1
00:00:00,000 --> 00:00:01,890
In this lesson, we'll dive into the world

2
00:00:01,890 --> 00:00:04,260
of mobile vulnerabilities and attacks.

3
00:00:04,260 --> 00:00:05,400
Now, our mobile devices,

4
00:00:05,400 --> 00:00:07,680
such as our smartphones, tablets, and wearables,

5
00:00:07,680 --> 00:00:10,440
have become an indispensable part of our daily lives.

6
00:00:10,440 --> 00:00:13,110
These devices are used to connect us, entertain us,

7
00:00:13,110 --> 00:00:14,880
and increasingly secure and manage

8
00:00:14,880 --> 00:00:16,950
our personal and professional data.

9
00:00:16,950 --> 00:00:19,320
Yet, the convenience provided by these mobile devices

10
00:00:19,320 --> 00:00:20,970
really is a double-edged sword,

11
00:00:20,970 --> 00:00:22,350
because the very features that make them

12
00:00:22,350 --> 00:00:23,970
so valuable to us as users

13
00:00:23,970 --> 00:00:25,740
are also going to expose us to a myriad

14
00:00:25,740 --> 00:00:28,380
of different vulnerabilities and potential attacks.

15
00:00:28,380 --> 00:00:29,610
To secure our mobile devices

16
00:00:29,610 --> 00:00:30,900
and the data they contain,

17
00:00:30,900 --> 00:00:33,240
we have to first understand the mobile vulnerabilities,

18
00:00:33,240 --> 00:00:36,060
including things like sideloading, jailbreaking, rooting,

19
00:00:36,060 --> 00:00:37,740
and insecure connection methods,

20
00:00:37,740 --> 00:00:40,140
as well as how to mitigate against these vulnerabilities,

21
00:00:40,140 --> 00:00:42,750
and how we can use a mobile device management solution

22
00:00:42,750 --> 00:00:44,340
to best minimize the other risks

23
00:00:44,340 --> 00:00:46,350
associated with mobile devices.

24
00:00:46,350 --> 00:00:49,260
Now, first, we have a vulnerability known as sideloading.

25
00:00:49,260 --> 00:00:50,820
Sideloading refers to the practice

26
00:00:50,820 --> 00:00:52,620
of installing applications on a device

27
00:00:52,620 --> 00:00:55,170
from unofficial sources, which actually bypasses

28
00:00:55,170 --> 00:00:57,720
the device's default application store.

29
00:00:57,720 --> 00:00:59,880
While it may be useful in certain situations,

30
00:00:59,880 --> 00:01:01,470
sideloading is also dangerous,

31
00:01:01,470 --> 00:01:02,850
because it can introduce malware

32
00:01:02,850 --> 00:01:04,620
or malicious apps onto a device,

33
00:01:04,620 --> 00:01:07,320
because the application files are not scanned or verified

34
00:01:07,320 --> 00:01:08,760
by your mobile device's provider's

35
00:01:08,760 --> 00:01:10,650
app store submission process.

36
00:01:10,650 --> 00:01:12,330
To ensure your device remains secure,

37
00:01:12,330 --> 00:01:14,310
you should avoid sideloading, and instead,

38
00:01:14,310 --> 00:01:17,520
always download apps from the official and trusted sources,

39
00:01:17,520 --> 00:01:19,650
like your mobile device's official app store,

40
00:01:19,650 --> 00:01:21,330
because these platforms often have

41
00:01:21,330 --> 00:01:23,220
a strict review process in place,

42
00:01:23,220 --> 00:01:26,220
to ensure all of their apps are free from malicious code.

43
00:01:26,220 --> 00:01:28,350
Second, we can have a lot of vulnerabilities

44
00:01:28,350 --> 00:01:31,710
added to our devices if we jailbreak or root our device.

45
00:01:31,710 --> 00:01:33,720
Now, jailbreaking on iPhones, and iPads,

46
00:01:33,720 --> 00:01:35,670
and rooting on Android-based devices

47
00:01:35,670 --> 00:01:37,800
is considered to be a process that gives the users

48
00:01:37,800 --> 00:01:40,110
escalated permissions on their devices,

49
00:01:40,110 --> 00:01:42,450
and allows them to circumvent built-in security measures

50
00:01:42,450 --> 00:01:44,100
provided by the device.

