<?xml version="1.0"?>
<?xml-stylesheet type="text/css" href="http://wiki.cas.mcmaster.ca/skins/common/feed.css?207"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>http://wiki.cas.mcmaster.ca/index.php?action=history&amp;feed=atom&amp;title=Security_in_Smartphones</id>
		<title>Security in Smartphones - Revision history</title>
		<link rel="self" type="application/atom+xml" href="http://wiki.cas.mcmaster.ca/index.php?action=history&amp;feed=atom&amp;title=Security_in_Smartphones"/>
		<link rel="alternate" type="text/html" href="http://wiki.cas.mcmaster.ca/index.php?title=Security_in_Smartphones&amp;action=history"/>
		<updated>2026-06-14T08:02:32Z</updated>
		<subtitle>Revision history for this page on the wiki</subtitle>
		<generator>MediaWiki 1.15.1</generator>

	<entry>
		<id>http://wiki.cas.mcmaster.ca/index.php?title=Security_in_Smartphones&amp;diff=6884&amp;oldid=prev</id>
		<title>Asokanp:&amp;#32;Fixed an inline referencing error</title>
		<link rel="alternate" type="text/html" href="http://wiki.cas.mcmaster.ca/index.php?title=Security_in_Smartphones&amp;diff=6884&amp;oldid=prev"/>
				<updated>2009-04-13T14:54:35Z</updated>
		
		<summary type="html">&lt;p&gt;Fixed an inline referencing error&lt;/p&gt;

		&lt;table style=&quot;background-color: white; color:black;&quot;&gt;
		&lt;col class='diff-marker' /&gt;
		&lt;col class='diff-content' /&gt;
		&lt;col class='diff-marker' /&gt;
		&lt;col class='diff-content' /&gt;
		&lt;tr valign='top'&gt;
		&lt;td colspan='2' style=&quot;background-color: white; color:black;&quot;&gt;← Older revision&lt;/td&gt;
		&lt;td colspan='2' style=&quot;background-color: white; color:black;&quot;&gt;Revision as of 14:54, 13 April 2009&lt;/td&gt;
		&lt;/tr&gt;
		&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 46:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 46:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;Smartphone users should be diligent in installing patches and keeping their OS software up to date so that their device is protected against attackers trying to take advantage of known problems or vulnerabilities [3].&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;Smartphone users should be diligent in installing patches and keeping their OS software up to date so that their device is protected against attackers trying to take advantage of known problems or vulnerabilities [3].&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;=== Remote locking/backups ===&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;=== Remote locking/backups ===&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;-&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;Since smartphones are vulnerable to getting lost or stolen, businesses should make sure that their smartphones are remotely accessible by the IT staff so that they can be locked and wiped in case such a situation arises [&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;11&lt;/del&gt;]. A tool that enables this over text messaging is preferable as it will allow the device to be secured even if it does not have an active data connection [10]. Data should also be backed up on enterprise servers so that it can be retrieved to a new device in case of one of these situations.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;Since smartphones are vulnerable to getting lost or stolen, businesses should make sure that their smartphones are remotely accessible by the IT staff so that they can be locked and wiped in case such a situation arises [&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;10&lt;/ins&gt;]. A tool that enables this over text messaging is preferable as it will allow the device to be secured even if it does not have an active data connection [10]. Data should also be backed up on enterprise servers so that it can be retrieved to a new device in case of one of these situations.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;=== Physical/Personal security ===&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;=== Physical/Personal security ===&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;Smartphone users should make sure not to leave their devices unattended in public or easily accessible areas in order to prevent attackers from extracting or corrupting information on them [3]. They should also be careful about posting their phone numbers online in order to minimize the number of people who have access to their information and limit risk of attacks and spam [4].&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;Smartphone users should make sure not to leave their devices unattended in public or easily accessible areas in order to prevent attackers from extracting or corrupting information on them [3]. They should also be careful about posting their phone numbers online in order to minimize the number of people who have access to their information and limit risk of attacks and spam [4].&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;!-- diff generator: internal 2026-06-14 08:02:32 --&gt;
&lt;/table&gt;</summary>
		<author><name>Asokanp</name></author>	</entry>

	<entry>
		<id>http://wiki.cas.mcmaster.ca/index.php?title=Security_in_Smartphones&amp;diff=6883&amp;oldid=prev</id>
		<title>Asokanp:&amp;#32;Re-arranged See Also topics</title>
		<link rel="alternate" type="text/html" href="http://wiki.cas.mcmaster.ca/index.php?title=Security_in_Smartphones&amp;diff=6883&amp;oldid=prev"/>
				<updated>2009-04-13T03:55:57Z</updated>
		
		<summary type="html">&lt;p&gt;Re-arranged See Also topics&lt;/p&gt;

		&lt;table style=&quot;background-color: white; color:black;&quot;&gt;
		&lt;col class='diff-marker' /&gt;
		&lt;col class='diff-content' /&gt;
		&lt;col class='diff-marker' /&gt;
		&lt;col class='diff-content' /&gt;
		&lt;tr valign='top'&gt;
		&lt;td colspan='2' style=&quot;background-color: white; color:black;&quot;&gt;← Older revision&lt;/td&gt;
		&lt;td colspan='2' style=&quot;background-color: white; color:black;&quot;&gt;Revision as of 03:55, 13 April 2009&lt;/td&gt;
		&lt;/tr&gt;
