News
Sophos received top marks in the latest report from AV-Comparatives, a leading international testing lab. The report, titled “Impact of Anti-Virus Software on System Performance,” evaluated twenty one of the world’s leading security products on a PC running under Windows 7.
The testing lab prepared a total of 545 infection scenarios, and Sophos’ antivirus offering tied for the highest score among the products reviewed. It also received an “Advanced +” award, based on the lab’s assessment of the overall results.
“We value the work of independent testing labs like AV-Comparatives, as they help vendors like Sophos to strengthen our offerings, while providing consumers and businesses great insight so that they can make better informed decisions,” said Mark Harris, vice president, engineering, Sophos. “This latest recognition validates the great work of our team, which is committed to developing complete security solutions to combat advanced threats.”
In related testing news, Virus Bulletin, another leading independent lab awarded Sophos with a VBSpam award for its comparative anti-spam testing. This marks the 20th time that Sophos has received this honor for its Sophos Email Appliance. Additionally, Sophos recently received a VB100 award for Sophos Endpoint Security and Control as part of Virus Bulletin’s comparative review on Windows XP Professional SP3.
Click here to see the original article.
“The new Sophos SG Series appliances are the fastest UTM and Next-Gen Firewall devices we’ve ever produced,” said Guenter Junk, Senior Vice President and General Manager, Network Security Group, Sophos. “They run our latest operating system, version 9.2, and are optimized to get the most out of latest performance innovations from Intel to ensure our customers and partners get an unrivalled performance and protection combination.”
The new SG Series includes models to meet the requirements of small offices to large, distributed enterprises. These 1U appliances are available today in the mid-range 200, 300 and 400 models. They all deliver over 10 Gbit/sec firewall throughput to easily handle the demands of multi-layered protection. The SG Series is the 6th generation of Sophos security gateways built on an Intel® architecture, to enable Sophos customers to quickly benefit from the frequent performance and protection enhancements. They utilize Intel® technologies including high-speed LAN interfaces, high volume Solid State Drives and AES-NI acceleration.
“By using Intel® Architecture, Sophos has been able to use the performance gains we’ve been able to deliver with the 4th Generation Intel Core processors which delivers improved software processing architecture,” said Bob Ghaffari, Director, Communications and Storage Infrastructure Division, Intel. “Sophos has been able to see dramatic performance improvements by unlocking Intel’s core processor capabilities to make fast, intelligent decisions.”
The SG Series run the latest Sophos UTM 9.2 operating system which features over 150 enhancements including new Advanced Threat Protection and SPX Email Encryption functionality. Designed to run on an Intel architecture, version 9.2 can also be deployed on Intel compatible servers as virtual appliances and in the cloud using Amazon Web Services.

Bruce Kneece, Chief Technology Officer at Convergent Information Security Solutions, said, “Our team was heavily involved in the UTM 9.2 beta program. From the outset we liked what we saw – added performance and simplicity across the board. Version 9.2 running on the SG Series hardware is a true winner. It’s easy for us to recommend it to our customers.”

Additional information on all of the features in Sophos SG Series appliances and Sophos network security solutions is available at: www.sophos.com/accelerated.
This isn’t entirely surprising as the FBI had issued a warning on Christmas Eve to media organizations about a new wave of phishing attacks associated with the infamous SEA. Skype has more than three million followers on Twitter, which indicates that, had the attackers wanted to send out malicious links or other dangerous content, this could have been a whole lot worse.
What I would like to know is why on earth a company social media profile with over three million followers would not be using two-factor authentication. Earlier this year Twitter rolled out an improved two-factor solution seemingly in response to previous attacks by the SEA. WordPress offers two-factor authentication and Facebook has supported two-factor authentication for a couple of years now, all in an attempt to prevent this exact type of attack.

Microsoft, would you care to explain why you apparently are not using it? We believe it is the responsibility of organizations with a large number of followers to do whatever they can to secure their profiles. We suppose this can be a lesson to the rest of us. Take advantage of the safety net of two-factor authentication whenever possible. While it may be less than perfect, so are you.
You can read the original article here.