51
00:01:44,100 --> 00:01:46,710
Jailbreaking and rooting is usually done so that a user

52
00:01:46,710 --> 00:01:49,230
can have greater device customization capabilities,

53
00:01:49,230 --> 00:01:51,270
but this process does expose your device

54
00:01:51,270 --> 00:01:53,250
to potential security breaches, too.

55
00:01:53,250 --> 00:01:55,500
After all, your mobile device manufacturer

56
00:01:55,500 --> 00:01:57,540
regularly provides updates to their devices

57
00:01:57,540 --> 00:01:58,890
to combat new vulnerabilities

58
00:01:58,890 --> 00:02:00,600
that are being discovered all the time,

59
00:02:00,600 --> 00:02:02,790
but if you jailbreak or root your device,

60
00:02:02,790 --> 00:02:04,470
you're unable to install these updates,

61
00:02:04,470 --> 00:02:05,640
and your device will be vulnerable

62
00:02:05,640 --> 00:02:08,039
to these newly discovered attacks and exploits.

63
00:02:08,039 --> 00:02:09,720
So, it's a good idea to keep

64
00:02:09,720 --> 00:02:11,550
your device's original security setting,

65
00:02:11,550 --> 00:02:14,490
to ensure you remain protected against any known threats.

66
00:02:14,490 --> 00:02:16,470
Third, insecure connection methods

67
00:02:16,470 --> 00:02:18,960
can be another large area of vulnerability for us.

68
00:02:18,960 --> 00:02:20,670
Since our mobile devices will usually rely

69
00:02:20,670 --> 00:02:22,890
on wireless connections like Wi-Fi and Bluetooth

70
00:02:22,890 --> 00:02:24,420
for their connectivity needs,

71
00:02:24,420 --> 00:02:26,730
these devices can be exploited by an attacker

72
00:02:26,730 --> 00:02:28,650
if you're using insecure connection methods

73
00:02:28,650 --> 00:02:31,680
when you connect to those wireless networks or connections.

74
00:02:31,680 --> 00:02:33,360
When you're using your mobile devices,

75
00:02:33,360 --> 00:02:35,940
you should always avoid using open Wi-Fi networks

76
00:02:35,940 --> 00:02:38,190
or pairing with unknown devices over Bluetooth,

77
00:02:38,190 --> 00:02:39,600
because both of these can expose

78
00:02:39,600 --> 00:02:41,430
your mobile devices to eavesdropping,

79
00:02:41,430 --> 00:02:43,980
an on-path attack, unauthorized data access,

80
00:02:43,980 --> 00:02:46,200
or other types of malicious attacks.

81
00:02:46,200 --> 00:02:48,510
Instead of relying on open Wi-Fi networks,

82
00:02:48,510 --> 00:02:49,890
you should instead use your device's

83
00:02:49,890 --> 00:02:51,450
own cellular data connection,

84
00:02:51,450 --> 00:02:53,490
because they are considered to be much more trustworthy

85
00:02:53,490 --> 00:02:55,950
and secure than a Wi-Fi connection is.

86
00:02:55,950 --> 00:02:58,680
Additionally, if you are going to use a Wi-Fi network,

87
00:02:58,680 --> 00:02:59,940
you should use one that's protected

88
00:02:59,940 --> 00:03:01,830
by a robust authentication system,

89
00:03:01,830 --> 00:03:04,530
like one with a long, strong, and complex password,

90
00:03:04,530 --> 00:03:07,650
or one that uses 802.1x authentication methods

91
00:03:07,650 --> 00:03:09,840
for even higher levels of security.

92
00:03:09,840 --> 00:03:12,000
Also, when you're using Bluetooth,

93
00:03:12,000 --> 00:03:13,890
you want to connect to only known devices,

94
00:03:13,890 --> 00:03:16,110
and ensure that your device is set to non-discoverable

95
00:03:16,110 --> 00:03:17,790
when you're not pairing it.

96
00:03:17,790 --> 00:03:19,020
So, now that we understand

97
00:03:19,020 --> 00:03:20,280
some of the different vulnerabilities

98
00:03:20,280 --> 00:03:21,720
and how we can mitigate them,

99
00:03:21,720 --> 00:03:23,430
let's take a look at a specialized product

100
00:03:23,430 --> 00:03:25,590
known as mobile device management.

