11 ms·
NSA Mobile Device Best Practices
- bottled_poe 5y agoKinda surprised biometrics are recommended. I’ve always thought passcodes were more secure - particularly as the data is not easily accessible by interrogators for example.
- WrtCdEvrydy 5y agoBiometrics are recommended if the data is not classified. Remember this is for people working on sensitive information. This is what the NSA's original mission was, to keep people safe and strengthen the American defense posture from the single person up to the entire infrastructure that we rely on day-to-day. The mission has shifted to offense after 9/11 so there's conflicting goals here (can't patch something we're using against the bad guys)
- nojito 5y agoNSA was always about offense and is strictly for international offense. The only shift after 9/11 was getting the three agencies to actually talk to each other.
- vajrabum 5y agoIt says on their mission statement that they do SIGINT and information assurance (i.e. IT security) and there is plenty of public evidence that they do both. Plus they've been deeply involved with designing cryptographic protocols and equipment for the US govt for a very long time which is part of SIGINT but it's not the offensive part. https://www.nsa.gov/about/mission-values/ https://www.nsa.gov/about/mission-values/
- AlexCoventry 5y agoThe NSA was created in a reorganization of US SIGINT/COMINT services, because SIGINT/COMINT during the Korean War had been unsatisfactory. Its primary mandate has always been COMINT. https://www.nsa.gov/about/cryptologic-heritage/historical-figures-publications/publications/korean-war/koreanwar-sigint-bkg/#14 https://www.nsa.gov/about/cryptologic-heritage/historical-fi... > The Brownell Committee suggested that the creation of AFSA could be seen as a "step backward," and recommended that the power of the director, AFSA, to centralize COMINT be increased. > In October, Harry Truman authorized a reorganization and renaming of AFSA, and in November, the secretary of defense authorized the replacement of AFSA by the National Security Agency.
- wil421 5y agoNo it wasn't. Take a look at the movie Enemy of the State that was released in 1998, 3 years before 9/11. In the movie the NSA is monitoring all calls, has NRO satellites that tail them, and a bunch of other Tinfoil hat stuff that was confirmed by the Snowden leaks a decade later. The biggest fiction in the movie was their ability to connect the dots and do stuff in real time as depicted. The NSA director even said they were appalled how the agents were portrayed and went on PR campaigns to defend them selves. They were always spying but not ruthless killers as depicted in the movie. https://en.wikipedia.org/wiki/Enemy_of_the_State_(film) https://en.wikipedia.org/wiki/Enemy_of_the_State_(film)
- hugh-avherald 5y agoIt explicitly says 'minimal sensitivity'. That basically means the threat vector is "I left it at the cafe."
- CompuHacker 5y agoIf every NSA employee has a perfect security posture, any adversary is going to have to take more extreme measures to get information. Better to let them have the occasional un-updated iPhone.
- imwillofficial 5y agoNo it’s not. The best way is to break them with your h yielding security posture.
- twox2 5y agoI went to a legal presentation at Defcon a couple of years back where they said that the government needs a court order / warrant in order to force you to tell them your password, but if you're using biometrics, they can just force you to touch your finger to your phone or scan your eyes without it. It's some legal loophole.... so in that respect I think passwords ARE more secure.
- ne9xt 5y agoSmart, but there is a way to force your (faceid/touchid) iphone to require your password by holding the power button to get to the "slide to power off" screen.
- greggturkington 5y agoA defendant was compelled to use their face to unlock their computer in a recent case (2021) [1]. The reasoning given by an analyst: > requiring a defendant to expose his face to unlock a computer can be lawful, and is not far removed from other procedures that are now routinely approved by courts, with proper justification: standing in a lineup, submitting a handwriting or voice exemplar, or submitting a blood or DNA sample Contrasting the logic used by a judge in a similar case in (2019) [2]: > If a person cannot be compelled to provide a passcode because it is a testimonial communication, a person cannot be compelled to provide one’s finger, thumb, iris, face, or other biometric feature to unlock that same device Ars has a summary of more cases [3]. It looks like in several instances state courts allowed the devices to be unlocked using biometrics, but the rulings were reversed at the federal level. In many cases a warrant was required. 1. https://archive.is/i2Bx9 https://archive.is/i2Bx9 2. https://archive.is/px2Qz https://archive.is/px2Qz 3. https://arstechnica.com/tech-policy/2020/06/indiana-supreme-court-its-unconstitutional-to-force-phone-unlocking/ https://arstechnica.com/tech-policy/2020/06/indiana-supreme-...
- panzagl 5y agoPresumably NSA employees are not using their phones for illegal activities, so they should not be in a situation where a court will order them to unlock their phone.