Jan
Keenan brings more than 20 years of sales and sales management experience to Sophos, including 13 years with SonicWALL, where he most recently built a new sales organization for mid-market accounts and developed the division’s channel strategy. As vice president of North America Sales, Keenan grew the business by fostering key relationships with the company’s channel partners.
“John Keenan is widely respected by the security channel, and I am thrilled to welcome him to Sophos. He brings a proven track record of success in the security space and has winning experience in leading channel and sales teams,” said Michael Valentine, senior vice president of sales for Sophos. “Every day, the Sophos team is working hard to be the preferred vendor in security for the channel and customers. Our products, our people and our partner programs continue to gain industry accolades. In bringing John aboard, we have an ideal leader for continued growth in our North American business.”
“I am excited to join Sophos; the company’s value proposition of ‘security made simple’ clearly resonates with customers and the channel,” said Keenan. “The company’s relentless focus on empowering the channel, a best-in-class portfolio of endpoint, mobile, server and network solutions, and the opportunity to contribute to Mike Valentine’s winning team made my decision to join Sophos an easy one.”
McAfee may be big, but that doesn’t mean better. When you look at independent tests and evaluations, Sophos comes out on top. Get our Endpoint Buyers Guide to see all the research that will help you evaluate the top endpoint protection products.
This buyers guide shows you how we match up against McAfee and other vendors in performance, protection, ease of management and customer support.
Better performance
Your endpoint protection can’t come at the expense of user productivity.
In a recent AV-Comparatives performance test, Sophos Endpoint Protection had the best (lowest) system impact score, meaning our software had the least amount of impact on a computer’s speed in performing tasks like launching programs and files.
As you can see in the chart below, we have the industry’s lowest impact on performance, while McAfee scored at the bottom of the scale. In this comparison, a lower score means better performance.
Sophos gives you protection that won’t slow you down.

Better protection
When you choose Sophos, you’re choosing better protection from malware.
As you can see in Info-Tech’s latest Vendor Landscape: Endpoint Anti-Malware report, Info-Tech placed us far higher and to the right of McAfee, meaning we continue to beat McAfee with better protection against malware. This also proves how our strategy of complete security, our strong market presence, and our reputation as trendsetters in the industry leaves McAfee far behind.
Info-Tech Research Group has ranked us Champions for the last three years, recognizing our superior products based on features, affordability, usability, and architecture. In addition, Info-Tech evaluates vendors for viability, strategy, reach and channel.

Fast on Macs
Here’s what a user from LowEndMac.com has to say about Sophos Endpoint Antivirus:
“With some antivirus suites for Windows you can really feel a difference in computer performance, sucking system resources and some even bring them down to a crawl. How does Sophos compare? I have been running Sophos on my 2009 MacBook running Mavericks for just over a week, and I haven’t noticed any performance drop since it has been installed.”
Read more about this review on our Sophos Blog.
Take a look at how we rank against other security vendors. Click the button below to download the Endpoint Buyers Guide.
Give Sophos a try
The best way to see how we perform is to give us a try. It’s easy to take a free trial of our Endpoint Antivirus. You can choose either on-premise or cloud deployment, and start your trial today.
You can read the original article, here.
Jan
The new version includes the following improvements.
- New wizards for step-by-step installation and uninstallation of one or multiple centralized scanners. The install wizard also supports assigning static IP addresses to the scanners.
- The ability for the centralized scanners to receive product upgrades automatically from Sophos, eliminating the need to manually install new product versions.
- More selective email alerts, so administrators can focus on the most critical information.
- A new command-line tool to generate compliance reports showing which virtual guests are protected by which centralized scanners.
If you are currently using Sophos Antivirus for vShield, you may download the new version from the MySophos download page. If you haven’t yet experienced the speed and convenience of agentless scanning for your VMware environment, download the free 30 day trial today.
You can read the original article here.
