{"id":8026,"date":"2011-04-01T14:03:39","date_gmt":"2011-04-01T18:03:39","guid":{"rendered":"http:\/\/www.bu.edu\/systems\/?p=8026"},"modified":"2021-08-23T14:24:55","modified_gmt":"2021-08-23T18:24:55","slug":"protecting-the-identity-in-your-pocket","status":"publish","type":"post","link":"https:\/\/www.bu.edu\/cise\/protecting-the-identity-in-your-pocket\/","title":{"rendered":"Protecting the Identity in Your Pocket"},"content":{"rendered":"<p>The same day that Mark Crovella and his computer science colleagues kicked off a symposium last semester to discuss their $3 million, five-year smartphone security project funded by the <a href=\"http:\/\/www.nsf.gov\/\" target=\"_blank\" rel=\"noopener noreferrer\">National Science Foundation<\/a>, the <em>New York Times<\/em> published a <a href=\"http:\/\/www.nytimes.com\/2010\/09\/05\/magazine\/05hacking-t.html?_r=2\" target=\"_blank\" rel=\"noopener noreferrer\">front-page article<\/a> about tabloid reporters in London hacking into the mobile devices of English soccer stars and celebrities, most notably members of the British royal family, including Prince William and Prince Harry.<\/p>\n<p>While the tabloid case, now unfolding in the <a href=\"http:\/\/www.nytimes.com\/2011\/02\/02\/world\/europe\/02hacking.html\" target=\"_blank\" rel=\"noopener noreferrer\">court system<\/a>, involves reporters hacking into voice mails with stolen pin numbers, it underscores how cell phones have not only centralized our personal information\u2014storing our schedules, finances, and social networking tools\u2014but exposed that data to such threats as malicious applications, identity theft, and eavesdropping.<\/p>\n<p>Last week, a German politician sued Deutsche Telekom (owner of <a href=\"http:\/\/www.t-mobile.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">T-Mobile<\/a>) for the tracking information the cell phone company had compiled on him. He was astounded to learn that over a six-month period, Deutsche Telekom had recorded and saved his longitude and latitude coordinates more than 35,000 times. It basically knew where he was at all times.<\/p>\n<p>Crovella, a College of Arts &amp; Sciences computer science professor, and his colleagues are looking to do something about this potential compromising of our electronic identities as hardwired features on phones give way to open-source software programs and customized applications. Based at BU\u2019s <a href=\"http:\/\/www.bu.edu\/riscs\/\" target=\"_blank\" rel=\"noopener noreferrer\">Center for Reliable Information Systems and Cyber Security<\/a> (RISCS), the project, called Securing the Open Softphone, includes nine senior investigators from CAS, the College of Engineering, and Metropolitan College (Deutsche Telekom and Raytheon Company\u2019s BBN Technologies are the project\u2019s industrial partners).<\/p>\n<p><img loading=\"lazy\" src=\"..\/..\/today\/files\/images\/2cellphone.jpg\" alt=\"\" width=\"222\" height=\"296\" align=\"right\" class=\"\" \/><em><\/em><\/p>\n<p><em>\u00a0B<\/em><em>U Today<\/em> spoke recently with Crovella, one of the project\u2019s lead researchers.<\/p>\n<p><strong><em>BU Today<\/em>: What is the difference between a \u201csoftphone\u201d and a cell phone?<\/strong><br \/>\n<strong>Crovella:<\/strong> The reason for coining a term like \u201csoftphone\u201d is that the nature of the security problem on the phone has changed because the capabilities of the phone have changed. The underlying architecture on the cell phone operating system is very different from five years ago. When we\u2019re talking about a smartphone, we\u2019re basically talking about a softphone. The reason for making the distinction is to draw attention to the wide array of sensors that are available on the phone and the new architecture for the software. The architecture is now closer to what\u2019s on a desktop PC.<\/p>\n<p><strong>Is surfing the web on a phone less safe than on a home computer?<\/strong><br \/>\nThere are just as many weaknesses in a softphone browser. But the effects of the exposure can be more serious. You\u2019re more likely to have a collection of personal data, financial data, location data. Phones are increasingly being used as the medium for financial transactions. The next iPhone will have near-field communication chips, which are used for \u201ccardless debit\u201d\u2014like a VISA you wave at a terminal or Mobil gas station has a key chain you wave at the pump. Those capabilities will be enabled in the next generation of phones. The compromised phone can be used to make unauthorized phone calls. There was an Android app in the last month or two that was sending text messages to a very expensive destination. The app developer was getting a cut of the resulting revenue.<\/p>\n<p><strong>Where does the level of responsibility lie? How much is on the shoulders of the phone manufacturer, the carrier, the user?<\/strong><br \/>\nThat\u2019s actually a struggle that\u2019s playing out right now. I think people have felt instinctively that the responsibility ought to lie with the phone owner. Now I think people are starting to realize maybe we should relinquish some of our control to a central party that can at least provide some measure of security over the applications.<\/p>\n<p>When the iPhone was announced, Apple had already worked out the details of a mechanism for third parties to create software and sell it, and that is the App Store that we know and love. The procedures that Apple put in place require very strong authentication. All developers have to sign their applications with a cryptographically secure certificate. Every application is tied to a developer, and as you know, all of the applications get reviewed by Apple. At the time, there was a hue and cry that this was a walled garden.