		&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 72:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 72:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;10. Temporale, Mike. &amp;quot;Smartphones: productivity booster or security time bomb?&amp;quot; Computing Unplugged Magazine. 5 Apr. 2009 &amp;lt;http://www.computingunplugged.com/issues/issue200805/00002179002&amp;gt;.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;10. Temporale, Mike. &amp;quot;Smartphones: productivity booster or security time bomb?&amp;quot; Computing Unplugged Magazine. 5 Apr. 2009 &amp;lt;http://www.computingunplugged.com/issues/issue200805/00002179002&amp;gt;.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;== See Also ==&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;== See Also ==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;-&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;1. [[&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;3G Communications&lt;/del&gt;]]&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;1. [[&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;Malware&lt;/ins&gt;]]&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;-&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;2. [[&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;Malware&lt;/del&gt;]]&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;2. [[&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;Man in the Middle Attack&lt;/ins&gt;]]&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;-&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;3. [[&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;Man in the Middle Attack&lt;/del&gt;]]&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;3. [[&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;Corporate Security and IT Policies&lt;/ins&gt;]]&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;-&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;4. [[&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;Corporate Security and IT Policies&lt;/del&gt;]]&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;4. [[&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;Data Encryption for Storage Devices&lt;/ins&gt;]]&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;-&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;5. [[&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;Data Encryption for Storage Devices&lt;/del&gt;]]&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;5. [[&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;3G Communications&lt;/ins&gt;]]&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;== External Links ==&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;== External Links ==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;1. [http://research.microsoft.com/en-us/um/people/helenw/papers/smartphone.pdf Smart Phone Attacks and Defenses]&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;1. [http://research.microsoft.com/en-us/um/people/helenw/papers/smartphone.pdf Smart Phone Attacks and Defenses]&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;!-- diff generator: internal 2026-06-14 08:02:32 --&gt;
&lt;/table&gt;</summary>
		<author><name>Asokanp</name></author>	</entry>

	<entry>
		<id>http://wiki.cas.mcmaster.ca/index.php?title=Security_in_Smartphones&amp;diff=6882&amp;oldid=prev</id>
		<title>Asokanp:&amp;#32;Inserted references for intro</title>
		<link rel="alternate" type="text/html" href="http://wiki.cas.mcmaster.ca/index.php?title=Security_in_Smartphones&amp;diff=6882&amp;oldid=prev"/>
				<updated>2009-04-13T03:48:04Z</updated>
		
		<summary type="html">&lt;p&gt;Inserted references for intro&lt;/p&gt;

		&lt;table style=&quot;background-color: white; color:black;&quot;&gt;
		&lt;col class='diff-marker' /&gt;
		&lt;col class='diff-content' /&gt;
		&lt;col class='diff-marker' /&gt;
		&lt;col class='diff-content' /&gt;
		&lt;tr valign='top'&gt;
		&lt;td colspan='2' style=&quot;background-color: white; color:black;&quot;&gt;← Older revision&lt;/td&gt;
		&lt;td colspan='2' style=&quot;background-color: white; color:black;&quot;&gt;Revision as of 03:48, 13 April 2009&lt;/td&gt;
		&lt;/tr&gt;
		&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 1:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 1:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;[[Image:smartphone-security-risk-lg.jpg|frame|Source: http://digital-lifestyles.info/2008/06/03/smartphones-bigger-security-risk-than-lappies/]]&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;[[Image:smartphone-security-risk-lg.jpg|frame|Source: http://digital-lifestyles.info/2008/06/03/smartphones-bigger-security-risk-than-lappies/]]&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;-&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;Security in smartphones is a serious concern today with the increasing number of people who use it for personal and corporate purposes. Previously, smartphones employed a default-deny security model as every feature was built to provide specific services.&amp;nbsp; Now, the devices are built to enable a variety of extraneous services to be run on them. This is equivalent to a default-allow model, which poses a major security risk. These risks are increased due to the fact that most smartphones enable connections to the internet or other networks that may be accessible to outsiders. This connectivity provides a channel for attackers to send or extract information from the devices. Smartphones are much more likely to be lost or stolen than desktops and laptops, which raises the issue of authenticating the identity of the user and being able to remotely lock and wipe the device.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;Security in smartphones is a serious concern today with the increasing number of people who use it for personal and corporate purposes. Previously, smartphones employed a default-deny security model as every feature was built to provide specific services &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;[1]&lt;/ins&gt;.