
iPhone 5C
iPhone 5
iPhone 4S
iPad Air
iPad with Retina Display
iPad 2
iPad mini with Retina Display
iPad mini
iPod touch 5th Generation

How are you going to protect your network?

Will iOS 8 Crush Your Network?TechRadar speculates that Apple’s new mobile operating system, iOS 8 will be released on September 10 and MacWorld UK reports that iOS 8 will run on most iPads, iPhones, or iPod Touch devices when it arrives. This means that if you haven’t already done something about it any iDevice that walks into your Wi-Fi will want to download 100+ megabytes of data. And you know what means user complaints that the internet is broken and the network is slow.

iOS 8 will cruch your networkThe folks at Exinda, a supplier of policy-based WAN Orchestration recently put out some suggestions on how to keep your network functional during Apple’s (AAPL) iOS 8 update madness, unlike the iOS 7 release last year. Few organizations were prepared for the effects that widespread software updates would have across corporate and educational networks.

Shortly after the software launch, download requests bombarded networks which prevented users from accessing key applications or completing work on time. Boston-based Exinda says reports from last year showed that the iOS 7 update used more than 60% of bandwidth and caused several networks to crash completely.

Exinda logoExinda polled their community of networking experts to weigh in with three possible strategies to help you survive release week, no matter how complex your IT environment is.

Set an iOS policy

Set a policy to completely block software upgrades 20% of Exinda customers said that controlling iOS 7 upgrades was their biggest IT headache last year. If iOS 7 put a huge strain on your network last year, proactively blocking this year’s software release may be the best way to protect your network.

complaints that the internet is brokenBefore release week, simply create a policy using the Apple Software Updates application signature and set it to discard the traffic. This will cause all network traffic generated from iOS 8 to be discarded, effectively keeping your users from upgrading their devices on your network.

Limit the bandwidth software upgrades use

Depending on your network and users, you may have no choice but to let some of your users upgrade their devices during peak hours, particularly if you’re a school with a 1:1 iPad program. To control the amount of bandwidth iOS 8 can use on your network, set a policy that guarantees minimum and maximum levels of bandwidth that can be consumed during this upgrade. We recommend setting the minimum at 1 Kbps and giving this policy a low priority so it does not take precedence over your more important traffic.

Three stratgiesBruce Miller, vice president of product marketing at Xirrus in a Fierce Mobile article, advised IT administrations to deploy Wi-Fi network application control software that regulates how the network handles bandwidth-hogging apps and spikes in traffic.

IT needs to be savvy at the application level, identify when something like this happens and then be able to apply QoS [quality of service] or prioritization to applications, not just to users.

Cache iOS software upgrades

Cache software upgrades at the network edge – Last year many Exinda customers cached the iOS download at the network edge, which allowed their users to upgrade their devices without using too much bandwidth or hurting network performance. To do this, create a new policy to cache the iOS 8 upgrade. This means that after the software has been downloaded on the network once, each subsequent download request will be served up locally, letting you preserve your bandwidth and prevent network outages.

rb-

The release of iOS 7 last year blindsided many IT managers. Large numbers of employees upgrading their devices at the same time caused many networks to crash, leaving users unable to access key apps or get work done on time.

I also blogged about how The NCAA Basketball and World Cup tournaments would be huge bandwidth wasters here. IT managers need to be more alert to events outside their network that can overwhelm the corporate network.

Related articles

 

Ralph Bach has been in IT long enough to know better and has blogged from his Bach Seat about IT, careers, and anything else that catches his attention since 2005. You can follow him on LinkedInFacebook, and Twitter. Email the Bach Seat here.