- 2OEH8eoCRo0 5y ago
- sandworm101 5y ago>> biometrics are recommended. Maybe by the NSA. Any defense attorney will tell you otherwise. If your fingerprint unlocks your phone then the cops will hold your finger to the phone. If you face unlocks your phone then they will do that too. A pin/password means you retain at least some control. If this was an Archer episode, I'd point out that while dead people cannot divulge pins/passwords their fingerprints still work.
- derefr 5y agoI believe they're recommending setting your phone up in a "lock immediately upon sleep; require password after five minutes" configuration. Passwords are better than biometrics for security; but between password validations, presuming some level of convenience is needed, using biometrics to check that the same person is still there is better than "just stay unlocked for a few minutes even after being put to sleep". It's like HTTP Basic Auth (sending credentials with every request), vs. logging in, receiving a short-lived session cookie, and then sending that session cookie with your requests for a few minutes.
- bradknowles 5y agoPIN/password to unlock the device, plus biometrics to access certain sensitive data or applications on the device. It’s not perfect, but I think it strikes the best balance.
- nonameiguess 5y agoIt says to protect your lock screen with a password, and additionally protect minimally sensitive data on an already-unlocked device with biometrics for convenience.
- ARandomerDude 5y ago> Power the device off and on weekly. Thoughts, HN? I can see how this might be good for performance, but how is it good for security?
- timpattinson 5y agoIt's possible to have a security exploit which can compromise a running device, but is not able to make itself permanent across restarts (e.g. changes programs in RAM but not in flash) That's my best guess.
- gruez 5y agoConcrete example: all the recent ios jailbreaks (aka sandbox escape and/or EoP exploits) are tethered, which means they're undone/reset after a reboot.
- deleted 5y ago[deleted]
- alex_anglin 5y agoMakes it harder to maintain persistence on the device, I believe. Whether it solves the problem in question is another matter.
- a5withtrrs 5y agoRunning your malicious actions without writing to disk is a very effective way of bypassing a lot of security and forensics technologies. As soon as you make changes have persistence you have proof and some operators are not oaky with that.
- whoisjohnkid 5y agoa lot of exploits deliberately avoid persistence as an extra layer of protection from detection. Since most folks rarely restart their phones these bugs can live on your phone until a restart. So by restarting your phone on a weekly basis you are potentially wiping out memory only infections.
- jeffbee 5y agoSurprised they go with "DO NOT" connect to wi-fi, but just "avoid" attaching untrusted hardware devices. That seems backwards.
- jvanderbot 5y ago"Avoid jumping off cliffs" does not mean that occasionally it's ok to jump off cliffs. Is the surgeon general's advice "Pregnant women should avoid alcohol" unclear?
- jeffbee 5y agoThe U.S. Surgeon General's mandatory warning for alcohol states "women should not drink alcoholic beverages during pregnancy because of the risk of birth defects." It does not use the word "avoid".
- jvanderbot 5y agoWell I asked for that. Here's a long list of scholarly articles that use "Avoid Alcahol" when stating or re-stating health recommendations from various countries. https://scholar.google.com/scholar?hl=en&as_sdt=0%2C5&q=women+avoid+alcahol+pregnancy https://scholar.google.com/scholar?hl=en&as_sdt=0%2C5&q=wome...
- shapefrog 5y agoThe Surgeon General avoids using the word "avoid" on their warnings.
- bamboo2 5y agoProblem with this: keep your phone with you always conflicts with don’t have secure conversations within mic range of your phone. You can’t do both of these. But otherwise this is great and I would probably add “reset and replace devices often.”
- sandworm101 5y agoThe rooms where you can have secure conversations will have a bank of tiny lockers outside the door for phones/keys.
- wycy 5y agoUsually, but not always. I've been to rooms that don't have this and there's just a pile of phones sitting outside.
- godelski 5y agoAre lockers really that secure? Similar documents advise against leaving laptops in hotel rooms or cars, even if locked, because they are easy to get into. I imagine a locker is not hard to break into. Small locks can be picked in a second or two by people with practice, which does not look different than retrieving your own phone.
- sandworm101 5y agoThe lockers are just so you have a place to put your phone. They are not secure in any way. Using a keyed locker just ensures you don't pick up someone else's phone by accident after the meeting. Remember that secure rooms live inside secure buildings, usually inside a secure facility with a fence and guy standing at the gate. And the guy has a gun.
- dragonwriter 5y ago> Using a keyed locker just ensures you don't pick up someone else's phone by accident after the meeting It also prevents casual but intentional unauthorized access, just not a determined attacker. As you note, there are other layers of security for that.
- ajdecon 5y agoI’ve seen most of these recommendations before, but the “mic-drowning case” to muffle room audio is new to me. Certainly makes sense, but are there any common commercial phone cases that advertise this feature?