&amp;nbsp; Now, the devices are built to enable a variety of extraneous services to be run on them. This is equivalent to a default-allow model, which poses a major security risk. These risks are increased due to the fact that most smartphones enable connections to the internet or other networks that may be accessible to outsiders &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;[3]&lt;/ins&gt;. This connectivity provides a channel for attackers to send or extract information from the devices. Smartphones are much more likely to be lost or stolen than desktops and laptops, which raises the issue of authenticating the identity of the user and being able to remotely lock and wipe the device.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;== Threats ==&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;== Threats ==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;=== Always-on data connections ===&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;=== Always-on data connections ===&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;!-- diff generator: internal 2026-06-14 08:02:32 --&gt;
&lt;/table&gt;</summary>
		<author><name>Asokanp</name></author>	</entry>

	<entry>
		<id>http://wiki.cas.mcmaster.ca/index.php?title=Security_in_Smartphones&amp;diff=6881&amp;oldid=prev</id>
		<title>Asokanp:&amp;#32;Re-arranged sections</title>
		<link rel="alternate" type="text/html" href="http://wiki.cas.mcmaster.ca/index.php?title=Security_in_Smartphones&amp;diff=6881&amp;oldid=prev"/>
				<updated>2009-04-13T03:46:06Z</updated>
		
		<summary type="html">&lt;p&gt;Re-arranged sections&lt;/p&gt;

		&lt;table style=&quot;background-color: white; color:black;&quot;&gt;
		&lt;col class='diff-marker' /&gt;
		&lt;col class='diff-content' /&gt;
		&lt;col class='diff-marker' /&gt;
		&lt;col class='diff-content' /&gt;
		&lt;tr valign='top'&gt;
		&lt;td colspan='2' style=&quot;background-color: white; color:black;&quot;&gt;← Older revision&lt;/td&gt;
		&lt;td colspan='2' style=&quot;background-color: white; color:black;&quot;&gt;Revision as of 03:46, 13 April 2009&lt;/td&gt;
		&lt;/tr&gt;
		&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 2:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 2:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;Security in smartphones is a serious concern today with the increasing number of people who use it for personal and corporate purposes. Previously, smartphones employed a default-deny security model as every feature was built to provide specific services.&amp;nbsp; Now, the devices are built to enable a variety of extraneous services to be run on them. This is equivalent to a default-allow model, which poses a major security risk. These risks are increased due to the fact that most smartphones enable connections to the internet or other networks that may be accessible to outsiders. This connectivity provides a channel for attackers to send or extract information from the devices. Smartphones are much more likely to be lost or stolen than desktops and laptops, which raises the issue of authenticating the identity of the user and being able to remotely lock and wipe the device.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;Security in smartphones is a serious concern today with the increasing number of people who use it for personal and corporate purposes. Previously, smartphones employed a default-deny security model as every feature was built to provide specific services.&amp;nbsp; Now, the devices are built to enable a variety of extraneous services to be run on them. This is equivalent to a default-allow model, which poses a major security risk. These risks are increased due to the fact that most smartphones enable connections to the internet or other networks that may be accessible to outsiders. This connectivity provides a channel for attackers to send or extract information from the devices. Smartphones are much more likely to be lost or stolen than desktops and laptops, which raises the issue of authenticating the identity of the user and being able to remotely lock and wipe the device.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;== Threats ==&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;== Threats ==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;nbsp;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;=== Always-on data connections ===&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;nbsp;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;While &amp;quot;always-on&amp;quot; data connections provide a great advantage to businesses by enabling real-time communications, it also leaves smartphones vulnerable to viruses and malware [10]. &lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;nbsp;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;=== Mobile malware infections ===&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;nbsp;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;Software in smartphones are newer than their desktop counterparts and hence less robust against attacks [5]. 3G and Wi-Fi connectivity and increased use of e-mail and web services on smartphones in addition to SMS and MMS services have made it easy for mobile malware to propagate over-the-air [7]. It has left smartphones open to man-in-the-middle type of attacks where an attacker could send a spoof message saying a software update is available from a trusted web server and instead send malicious code [5]. The worst threat to smartphone security are worms. They are able to propagate quickly through a large number of systems via malware delivery vectors, such as Bluetooth (Worm.SymbOS.Cabir) and MMS (Worm.SymbOS.Comwar), and disrupt the functioning of mobile networks or transform a mobile network into a widely distributed network controlled by a malicious user [8].&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;nbsp;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;=== Developer-friendly mobile platforms ===&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;nbsp;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;Malware writers are discouraged by diverse, closed developer environments [7]. Open system development platforms, such as was employed by Symbian OS,&amp;nbsp; on the other hand provide them with the tools necessary to create malware, thus leaving smartphones using the OS wide open to malicious attacks [7].