Jan
“This certification is a critical step toward the future development of LogPoint. It will enable us to pursue significant opportunities with government authorities, in the security and intelligence sector as well as with major corporations globally,” says Jesper Zerlang, CEO of LogPoint. “We are extremely excited about the partnership with Boeing that will elevate the LogPoint platform to the Tier 1 in the market and place us among the best enterprise SIEM security solutions”
Boeing will assist LogPoint prepare the SIEM platform for the Common Criteria for Information Technology Security Evaluation, with the goal of obtaining Evaluation Assurance Level 3 certification before mid-2014. This certification is often a requirement for cybersecurity contracts in NATO countries and throughout the world. Obtaining it will make LogPoint the only Danish cybersecurity company to meet the standard – and one of few globally.
“We are experiencing a dramatically increasing demand for improved network security as the number of successful network attacks globally are sadly rising. An effective SIEM-solution is one of the cornerstones of efficient enterprise network security, not only to improve security monitoring and early breach detection, but also to answer an increasing demand for regulatory compliance in many countries around the world”, says Jesper Zerlang.
The LogPoint SIEM-platform are currently deployed with more than 250 organizations in Europe, including large- and midsized enterprises in all industry sectors as well as public authorities ranging from municipalities to government authorities. LogPoint is present with offices in the Scandinavian countries as well as Germany and the UK and are currently expanding to a number of other European markets. LogPoint is partner centric and deploy its solution through a network of certified partners, ISP’s and system integrators throughout Europe.
LogPoint is a European, Copenhagen-based IT security company that delivers IT security SIEM solutions for enterprise networks. The LogPoint technology is an advanced Security Information and Event Management (SIEM) platform that provides real-time monitoring and incident management for security-related events from network, security devices, systems and applications as well as log management, analytics and compliance reporting.
You can read the original article here.
Jan
She writes: “I personally notified the very first bounty recipient via email today that his submission for the Internet Explorer 11 Preview Bug Bounty is confirmed and validated. (Translation: He’s getting paid.)“.
She hasn’t yet named names or put a price tag on the first recipient. In fact, there are already multiple researchers who’ll be receiving bounty payouts. MSRC plans to hook up those researchers who want to be publicly recognized for their contributions on an acknowledgement page on its bounty web site. “Stay tuned, as it will come soon“, Moussouris says.
What Microsoft can share at this point are these two key results:
- They’re getting more submissions, earlier. Microsoft has received more vulnerability reports in the first two weeks of its bounty programs than it typically would in an average month. It shows that the strategy for getting more vulnerability reports earlier in the release cycle is working, it says.
- They’re attracting new researchers. Researchers who’ve rarely, or even never, reported directly to Microsoft are now choosing to talk directly to the company. Microsoft interprets that as proof that its strategy to hear from people it usually doesn’t hear from is bearing fruit.
As Moussouris explains it, Microsoft was canny in how it chose to approach the vulnerability market. There’s the black market, where zero-day bugs fetch the highest prices. Then there’s the gray market, where bug-hunting mercenaries make a mint selling information about exploit techniques and unpatched vulnerabilities to corporations and nation states. Microsoft didn’t go there. Instead, it focused on the white market: the place where buyers are after vulnerability information for defensive use, whether it’s vendors themselves (via bounty programs) or a broker who uses the vulnerabilities for their own protection services or threat reports. Moussouris says that three years ago, white-hat bug hunters were passing up cash on the white market and were instead mostly coming to Microsoft directly. That changed over the past few years. Microsoft has witnessed researchers increasingly holding bugs back to see what the going rate might reach on the various markets, typically after Microsoft has released code to manufacturing. The way Microsoft figures it, it’s identified a gap in the market that its new bounty program is filling: namely, in the pre-release, or beta, period.
Moussouris writes: “It’s not about offering the most money, but rather about putting attractive bounties out at times where there are few buyers (if any)… Trying to be the highest bidder is a checkers move, and we’re playing chess“.
There is data out there that bolster Moussouris’ contention that strategically structured, well-timed bounty programs are a good investment. A study recently released by the University of California, Berkeley reports that paying bounties to independent security researchers is a better investment than hiring employees to do it. Piggy and mouse. Image from ShutterstockFor example, Google’s paid out about $580,000 over three years for 501 Chrome bugs, and Firefox has paid out about $570,000 over the same period for 190 bugs. Compare that with just one full-time salaried security researcher digging through code, at, say, $100,000 per year, and the savings can be huge.