- spacephysics 5y agoI would also like to know. I’ve only found phone cases that hide the camera via a slide or flap. Ideally I’d like both the mic and camera cover
- cybergek 5y agohttps://www.vysk.com/technology/qs1 https://www.vysk.com/technology/qs1
- barcoder 5y agoHaving recently switched to iPhone I have been very surprised at finding my wifi and Bluetooth automatically turning on. There could be a better way, but I had to create a shortcut to disable connectivity until I manually turn it back on
- markn951 5y agoThey're not automatically turning on if you're "turning them off" from Control Center. Those buttons just temporarily disable them (and state that clearly when you do so). The only way to actually turn off Wifi and Bluetooth is to go into Settings and turn them off there.
- MAGZine 5y ago"Clearly" it's not as clear as you think it is. On android, if I turn bluetooth off from the quick access menu, it stays off--which is what I expect.
- marcellus23 5y agoCan't get much clearer than text that says "Disconnecting nearby wi-fi networks until tomorrow."
- bkallus 5y agoBut that same button used to be a permananent toggle, and now there is no way to restore the (better) old behavior. Another instance of Apple thinking they know better than their users.
- marcellus23 5y agoYou are not everyone. Just because you think it's better doesn't mean it actually is. Most of the time when I want to disconnect from Wifi, it's a temporary measure because the network I'm connected to is slow or dead. I imagine it's the same for many others. Apple is notoriously allergic to putting toggles for every little thing, and that shouldn't be a surprise to software developers. We all know every user-configurable setting increases complexity.
- aasasd 5y agoSorta have to wonder if it's safe to open that pdf locally—the site doesn't quite work on the phone.
- sandworm101 5y agoDefense links for anyone on government systems that might not have easy access to documentcloud. https://media.defense.gov/2020/Jul/28/2002465830/-1/-1/0/MOBILE_DEVICE_BEST_PRACTICES_FINAL_V3%20-%20COPY.PDF https://media.defense.gov/2020/Jul/28/2002465830/-1/-1/0/MOB... Corresponding NSA document for OCONUS (travel outside continental US) https://home.army.mil/stewart/index.php/download_file/view/12526/2822 https://home.army.mil/stewart/index.php/download_file/view/1...
- derefr 5y ago> Do not charge your devices by connecting them to charging stations, computers, televisions, DVRs, etc. Use only issued chargers or those acquired with sufficient OPSEC. I'm surprised the government/military does not issue its employees USB condoms to obviate this worry.
- dsr_ 5y agoSame reason people treat internal email as insecure: you get used to the convenience, then one day you reply-all to an outside address. In this case, you get used to using public chargers with a condom and one day you forget the condom.
- derefr 5y agoThe parallels don’t quite line up, as in this case, they could be issued official cables that have a condom integrated/soldered on. Maybe in a special colour to remind you that these are “secure” cables. It’d be like your internal corporate email client not even letting you send mail out to external addresses. Sure, you could intentionally set up IMAP with an untrusted client and then send such messages (and likewise, you could intentionally bring some other insecure cable with you); but someone doing that would likely have a visible pattern of doing that, long before they actually get spearphished—one that could be noticed and reprimanded. Of course, ideally, you’d make using the insecure clients / cables impossible, by giving the “other end” a proprietary shape that only the secure client/cable fits with. (Maybe they could design a little adapter that could be semi-permanently socketed into a phone’s USB-C/Lightning port, turning it into something proprietary that only their secure cable has the male end for? I’m assuming here they still need a data connection — with a different special cable — for device maintenance; otherwise you could just make that little socketed-on adapter be the condom.)
- baybal2 5y agoOne problem with both Android, and Ios: impossible to disable automatic previews Send yourself a link by SMS, or some popular messenger like Whatsapp. Your phone will automatically make you a browser page preview, and in the process run every browser exploit available. Google added an extremely well hidden option to disable it it Messages few versions ago. Since there is no way to be sure Google does not remove it, and add some kind of another autoplay like feature in the future, I just replaced the SMS app altogether to one which does not peek into my conversations https://play.google.com/store/apps/details?id=com.simplemobiletools.smsmessenger https://play.google.com/store/apps/details?id=com.simplemobi... (google straight tells they can get a copy of your SMSes as per their disclaimer if you use Google Messages for "improving service")
- jvanderbot 5y agoSounds like we need a more secure messenger app?
- baybal2 5y agoWe need, but making a default SMS app straight sending your texts to Google.com by default, and making it very hard to disable for a technically illiterate user is beyond unethical.
- Hackbraten 5y agoNo idea how Android does it but Apple has recently moved message parsing and preview generation into a heavily sandboxed process.
- johnchristopher 5y agoWell, considering all those restrictions and how it's still not secure enough anyway how long before the recommendation will be "Don't use your smartphone. Use the landline phone in your office" ?