&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;=== Tradeoff between security and performance ===&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;=== Tradeoff between security and performance ===&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;GSM and CDMA authentication algorithms are not very effective to start with and many carriers chose not to implement all the available security controls in favour of better performance [1].&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;GSM and CDMA authentication algorithms are not very effective to start with and many carriers chose not to implement all the available security controls in favour of better performance [1].&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 12:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 18:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;Most smartphones do not require authentication when plugged in via USB and provide easy access to whatever data is stored on them [1].&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;Most smartphones do not require authentication when plugged in via USB and provide easy access to whatever data is stored on them [1].&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;-&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&lt;del style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;=== Always-on data connections ===&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;-&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&lt;del style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;While &amp;quot;always-on&amp;quot; data connections provide a great advantage to businesses by enabling real-time communications, it also leaves smartphones vulnerable to viruses and malware [10]. &lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;-&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&lt;del style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;=== Residual data ===&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;-&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&lt;del style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;The power of smartphones to support a wide variety of media and the availability of large capacity removable memory cards have enabled users to carry a large amount of sensitive data on their devices. With new smartphones becoming available on the market every so often, users are frequently upgrading to the latest and greatest device. This means that all the confidential data will need to be deleted from the outdated device. In most devices, when a file is deleted, the markers for the beginning and end of the data on the storage media are removed, with the actual data persisting until it is overwritten [1]. Such data is termed orphaned data and wipes that do not guarantee against this pose a confidentiality threat [1].&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;=== Remote phone monitoring ===&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;=== Remote phone monitoring ===&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;Software, such as FlexiSPY, have made it child's play to remotely monitor smartphones [1, 9]. It takes about 5 minutes to install, after which it collects data on all communications (eg. phone calls, text messages) and sends it to a web account from where it can be viewed conveniently [9]. It also has a remote listening feature that allows you to hear phone calls via a remote microphone [9].&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;Software, such as FlexiSPY, have made it child's play to remotely monitor smartphones [1, 9]. It takes about 5 minutes to install, after which it collects data on all communications (eg. phone calls, text messages) and sends it to a web account from where it can be viewed conveniently [9]. It also has a remote listening feature that allows you to hear phone calls via a remote microphone [9].&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;-&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;=== &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;Mobile malware infections &lt;/del&gt;===&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;=== &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;Residual data &lt;/ins&gt;===&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;-&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;Software in smartphones are newer than their desktop counterparts and hence less robust against attacks [5]. 3G and Wi-Fi connectivity and increased use &lt;/del&gt;of &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;e-mail and web services on &lt;/del&gt;smartphones &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;in addition &lt;/del&gt;to &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;SMS &lt;/del&gt;and &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;MMS services &lt;/del&gt;have &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;made it easy for mobile malware &lt;/del&gt;to &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;propagate over-the-air [7]&lt;/del&gt;. &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;It has left &lt;/del&gt;smartphones &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;open &lt;/del&gt;to &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;man-in-&lt;/del&gt;the&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;-middle type of attacks where an attacker could send a spoof message saying a software update is available from a trusted web server &lt;/del&gt;and &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;instead send malicious code [5]&lt;/del&gt;. &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;The worst threat &lt;/del&gt;to &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;smartphone security are worms&lt;/del&gt;. &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;They are able to propagate quickly through &lt;/del&gt;a &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;large number of systems via malware delivery vectors&lt;/del&gt;, &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;such as Bluetooth (Worm.SymbOS.Cabir) &lt;/del&gt;and &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;MMS (Worm.SymbOS.Comwar), and disrupt &lt;/del&gt;the &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;functioning of mobile networks or transform a mobile network into a widely distributed network controlled by a malicious user [8].