You can read the original article, here.
Saving your data and increasing your bottom line just got easier. Purchase a WD Arkeia backup appliance at a reduced price and get all licenses for popular software agents at no additional cost. The WD Arkeia bundle comes standard with software, hardware and one year of maintenance at up to 50% less than the competition.
Here’s what’s included:
- Software, hardware and one year of maintenance
- Virtualization agents: VMware and MS Hyper-V
- Microsoft hot-backup agents: MS SQL, Exchange, Active Directory & SharePoint
- Agents for MySQL, PostgreSQL and Oracle
- Agents for Novell GroupWise and eDirectory / NetIQ
- Hybrid-cloud backup replication
- End-to-End
- Encryption
- Bare metal restore for Linux and Windows
- Remote Storage Option and Shared Storage Option
WD Arkeia offers six backup appliance models including both desktop and rackmount options. See our full backup appliance range here.

This limited time offer ends September 21, 2014. Find more at http://info.arkeia.com/emea/bundle
Jan
Info-Tech examined ADC vendors that are solving the problems of server downtime due to increased web traffic and preventing malicious attacks against corporate systems. Array Networks’ APV line of application delivery controllers deliver a seamless end-user experience while simultaneously preventing attacks and data leakage.
Array’s feature-rich ADC products, industry-leading price and performance and unmatched reputation for customer service and support make them an unbeatable value to businesses.
Array Networks helps enterprises meet the challenges of delivering applications in the dynamic network environments of modern enterprises. Array has over 5,000 worldwide customers including enterprises, service providers, government and vertical organizations in healthcare, finance, insurance and education. Organizations look to Array to cost-effectively scale the performance, availability and security of applications and data in dynamic network, cloud and mobile environments.
“It’s an honor to be recognized as an Innovator in the ADC market,” said Michael Zhao, President and CEO of Array Networks. “Array is improving enterprise security and traffic management and we will continue to develop application delivery networking solutions that meet customer requirements.
You can read the original article here.
Once these are exceeded interSeptor will provide an alert. For other sensors (security, water, power, smoke and dry contact), interSeptor will provide an alert as soon as the sensor switches to an alarm condition.
There are currently five different optional sensors : smoke, water leak, power, security and dry contact sensors.
The interSeptor water detector uses a specially designed cable to detect the presence of moisture at any point along the length of the cable. The water detection unit will sound an audible alarm upon detection and also sends a signal to the interSeptor to start the alarm process. Want an example? You arrive at work on Monday to discover an inch of water across a critical floor space. Of course you are able to quickly install a leak detection system to protect against future instances of this, but what if a system had been in place already? Could you have saved time and money? Could critical equipment be saved? Could staff have spent more time on more important matters?
The answer to these questions is, of course, YES! There is an easy-to -install, leak detection system with:
- Up to 30m leak detection cable
- Hassle-free installation
- Remote Web Access
- Free technical assistance via phone and email
- 60-day money-back guarantee
- 2-year swap out warranty
There’s definitely an update coming next Tuesday, 18 June 2013, and you might as well get ready for it now if you haven’t already. The details of what will be fixed aren’t a matter of public record yet, so we can’t spell them out for you in detail. Nevertheless, Oracle has published a very brief pre-announcement to remind us of the importance of this month’s fixes. The good news is that lots of security vulnerabilities have been repaired – 40 in total, of which all but three are RCEs, or remote code execution holes.
That’s where untrusted content sent over the network might be able to trick Java into performing operations that really ought to be limited to already-installed, trusted code. In short, an RCE means that you could get infected by malware simply by looking around online, without explicitly downloading, authorising or even noticing the malware being installed.

There are two handy ways to reduce this RCE risk:
· Apply Oracle’s patches as soon as practicable. You can turn on fully-automatic updating if you like.
· Turn off Java in your browser, so that web-based Java applets can’t run at all.
Click here to see the original article.
