Mobile Security Forum
Total Page:16
File Type:pdf, Size:1020Kb
1 FEDERAL TRADE COMMISSION 2 3 4 5 6 7 MOBILE SECURITY FORUM 8 POTENTIAL THREATS AND SOLUTIONS 9 10 11 JUNE 4, 2013 12 13 14 15 16 17 Federal Trade Commission 18 601 New Jersey Avenue, N.W., Conference Center 19 Washington, DC 20 21 22 23 24 25 2 Final Version Mobile Security Forum 6/4/2013 1 FEDERAL TRADE COMMISSION 2 I N D E X 3 4 Session Page 5 6 Welcome, Emily Cope Burton 3 7 8 Opening Remarks, Chairwoman Edith Ramirez 6 9 10 Overview, Steven M. Bellovin 12 11 12 Panel 1: Understanding Mobile Malware 20 13 14 Panel 2: Building Security into Modern 15 Mobile Platforms 78 16 17 Speaker, Markus Jakobsson 145 18 19 Panel 3: Extending Security Throughout the 20 Mobile Ecosystem 160 21 22 Panel 4: Solutions for Consumers to Protect 23 Themselves from Mobile Threats 225 24 25 Closing Remarks, Charles A. Harwood 290 For The Record, Inc. (301) 870-8025 - www.ftrinc.net - (800) 921-5555 3 Final Version Mobile Security Forum 6/4/2013 1 WELCOME 2 MS. BURTON: Good morning, everyone. I’m Emily 3 Cope Burton from the Division of Marketing Practices of 4 the Federal Trade Commission, and it is my pleasure to 5 welcome you to our Mobile Security Forum. I’m delighted 6 that you’re all here to learn with us and teach us as 7 well. Since this is a post-sequester-era government 8 event, there is no coffee or water. I just want to warn 9 you in advance. You will have full access to the 10 bathrooms, which are across the lobby to the left of the 11 security desk. There is also a water fountain there if 12 you brought your own container. We have a 20-minute 13 break after the first panel, though, so those of who you 14 did not come prepared will have time to get some 15 provisions. 16 A few notes about the Q&A. We will not have 17 specific Q&A sessions or Q&A portions of panels, so if 18 you have a question, you can write it down on a Q&A card. 19 There are a couple in each of the folders, and there are 20 also some out on the table with the materials. Hold it 21 up in the air, someone will come and get it and deliver 22 it to the moderator, and we’ll try to ask -- get through 23 as many of those questions as we can. But we will be 24 taking only written questions. 25 We will also, because we are very high-tech For The Record, Inc. (301) 870-8025 - www.ftrinc.net - (800) 921-5555 4 Final Version Mobile Security Forum 6/4/2013 1 here at the FTC, be taking questions over our Facebook 2 page, in the Workshop Status thread, and via email to 3 OPA, for Office of Public Affairs, @ftc.gov. And then 4 also the FTC staff will be live-tweeting this event from 5 the FTC Twitter account and using #ftcmobile. So, 6 speaking of mobile, please take this opportunity to turn 7 off your mobile devices. 8 And then let me just quickly run through our 9 security procedures. Anyone who leaves the building 10 without an FTC badge will require -- be required to go 11 back through security, including the metal detectors, 12 prior to reentry. So, if you’re leaving for a break or 13 lunch, please time your return accordingly. 14 In the event of a fire or evacuation of the 15 building, please leave the building in an orderly 16 fashion. Once aside, look directly across New Jersey 17 Avenue to the Georgetown Law Center, which is our 18 rallying point. On the front sidewalk to the right side 19 of the building is where you’ll meet, and there will be a 20 person accounting for all of the conference center 21 attendees. 22 In the event that it’s safer to remain inside 23 the building, you’ll be told where to go inside the 24 building. If you spot suspicious activity, please report 25 it to security. And this event may be photographed, For The Record, Inc. (301) 870-8025 - www.ftrinc.net - (800) 921-5555 5 Final Version Mobile Security Forum 6/4/2013 1 videotaped, webcast or otherwise recorded. By 2 participating in this event you are agreeing that your 3 image and anything you say or submit may be posted 4 indefinitely at ftc.gov or one of the Commission’s 5 publicly available social media sites. 6 With that, I’d like to introduce the Chairwoman 7 of the Federal Trade Commission, Edith Ramirez, who will 8 be giving us opening remarks to set the stage for the 9 rest of the day. Thank you to the Chairwoman and thank 10 you to all of you for participating. 11 (Applause.) 