<\/p>\n<p>So when Google announced the Android app store, they specifically eschewed this Big-Brotherish control that Apple exerts, and they only require applications to be signed by the developer in a way that is not as secure. Most importantly, they don\u2019t require a review for the source code or the application. But in just the last couple of weeks, we\u2019ve seen some really nasty Android apps that were essentially only possible because Google adopted this hands-off strategy. Some bad guys found ways to take an existing application, modify it to send, for example, really expensive text messages, and then upload it back to the store. So you could be downloading your favorite Tetris application, and it looks for all the world like the application was released by the famous developer, but it has in fact been surreptitiously modified to do something very nasty.<\/p>\n<p><strong>Should people feel worried that cell phone companies can track their every move if they want to?<\/strong><br \/>\nThe tracking itself is not a violation. Phone companies are allowed to collect data that helps them engineer their networks, and this data is necessary for deciding where to place cell towers, how to route calls, and so on. The problem occurs when companies use or sell location information for other purposes: marketing, mostly. There\u2019s incredible pressure for companies to monetize their assets, and it\u2019s becoming increasingly clear that data can be a game-changing asset. Phone companies have considered using their data for personalized and location-based advertising, and in some cases are even analyzing social networks based on call records. So people have good cause to be concerned.<\/p>\n<p><strong>BU is working on this project with Deutsche Telekom, recently forced to reveal it had closely tracked a German politician. Does that pose a conflict for your work? <\/strong><br \/>\nDT is an immense company and we work with folks in the research arm while the story about the politician concerns the operational side. However, when data like this is released into the public domain, it actually aids research, because it provides realistic inputs for experiments and analyses.<\/p>\n<p><strong>What sort of work have you been doing since receiving the NSF grant?<\/strong><br \/>\nThe work is just getting started. There\u2019s the research side and the outreach side. We\u2019ve started a project to do a stronger form of authentication between phones. Say we meet in a bar and I want to send you my contact information. If I sent it through the internet, there\u2019s all sorts of security issues associated with that. It would be nice if I could send this directly from my phone to your phone. We could do this in a way that had no exposure to eavesdropping over the internet. One of the advantages you have in this situation is that both phones are in the same environment, so they can sense the same environment. And a simple way to do that is to take the two phones and shake them at the same time while holding them together. So they\u2019re both sensing acceleration and that can be measured, and that gives you the ability to create encryption keys in both phones, without any data passing between them. So nothing that can be eavesdropped on passed between the two phones, but both phones now possess a secret that allows them to communicate.<\/p>\n<p><strong>What kind of phone do you use?<\/strong><br \/>\nAn iPhone.<\/p>\n<p><strong>Do you think that\u2019s the most secure?<\/strong><br \/>\nOf the softphones? Yes. Of all phones? Not at all. It\u2019s certainly less secure than a phone from the previous generation where the software was provided by the manufacturer and couldn\u2019t be modified.<\/p>\n<p><strong>What kind of security measures have you taken?<\/strong><br \/>\nActually, the biggest change that I\u2019ve made is to realize how vulnerable my data is if it doesn\u2019t have a pass code on it. But a pass code only slows down dedicated hackers; it doesn\u2019t prevent them. Studies have shown it\u2019s not hard to disable a pass code if you have access to the phone. But it takes a certain period of time. The idea is that you slow the attacker down enough so that you\u2019d have time to, let\u2019s say, engage the remote wipe feature, if that\u2019s what you decide to do. Apple has now added a remote erase feature, which was a big selling point for the BlackBerry for a long time. The basic idea was that your BlackBerry contained so much company information that the company needs the ability to erase it if you lose it.<br \/>\n<em><\/em><\/p>\n<p><em>Caleb Daniloff can be reached at cdanilof@bu.edu.<\/em><br \/>\n<em>Published in BUToday April 1, 2011<\/em><br \/>\nhttp:\/\/www.bu.edu\/today\/node\/12638<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The same day that Mark Crovella and his computer science colleagues kicked off a symposium last semester to discuss their $3 million, five-year smartphone security project funded by the National Science Foundation, the New York Times published a front-page article about tabloid reporters in London hacking into the mobile devices of English soccer stars and [&hellip;]<\/p>\n","protected":false},"author":1500,"featured_media":33826,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[26],"tags":[],"_links":{"self":[{"href":"https:\/\/www.bu.edu\/cise\/wp-json\/wp\/v2\/posts\/8026"}],"collection":[{"href":"https:\/\/www.bu.edu\/cise\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.bu.edu\/cise\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.bu.edu\/cise\/wp-json\/wp\/v2\/users\/1500"}],"replies":[{"embeddable":true,"href":"https:\/\/www.bu.edu\/cise\/wp-json\/wp\/v2\/comments?post=8026"}],"version-history":[{"count":8,"href":"https:\/\/www.bu.edu\/cise\/wp-json\/wp\/v2\/posts\/8026\/revisions"}],"predecessor-version":[{"id":33829,"href":"https:\/\/www.bu.edu\/cise\/wp-json\/wp\/v2\/posts\/8026\/revisions\/33829"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.bu.edu\/cise\/wp-json\/wp\/v2\/media\/33826"}],"wp:attachment":[{"href":"https:\/\/www.bu.edu\/cise\/wp-json\/wp\/v2\/media?parent=8026"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.bu.edu\/cise\/wp-json\/wp\/v2\/categories?post=8026"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.bu.edu\/cise\/wp-json\/wp\/v2\/tags?post=8026"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}