Jan
This data can include sensitive material such as the server’s private key, but is not limited to that, any data that is in memory on the server is at risk including sensitive customer data as well. This is not limited to web servers, if you use a SSL based VPN that leverages OpenSSL you may also be at risk. Access to this type of sensitive data creates a serious vulnerability because attackers can use it to decrypt past communications (when Perfect Forward Secrecy (PFS) is not configured), steal critical data and in the case of a private key compromise, enable the attacker to impersonate the associated server.
Resolution and Recommendations
We strongly recommend anyone using OpenSSL to:
- Verify what version of OpenSSL they are using and upgrade their systems to the appropriate fix from OpenSSL.
- Request a reissue (with new private key) for SSL Certificates that were installed on affected servers, install the new certificate, then request revocation of the old certificate.
- Use GlobalSign’s SSL Configuration Checker tool to test your server for the Heartbleed vulnerability
GlobalSign offers free reissues to its direct customers, so if you are a GlobalSign SSL customer affected by the Heartbleed bug, please see our support center for instructions on reissuing your SSL Certificate.
You can read the original article here.
We all believe (and hope) that ‘it won’t happen to us’ but how many horror stories of you heard where an unnoticed leak has turned into a flood, a briefly un-manned room has resulted in theft, or a faulty piece of equipment has led to ruined stock, lost data or hardware? SMS Alarm General is an extremely cost-effective way of helping to prevent these initially minor events becoming catastrophic for you or your business.
Up to 2 x Go-Probe sensors and 1 x Temperature sensor can be monitored by the Alarm General and it is also possible to link the Alarm General to alarm panels such as fire, security, generator, UPS, fire suppression, air-conditioning, etc. SMS Alarm General can be used to help protect all types of premises: Offices, data centres, shops, warehouses, industrial units, homes, holiday villas – the list is endless!
How Does SMS Alarm General Work?
The SMS Alarm General solution consists of a quad-band modem, integrated Jacarta configuration and alerting software module, and the capacity to connect up to 2 x Go-Probe sensors and 1 x Temperature sensor. Once a user-supplied SIM card is inserted and the sensors connected, configuration of alarm messages and contact telephone numbers can be carried out by sending text messages to the Alarm General. The Alarm General will reply to acknowledge each of the messages, confirming that the required instruction has been carried out.
Once configured, SMS Alarm General will continually monitor the condition of the sensors and alert the configured mobile phone numbers when an alarm condition is detected. Up to 5 numbers can be alerted. In addition to the alerts, Alarm General can send you a daily status text, and you can remotely check the status of your sensors at any time by sending a text message to the Alarm General.
You can download the brochure here.
Jan
This joint solution provides a highly efficient, scalable and effective network-based platform for service providers and enterprise networks. In turn, they can deliver increased levels of security to their consumer, business and internal customers without any need for end-device software or new network elements. Utilizing DNS, a lightweight, multi-network, multi-end device protocol, this solution is available for both fixed (xDSL, Cable, NBN) and wireless networks offering protection for PCs, tablets, smartphones, wireless dongles, games consoles, and any IP- enabled device.
“Sophos provides threat intelligence feeds to our network, gateway and endpoint security products. Our partnership with Nominum extends this intelligence to the DNS level, offering security in the core operations of the network,” said Stuart Fisher, Managing Director, Sophos APAC. “SophosLabs identifies more than 30,000 new malicious URLs daily. By adding intelligence from the DNS into the equation, the joint Nominum–Sophos solution offers maximum protection for all network users.”
“Both our companies are highly committed to making the Internet a safer, more secure place for users. Considering the value this partnership will bring into our core markets such as Australia, New Zealand, Singapore, ASEAN, China and India, we anticipate we will see a high-level of adoption.”
“By joining our partner ecosystem, Sophos and Nominum can provide increased protection to Internet users across multiple platforms,” said Brian McElroy, Vice President of Business Development, Nominum. “A joint Nominum-Sophos security solution offers near real-time (zero day) in-network protection, like the Interpol-fed Nominum Content Blocking solution deployed in Australian carrier networks, which protects Internet users from child sexual exploitation content. Adding this new policy and protection in-network from malicious threats makes great sense.”