&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;The power &lt;/ins&gt;of smartphones to &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;support a wide variety of media &lt;/ins&gt;and &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;the availability of large capacity removable memory cards &lt;/ins&gt;have &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;enabled users &lt;/ins&gt;to &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;carry a large amount of sensitive data on their devices&lt;/ins&gt;. &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;With new &lt;/ins&gt;smartphones &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;becoming available on the market every so often, users are frequently upgrading &lt;/ins&gt;to the &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;latest &lt;/ins&gt;and &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;greatest device&lt;/ins&gt;. &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;This means that all the confidential data will need &lt;/ins&gt;to &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;be deleted from the outdated device&lt;/ins&gt;. &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;In most devices, when &lt;/ins&gt;a &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;file is deleted&lt;/ins&gt;, &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;the markers for the beginning &lt;/ins&gt;and &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;end of &lt;/ins&gt;the &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;data on the storage media &lt;/ins&gt;are &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;removed&lt;/ins&gt;, &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;with the actual data persisting until it is overwritten &lt;/ins&gt;[&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;1&lt;/ins&gt;]. &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;Such data is termed orphaned data and wipes that do not guarantee against this pose a confidentiality threat &lt;/ins&gt;[&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;1&lt;/ins&gt;].&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;-&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;=== Developer-friendly mobile platforms ===&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;-&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;Malware writers &lt;/del&gt;are &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;discouraged by diverse&lt;/del&gt;, &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;closed developer environments &lt;/del&gt;[&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;7&lt;/del&gt;]. &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;Open system development platforms, such as was employed by Symbian OS,&amp;nbsp; on the other hand provide them with the tools necessary to create malware, thus leaving smartphones using the OS wide open to malicious attacks &lt;/del&gt;[&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;7&lt;/del&gt;].&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;== Defense Mechanisms ==&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;== Defense Mechanisms ==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;=== Mix of process and technology ===&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;=== Mix of process and technology ===&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;The best defense mechanism employs a mix of process and technology [1]. It involves securing the device, securing the network and additional security for accessing corporate networks and mail servers [2]. &amp;nbsp;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;The best defense mechanism employs a mix of process and technology [1]. It involves securing the device, securing the network and additional security for accessing corporate networks and mail servers [2]. &amp;nbsp;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;-&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&lt;del style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;=== VPN use ===&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;-&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&lt;del style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;Using VPN is an effective method to overcome any security deficiencies in the cellular connections of smartphones [2].&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;-&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&lt;del style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;=== Neutral service vendor ===&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;-&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&lt;del style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;Corporate users should know where messages and other data reside when sent from a smartphone and ensure that the service provider is a neutral vendor and will not disclose data to competitors [1].&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;=== Start-up passcode ===&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;=== Start-up passcode ===&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;Use devices that allow you to protect your data with passwords and set them to require passwords on start-up and also to lock automatically when not in use for a specified length of time [1]. Select strong passwords that are not easy to guess and do not choose options that allow passwords to be remembered on the device [3].