101
00:03:25,590 --> 00:03:28,260
Now, a mobile device management, or MDM solution,

102
00:03:28,260 --> 00:03:29,490
will help to minimize the risk

103
00:03:29,490 --> 00:03:31,410
associated with mobile vulnerabilities

104
00:03:31,410 --> 00:03:32,970
by ensuring that regular patching,

105
00:03:32,970 --> 00:03:34,440
device configuration management,

106
00:03:34,440 --> 00:03:35,790
and best practice enforcement

107
00:03:35,790 --> 00:03:38,070
are occurring within your organization.

108
00:03:38,070 --> 00:03:40,230
Mobile device management solutions can be used

109
00:03:40,230 --> 00:03:42,240
to conduct regular patching of your devices

110
00:03:42,240 --> 00:03:44,790
by pushing any necessary updates to your devices,

111
00:03:44,790 --> 00:03:46,470
in order to ensure that they're always equipped

112
00:03:46,470 --> 00:03:48,420
with the latest security patches.

113
00:03:48,420 --> 00:03:51,090
Another key function of a mobile device management solution

114
00:03:51,090 --> 00:03:52,620
is to enforce configuration management

115
00:03:52,620 --> 00:03:54,180
on all of your devices.

116
00:03:54,180 --> 00:03:56,130
By relying on an MDM solution,

117
00:03:56,130 --> 00:03:57,870
we can set a standardized configuration

118
00:03:57,870 --> 00:03:59,190
for all of our devices,

119
00:03:59,190 --> 00:04:00,870
to ensure that our devices are all meeting

120
00:04:00,870 --> 00:04:02,730
our organization security benchmarks

121
00:04:02,730 --> 00:04:04,620
and baseline configurations.

122
00:04:04,620 --> 00:04:07,320
Also, we can use a mobile device management solution

123
00:04:07,320 --> 00:04:09,090
to enforce the use of best practices

124
00:04:09,090 --> 00:04:11,040
on our organization's devices.

125
00:04:11,040 --> 00:04:12,570
For example, we can disable

126
00:04:12,570 --> 00:04:14,790
a device's ability to sideload programs,

127
00:04:14,790 --> 00:04:17,220
to detect if a device has been jailbroken or rooted,

128
00:04:17,220 --> 00:04:19,769
and to force each device to use a VPN connection

129
00:04:19,769 --> 00:04:20,603
when it connects back

130
00:04:20,603 --> 00:04:22,530
to your organization's data repositories

131
00:04:22,530 --> 00:04:24,630
over a Wi-Fi or cellular connection,

132
00:04:24,630 --> 00:04:27,780
all by enforcing this inside of our MDM solution.

133
00:04:27,780 --> 00:04:29,520
So, remember, our mobile devices

134
00:04:29,520 --> 00:04:31,230
are powerful and convenient,

135
00:04:31,230 --> 00:04:32,520
but they also are vulnerable

136
00:04:32,520 --> 00:04:34,680
to a wide range of threats and attacks.

137
00:04:34,680 --> 00:04:37,470
Whether it's the temptation to sideload that must-have app,

138
00:04:37,470 --> 00:04:39,330
the allure of jailbreaking or rooting your device,

139
00:04:39,330 --> 00:04:40,650
so you have additional functionalities

140
00:04:40,650 --> 00:04:42,030
and configuration options,

141
00:04:42,030 --> 00:04:43,590
or the oversight of connecting

142
00:04:43,590 --> 00:04:45,600
to an unsecured Wi-Fi network.

143
00:04:45,600 --> 00:04:46,710
The risk to your devices

144
00:04:46,710 --> 00:04:49,230
and the data they contain are very real.

145
00:04:49,230 --> 00:04:51,750
However, by understanding these different vulnerabilities

146
00:04:51,750 --> 00:04:53,190
and implementing best practices,

147
00:04:53,190 --> 00:04:55,380
and a robust mobile device management solution,

148
00:04:55,380 --> 00:04:57,330
you can enjoy the benefits of your devices,

149
00:04:57,330 --> 00:05:00,303
while still ensuring that your data remain safe and secure.