Jan
SC Magazine’s July 2014 review calls Sophos Mobile Control 4.0 (SMC) a “solid, quality enterprise-capable product,” and notes that SMC is “easy to deploy and manage with a vast set of features.”
This award shouldn’t be too surprising — SMC version 3.5 also received five stars from SC Magazine. And we’ve been recognized as a Visionary in the Gartner Magic Quadrant for Enterprise Mobility Management.
Here are some other highlights from the SC Magazine review:
1. SMC supports BYOD initiatives with its self-service portal, so users can “handle most of the help desk activities themselves if admins choose this path.”
2. “Configuration, user provisioning and device enrollment took only minutes.”
3. “The dashboard was feature-rich and easy to navigate.”
4. “One of the features of note was the integration of the anti-virus and protection solution well known to Sophos customers.”
5. Support documentation provided “excellent information for each feature of the product” that were “clear and easy to understand.”
6. “Value for money is good.”
Sophos is a Visionary in Enterprise Mobility Management
Gartner’s Magic Quadrant for Enterprise Mobility Management Suites 2014 recognizes Sophos in the Visionary Quadrant. Find out what Gartner has to say about Sophos and SMC in the free Magic Quadrant report.
Learn more about Sophos Mobile Control
SMC 4.0 takes data protection beyond the office door by ensuring persistent mobile encryption on devices. Additional network access control based on device compliance status makes mobile device management, content management and mobile security simple and effective.
Available on premise or as a service, SMC provides a simple and differentiated approach for small and mid-market organizations to manage and secure mobile devices, content and applications. Watch the video for a quick overview of Sophos Mobile Control, or sign up for a free trial to see for yourself why SMC is the best EMM product for businesses of any size.
You can read the original article, here.
The survey was organised by the University of Kent’s Interdisciplinary Research Centre in Cyber Security, by a team composed of both computer scientists and psychologists, and conducted using Google’s Consumer Surveys platform. As the authors of the report caution their readers, the survey covered a relatively small number of people – just over 1,500 UK adults. That leaves it open to inaccuracies for all sorts of reasons, including sampling bias due to the kinds of people drawn to responding to online surveys, but the results seem dramatic enough to be more than just an anomaly. Other data picked up by the survey seems fairly predictable. Around two-thirds of us feel at risk from cybercrime, just over 1 in 4 have been the victim of some sort of “cyber-dependent crime” in the last year, with malware (11.9%) and phishing (7.3%) the main culprits. 1 in 10 has been exposed to online bullying, harassment or stalking.
If the rate of malware infections seems a little higher than we normally see in surveys of this nature, that could well be down to the high levels of CryptoLocker and other ransomware included in those figures. 9.7% of people claimed they had been infected by ransomware of some kind, with CryptoLocker specifically named in the survey question and making up around a third of all reported infections.
Survey data always has a problem in that it’s only as accurate as the knowledge (and honesty) of the people being surveyed. Malware, for the most part, aims to avoid revealing its presence to its victims, sometimes going to great lengths to do so. So when you ask someone if they have ever been hit by malware, and their response is a strong and definite “no”, that answer should always be viewed sceptically. How can they possibly know? Proving a negative is not easy in the best of circumstances, and being certain something hasn’t happened simply because you haven’t noticed it happen is particularly difficult when the thing you haven’t noticed is specifically designed to be secretive and stealthy. Have you ever been spied on from a distant rooftop? No? Can you really be sure of that?
Unlike most malware though, CryptoLocker and other ransomware attacks make no secret of their presence, indeed their main intention is to make it very plain to their victims that they have been infected. So it could be that what we’re seeing here is not a change in the total level of malware going around, simply a change in the visibility of it to the general public.
Only a third have firewalls, and perhaps that is no bad thing. Other details emerging from this same survey include less than half of respondents using up-to-date anti-malware, just over a third implementing firewalls, and a little less than that exercising sensible password hygiene. Maybe a little more visibility will finally make the general public start sitting up and paying more attention to the risks of malware and other online threats. At the moment, it seems like we’re still mostly either ignorant or in denial, right up until something nasty infects our machine and nabs our data, or encrypts it and demands a ransom. That so many people pay up is not much of a surprise either. Like other security basics, it looks like proper backing up of sensitive or precious files is a rare thing.