&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;Use devices that allow you to protect your data with passwords and set them to require passwords on start-up and also to lock automatically when not in use for a specified length of time [1]. Select strong passwords that are not easy to guess and do not choose options that allow passwords to be remembered on the device [3].&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;-&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&lt;del style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;=== Whitelisting and Digital Signatures ===&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;-&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&lt;del style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;Users should be taught to be wary of downloadable software since they may contain malicious code [4]. They should be taught only to allow mobile software executables and installers that have digital signatures issued by certification programs like Symbian Signed, Microsoft Mobile2Market and Research In Motion Ltd.'s Controlled APIs for BlackBerry to run on their devices [7]. Create white lists and black lists of approved and restricted mobile software respectively and enforce it either by educating users of the dangers of allowing untrustworthy software to run on their devices or by using software [1, 7, 10].&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;-&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&lt;del style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;=== Proper disposal ===&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;-&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&lt;del style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;Outdated smartphones should be thoroughly wiped before disposal. Tools to ensure that residual data is removed should be used [1]. If the device memory cannot be erased, it should be destroyed in order to protect the confidentiality of any data stored on it [1].&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;=== Configuring access control ===&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;=== Configuring access control ===&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;Take the time to explore the security options on your smartphone and take advantage of them. If your smartphone has encryption software, make use of it to encrypt any information you are storing on your device [3]. This will prevent an attacker from being able to view your data even if he/she has physical access to it [3].&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;Take the time to explore the security options on your smartphone and take advantage of them. If your smartphone has encryption software, make use of it to encrypt any information you are storing on your device [3]. This will prevent an attacker from being able to view your data even if he/she has physical access to it [3].&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;Businesses should ensure that the tools they use to manage their devices supports encryption of the smartphones' onboard storage memory and should employ remote setup and configuration capabilities to safeguard their devices and data [10].&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;Businesses should ensure that the tools they use to manage their devices supports encryption of the smartphones' onboard storage memory and should employ remote setup and configuration capabilities to safeguard their devices and data [10].&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;nbsp;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;=== Whitelisting and digital signatures ===&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;nbsp;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;Users should be taught to be wary of downloadable software since they may contain malicious code [4]. They should be taught only to allow mobile software executables and installers that have digital signatures issued by certification programs like Symbian Signed, Microsoft Mobile2Market and Research In Motion Ltd.'s Controlled APIs for BlackBerry to run on their devices [7]. Create white lists and black lists of approved and restricted mobile software respectively and enforce it either by educating users of the dangers of allowing untrustworthy software to run on their devices or by using software [1, 7, 10].&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;nbsp;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;=== VPN use ===&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;nbsp;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;Using VPN is an effective method to overcome any security deficiencies in the cellular connections of smartphones [2].&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;nbsp;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;=== Neutral service vendor ===&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;nbsp;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;Corporate users should know where messages and other data reside when sent from a smartphone and ensure that the service provider is a neutral vendor and will not disclose data to competitors [1].&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;=== Disable remote connectivity ===&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;=== Disable remote connectivity ===&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;Make sure to disable Bluetooth and any other wireless technologies that enable connections to other devices or computers when not in use to avoid unauthorized access of your device [3].&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;Make sure to disable Bluetooth and any other wireless technologies that enable connections to other devices or computers when not in use to avoid unauthorized access of your device [3].