190 likes | 563 Views
Mobile Banking Security. Joe LoBianco, CISSP, CISM Moderator: Illena Armstrong, editor-in-chief, SC Magazine. Presentation Agenda. What is the current state of mobile computing? What are consumer attitudes toward mobile banking? Is mobile banking secure? What could the future hold?.
E N D
Mobile Banking Security Joe LoBianco, CISSP, CISM Moderator: Illena Armstrong, editor-in-chief, SC Magazine
Presentation Agenda What is the current state of mobile computing? What are consumer attitudes toward mobile banking? Is mobile banking secure? What could the future hold?
Current State of Mobile Computing Industry is in a state of flux – mobile devices are evolving rapidly
Smartphone Usage Trends Source: Quantcast • What will this look like in 2011? • Does Windows Phone 7 change anything? May 2010 Mobile Web Usage:
Mobile Banking Today 10 Million Mobile Banking Subscribers 22 Million Mobile Banking Subscribers Source: ABI Research
Consumer Attitudes towards Mobile Banking Only 19% of Canadian Consumers feel comfortable with mobile banking Why are the other 81% not comfortable? Source: KPMG
Is this Consumer Attitude Justified? VS. Virtually all mobile threats have originated from fake apps, with little consumer impact
Hacker’s Magic Quadrant Hacker’s Magic Quadrant Easy money Reward/Impact Waste of time Ease of Attack/Likelihood Why spend time on difficult and low return activities when there are easy ones with higher returns?
Today’s Mobile Banking Threats Phishing and fake apps pose a threat to mobile banking Other types of malware have yet to emerge as an active threat
Drive-by Malware In More Depth What is it? Malware that installs without user intervention Why is it such a threat? Users can be infected by visiting legit sites without taking any action Conditions for success: Browsers or web plug-ins with lots of vulnerabilities, preferably found very often Common OS base Common hardware platform As of today, this remains a significant threat for PCs, but not for mobile devices
Bringing it all together... Hacker’s Magic Quadrant Easy money... Waste of time ...
Advice for Security Professionals When doing an assessment of mobile banking: Standard secure development practices Conduct Pen Test & code review Watch out for client side caching of data! Protecting your users: Educate users on fake apps Lock down devices, where possible