- necheffa 5y agoBecause land lines are super secure and no one has found out how to tap the line from a switching station?
- johnchristopher 5y agoEven if I take your comment at face value a landline phone in an NSA office is most likely still more secure than any smartphones if I am to believe that NSO/Pegasus thing.
- duxup 5y agoI worked for a company where we sent folks onsite to very secure sites. Nothing electronic EVER arrived at the facility or left with you when you left the facility that wasn't accounted for. Nothing that ever entered that wasn't needed, NO phones allowed ever. You and your vehicle were searched on arrival and exit. We went through a lot of laptops... With the complexity of hardware / software involved, I suspect that's the only way.
- mikewarot 5y agoWhy do people need smart phones, really? The only time they come in handy is for driving directions. It turns out my Samsung candy bar phone with no camera, GPS and internet leads the way in security.
- CabSauce 5y agoWhy stop there? You can't get hacked if you don't have electricity.
- shapefrog 5y agoWhy do people need electricity, really? The only time they come in handy is for charging your phone so you can get driving directions, or hacked.
- lovelettr 5y agoYou must work at my company’s cyber security team. They’re convinced that the safest stuff is when that stuff is never allowed to exist in the first place. Which is probably true but in my opinion misses the point.
- vajrabum 5y agoWhy do people need computers, really? A smart phone is a small portable computer with a phone built in. Maps is one of the types of apps that most people use but it's not the only one. Email, social media, text messaging, note taking, audio and video recording, a camera, a compass, pedometer, access to cloud file storage, reading apps like nook or kindle are a few of the apps that I use regularly on my phone in places where a laptop or even a tablet wouldn't be inconvenient or impossible.
- throwawayboise 5y agoI've given some serious thought to going back to a dumb phone and a separate navigation device in the car, but I don't know if a stand-alone comsumer GPS with maps and turn-by-turn navigation is something you can even buy anymore, since 99% of people use their phones for that now.
- maerF0x0 5y agoI'm curious if anyone has any leads/stories on compromised 3rd party devices? Would love to learn more about detecting these things. Like say a USB charging brick that also attempts malware or a keyboard etc?
- Arrath 5y agoIs there much that can be done to detect them? I know they're for sale for pen testing and what not, but I've never seen much in the realm of preventing or protecting against them.
- maerF0x0 5y agoI've thought about somehow creating a raspberry pi that sits between usb devices and snitches on data transfer that is not expected? It could be really hard to do, and probably easy for a device to mask (only attempt attacks when other file operations are happening)
- motohagiography 5y agoAnnoyingly, putting your device in a shielded evidence bag without turning it off can cause its various radios to franticly seek connections and even amplify their signals until they completely empty your battery. Useful to have if you are curious about protests or concerts and other gatherings of people with a significant criminal element who could get your IMEI stingray-ed and then palantir-ed.
- Arrath 5y agoI usually change my phone to airplane mode for long drives or hikes through signal-less wilderness, otherwise they'll thrash around searching frantically for signal until they drain the battery outrageously fast. It's really quite annoying.
- nimbius 5y ago>Use strong lock-screen pins/passwords: a 6-digit PIN is sufficient if the device wipes itself after 10 incorrect password attempts. im calling BS. NSO and others have demonstrated repeatedly they can (and do) bruteforce these pin based logins quickly and efficiently without triggering the wipe using sidechannel attacks on running services and software over the air and through USB. use a PASSPHRASE. >Consider using Biometrics (e.g., fingerprint, face) authentication for convenience to protect data of minimal sensitivity remember: the fifth amendment does not cover biometrics . if a DUI case can forcibly extract your blood, then you can and will be required to present your face to unlock a laptop. use passphrases. >DO NOT jailbreak or root the device. this often allows people to remove pre-installed spyware just as easily as it can be installed.
- spurgu 5y ago> remember: the fifth amendment does not cover biometrics . if a DUI case can forcibly extract your blood, then you can and will be required to present your face to unlock a laptop. On the iPhone theres a neat trick: If you seem to be in a situation where you might be forced to hand over your phone (and unlock it with bio), hold down the power button for a second or two (secretly/inconspicuously in your pocket or wherever your phone is). This will disable fingerprint unlocking and you will be forced to enter PIN. Doesn't seem to work on Android (11 at least) though.
- hiq 5y ago> Doesn't seem to work on Android (11 at least) though. I'd hold the power button a bit longer and turn off the device altogether. Granted, not as convenient.
- spurgu 5y agoHmm okay yeah, that works. Had to hold it for 5+ seconds and then it rebooted.
- dragonwriter 5y agoAndroid doesn't have a stealthy way to do it without powering down, but you can either activate lockdown mode, reboot, or power down and the next access will require PIN, not biometrics.