&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 45:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 43:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;Networks should install antivirus software on the internet server through which MMS passes in order to protect their users from worms that propagate via MMS [8].&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;Networks should install antivirus software on the internet server through which MMS passes in order to protect their users from worms that propagate via MMS [8].&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;nbsp;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;=== Keep software up to date ===&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;nbsp;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;Smartphone users should be diligent in installing patches and keeping their OS software up to date so that their device is protected against attackers trying to take advantage of known problems or vulnerabilities [3].&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;=== Remote locking/backups ===&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;=== Remote locking/backups ===&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;Since smartphones are vulnerable to getting lost or stolen, businesses should make sure that their smartphones are remotely accessible by the IT staff so that they can be locked and wiped in case such a situation arises [11]. A tool that enables this over text messaging is preferable as it will allow the device to be secured even if it does not have an active data connection [10]. Data should also be backed up on enterprise servers so that it can be retrieved to a new device in case of one of these situations.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;Since smartphones are vulnerable to getting lost or stolen, businesses should make sure that their smartphones are remotely accessible by the IT staff so that they can be locked and wiped in case such a situation arises [11]. A tool that enables this over text messaging is preferable as it will allow the device to be secured even if it does not have an active data connection [10]. Data should also be backed up on enterprise servers so that it can be retrieved to a new device in case of one of these situations.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;=== Physical/Personal security ===&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;=== Physical/Personal security ===&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;Smartphone users should make sure not to leave their devices unattended in public or easily accessible areas in order to prevent attackers from extracting or corrupting information on them [3]. They should also be careful about posting their phone numbers online in order to minimize the number of people who have access to their information and limit risk of attacks and spam [4].&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;Smartphone users should make sure not to leave their devices unattended in public or easily accessible areas in order to prevent attackers from extracting or corrupting information on them [3]. They should also be careful about posting their phone numbers online in order to minimize the number of people who have access to their information and limit risk of attacks and spam [4].&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;-&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;=== &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;Keep software up to date &lt;/del&gt;===&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;=== &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;Proper disposal &lt;/ins&gt;===&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;-&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;Smartphone users &lt;/del&gt;should be &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;diligent in installing patches and keeping their OS software up &lt;/del&gt;to &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;date so &lt;/del&gt;that &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;their device &lt;/del&gt;is &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;protected against attackers trying &lt;/del&gt;to &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;take advantage &lt;/del&gt;of &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;known problems or vulnerabilities &lt;/del&gt;[&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;3&lt;/del&gt;].&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;Outdated smartphones &lt;/ins&gt;should be &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;thoroughly wiped before disposal. Tools &lt;/ins&gt;to &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;ensure &lt;/ins&gt;that &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;residual data &lt;/ins&gt;is &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;removed should be used [1]. If the device memory cannot be erased, it should be destroyed in order &lt;/ins&gt;to &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;protect the confidentiality &lt;/ins&gt;of &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;any data stored on it &lt;/ins&gt;[&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;1&lt;/ins&gt;].&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;== References ==&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;== References ==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;1. Espenschied, Jon. &amp;quot;Ten dangerous claims about smart phone security.&amp;quot; Computerworld. 27 Mar. 2007. 5 Apr. 2009 &amp;lt;http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9014118&amp;gt;.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;1. Espenschied, Jon. &amp;quot;Ten dangerous claims about smart phone security.&amp;quot; Computerworld. 27 Mar. 2007. 5 Apr. 2009 &amp;lt;http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9014118&amp;gt;.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;!-- diff generator: internal 2026-06-14 08:02:32 --&gt;
&lt;/table&gt;</summary>
		<author><name>Asokanp</name></author>	</entry>