12 13 14 15 16 17 18 19 20 21 22 23 24 25 For The Record, Inc. (301) 870-8025 - www.ftrinc.net - (800) 921-5555 6 Final Version Mobile Security Forum 6/4/2013 1 OPENING REMARKS 2 CHAIRWOMAN RAMIREZ: Thank you, Emily, and 3 thanks to all of you for being here today. And welcome 4 to the FTC’s Mobile Security Forum. It’s no exaggeration 5 to say that we’re in the midst of a mobile revolution. 6 Today, consumers buy twice as many mobile devices as they 7 do PCs. Nearly a third of the consumers who use their 8 phones to get to the Internet say it’s their primary way 9 of reaching the web. And we’re starting to see the rise 10 of the mobile-only Internet user. 11 In the first quarter of this year, tablets and 12 smartphones accounted for over a fifth of all e-commerce 13 traffic in the U.S., compared to -- get this -- just 2 14 percent only two years ago. Smartphone users reach for 15 their phones an astonishing 150 times a day on average, 16 to send a text, check for email, occasionally make a 17 phone call, surf the web, or use an app. 18 Today, though, we’ll be turning away from our 19 addictive smartphones and tablets, or so I hope, to 20 consider the current state of mobile security, emerging 21 threats, and the measures industry, government, and 22 consumers can take to protect against security risks. 23 Our interest in mobile security is an outgrowth of the 24 FTC’s broad mandate to protect consumers, which includes 25 protecting them from threats to the use and enjoyment of For The Record, Inc. (301) 870-8025 - www.ftrinc.net - (800) 921-5555 7 Final Version Mobile Security Forum 6/4/2013 1 new technologies. 2 In the last decade, the FTC has been at the 3 forefront, along with our partners at the Justice 4 Department and in the states, of the fight against 5 spyware on the desktop computer. We’ve brought a dozen 6 enforcement actions against purveyors of spyware, from 7 rogue ISPs that distribute malware, to computers that 8 installed keystroke loggers that captured sensitive 9 information, to businesses that transmitted nuisance 10 adware that delivered popup ads. 11 Most recently, we brought a number of cases, 12 including an enforcement sweep initiated last fall 13 against marketers of PC scareware scams that operated in 14 the U.S. and across the globe. As consumers migrate to 15 smartphones and tablets in record numbers, we’re now also 16 turning our attention to the security of the mobile 17 environment. 18 We have three main tools at our disposal: law 19 enforcement, consumer and business education, and policy, 20 which includes promoting industry dialogue and advocating 21 best practices. On the enforcement front, we’ve already 22 begun to address mobile security with our first case in 23 this arena. In February, the Commission alleged that HTC 24 America, the mobile device maker, introduced an array of 25 security vulnerabilities in the course of customizing its For The Record, Inc. (301) 870-8025 - www.ftrinc.net - (800) 921-5555 8 Final Version Mobile Security Forum 6/4/2013 1 mobile devices, thereby putting at risk the sensitive 2 information of millions of consumers. 3 We charged HTC with violating the FTC Act's, 4 prohibitions on both deceptive and unfair practices. To 5 resolve the FTC’s charges, HTC agreed to establish a 6 comprehensive security program and undergo independent 7 security audits every other year for 20 years. Our 8 settlement also includes a provision that is the first of 9 its kind in an FTC order, and as far as I’m aware, the 10 first of its kind in any other U.S. or foreign agency 11 order: a requirement that HTC develop and release 12 software patches to fix the vulnerabilities on millions 13 of its devices. 14 But cases like HTC demand sophisticated 15 technological expertise and tools. And to make these 16 cases possible, we’ve created a forensic mobile lab to 17 allow FTC staff to conduct research and investigations. 18 We’ve brought in distinguished technologists, like Steve 19 Bellovin of Columbia University, and his predecessor, Ed 20 Felton of Princeton. And we’ve created a mobile unit to 21 ensure that we are alert to mobile issues in all of our 22 consumer protection work. 23 As to the FTC’s second tool, consumer and 24 business education, the good news is that some of you who 25 are with us today already offer an array of innovative For The Record, Inc.