Victims forced to pay up include police departments and law firms, with ransomware threats clearly targeting small businesses where proper security practices such as backups are more likely to be lacking. These shortcomings may have been hidden in the past, but now they are being forced into the spotlight, and the shock may just jolt people into giving the right priority to their security needs.
Here are five “top tips” for keeping safe against malware in general, and cyberblackmailers in particular:
- Keep regular backups of your important files.
- Use an anti-virus, and keep it up to date.
- Keep your operating system and software up to date with patches.
- Review the access control settings on any network shares you have.
- Don’t give administrative privileges to your user accounts.
You can read the original article here. More information about CryptoLocker here.
Jan
A new program, dubbed PIN Skimmer by its University of Cambridge creators, can correctly guess a high proportion of PINs using the device’s camera and microphone. When selecting from a test set of 50 4-digit PINs, PIN Skimmer correctly infers more than 30% of PINs after 2 attempts, and more than 50% of PINs after 5 attempts on android-powered Nexus S and Galaxy S3 phones. When selecting from a set of 200 8-digit PINs, PIN Skimmer correctly infers about 45% of the PINs after 5 attempts and 60% after 10 attempts. The university team discovered that PIN Skimmer could identify PIN codes entered on number-only softpads by using the camera on the device to monitor the user’s eye movements as they enter their code. Also, the microphone could be used to detect “touch events” – the clicking sound made as the user enters their PIN on the touch screen.
The paper, written in order to raise awareness of side-channel attacks on smartphones, took the approach that the device had already been infected with malware that was then attempting to snaffle the PIN. The university team then set out to see how effective an attack could be and, also, how PIN length may affect the likelihood that the code could be correctly guessed. Mimicking a typical piece of malware, stealth was a key feature in the design. The researchers ran image processing algorithms remotely to minimise battery drain, something that could alert the user that an unauthorised program was running.
An API exposed by the Android operating system was used to disable the LED that switches on in some handsets when the camera is in use. Photos and video taken by PIN Skimmer were saved to the phone but the file sizes were limited to 2.5MB to reduce detection. A real piece of malware could likely hide such files from view completely. Likewise, the research team hypothesised that the sending of data back to the remote server could also be hidden from the user.
Additional network charges is another problem connected with transmitting data. Many smartphone users are on tariffs that charge them additional fees should they use more than a pre-determined amount of data within any monthly period. To that end the report suggested that a real-life Trojan would probably report back to its control centre only when it detected a free WiFi connection within range. The researchers discovered that, contrary to what you may have expected, longer PINs were actually easier to crack than shorter ones. This unexpected result was put down to the fact that longer PINs actually gave the program more information to work with which increased its accuracy.
One of the co-authors of the report, Professor Ross Anderson wrote: Our work shows it’s not enough for your electronic wallet software to grab hold of the screen, the accelerometers and the gyro; you’d better lock down the video camera, and the still camera too while you’re at it. (Our attack can use the still camera in burst mode.)
As for mitigating the risks posed by such an attack, Anderson suggested that questions need to be asked as to which resources should remain accessible during PIN entry, though he did note how disabling some functions, i.e. the speakers, could cause extreme problems to the usability of the device: For instance when a call comes in, the user needs to hear the ring tone while unlocking his phone; otherwise he may assume the caller has hung up.
Instead, he suggests that whitelists may be the answer – denying use of all resources during PIN entry, unless explicitly authorised. Another option, according to Anderson, would be a more widespread adoption of biometrics in smartphones but that is not without its own issues.
You can read the original article here.
Jan
Some recent industry estimates report that as many as 96 percent of organizations now have employees who use both corporate-managed and personal mobile devices for work purposes, forcing IT to adopt new strategies to protect their data on those devices. Even though huge numbers of smartphones and tablets are lost every day, many users don’t enable even basic password protection.
Mobile malware and hacking is on the rise and many workers are still using unsecured personal mobile devices to access corporate data—a major concern for organizations trying to protect data while letting users work how they want.
Sophos Mobile Control provides the complete security that IT requires to confidently embrace employee device mobility. This latest version delivers Windows Phone 8 support alongside iPhone/iPad and Android, with self-enrollment and self-service capabilities for users, and allows IT to manage the complete device lifecycle as well as loss & theft scenarios.
Also included is an easy-to-use client app, which provides access to compliance status, messages and support information—allowing for comprehensive reporting and giving IT a holistic view of devices. Simpler administration is delivered by an updated menu, dashboard and various other workflow improvements. The SaaS version of Sophos Mobile Control 3.5 delivers better integration into corporate IT with a new remote Exchange ActiveSync (EAS) Proxy that enables organizations to block non-compliant devices from receiving email, and remote LDAP support that allows users to easily connect to Active Directory.
You can read the original article, here.
It features user-based management, reporting and licensing; built-in web security to prevent user access to malicious and infected websites, and new policy-based Web Control features to enforce safe and productive web usage. Sophos Cloud is effortless to deploy and easy to use and manage for IT managers and channel partners, given its simple, intuitive user experience.
A recent Sophos survey of IT managers highlighted the growing challenge of device diversity across their organizations, with a need to support Windows PCs, Macs and mobile devices: 78 percent support or plan to support Macs on their corporate networks, and 41 percent see the number of Macs increasing in their corporate environments. A recent IDC study showed that a quarter of SMBs are using mobile device management (MDM) and Sophos is the number one solution. However, 75 percent still have not adopted MDM and with this new release Sophos has made it simpler than ever for those customers to get control of their mobile devices to secure their future. Clearly organizations need an integrated security strategy to support users’ demands to choose their own device (BYOD), while providing IT managers real-time visibility and access to information to keep organizations safe from advanced threats. Sophos Cloud delivers a simple and effective approach for IT organizations to confidently embrace BYOD and to support and protect the wide range of user devices in their environments.
Based on the same proven technology that protects over 100 million devices worldwide, Sophos Cloud is a smart choice for global organizations. It delivers effective mobile device management to keep users productive and corporate information secure. The new web features enable IT managers to easily set and enforce policies for enhanced security and compliance; user-based policies can be created once and rapidly deployed across multiple groups and platforms, and follow the users and their devices even when they are off the network. Sophos Cloud also adds Active Directory synchronization to simplify deployment and management for users and groups.
“IDC predicts that the continuing SMB productivity push will drive cloud and mobility adoption, in a big way; in the U.S., 1/3 of small businesses and almost 3/4 of mid-sized firms are using the cloud, and the share will continue to grow,” reports Raymond Boggs, research vice president at IDC. “Sophos Cloud can help manage security across Windows, Mac, and mobile devices, which is especially important given the diversity – some might say chaos – of an SMB environment. Its user-based management is well suited to SMBs looking to secure users of corporate devices or their own BYOD equipment. Sophos Cloud will be a useful resource for channel partners to leverage in helping support the resource-limited IT teams of their SMB customers.”
“We’re pleased to deliver this new release of Sophos Cloud, as it’s another positive step in our strategy to use the cloud to create new, innovative solutions to the ever-increasing security challenges faced by small and mid-market businesses today,” said Bill Lucchini, vice president and general manager of Sophos Cloud. “Sophos Cloud is a differentiated offering that enables IT professionals to simplify security management without compromising users’ demands for usability and performance. We continue to address the market’s desire for powerful simple-to-use solutions to combat the evolving threat landscape. Sophos security delivered with cloud simplicity is clearly resonating with our customers and partners.”
Sophos Cloud: Ideal for IT Solutions Providers
Consistent with Sophos’ commitment to its channel partners, Sophos Cloud enables IT solution providers and outsourcers to deliver value to customers. A unified web-based management console, hosted in the cloud by Sophos, enables complete protection for users and devices, and a new partner dashboard gives partners visibility into, and control over, their customers’ subscriptions, devices and policies.
Sophos Cloud is currently available. For more information or for a 30-day trial, visit: www.sophos.com/cloud