NSA Mobile Device Best Practices
documentcloud.org
documentcloud.org
https://media.defense.gov/2020/Jul/28/2002465830/-1/-1/0/MOB...
Corresponding NSA document for OCONUS (travel outside continental US)
https://home.army.mil/stewart/index.php/download_file/view/1...
I'm surprised the government/military does not issue its employees USB condoms to obviate this worry.
It’d be like your internal corporate email client not even letting you send mail out to external addresses.
Sure, you could intentionally set up IMAP with an untrusted client and then send such messages (and likewise, you could intentionally bring some other insecure cable with you); but someone doing that would likely have a visible pattern of doing that, long before they actually get spearphished—one that could be noticed and reprimanded.
Of course, ideally, you’d make using the insecure clients / cables impossible, by giving the “other end” a proprietary shape that only the secure client/cable fits with.
(Maybe they could design a little adapter that could be semi-permanently socketed into a phone’s USB-C/Lightning port, turning it into something proprietary that only their secure cable has the male end for? I’m assuming here they still need a data connection — with a different special cable — for device maintenance; otherwise you could just make that little socketed-on adapter be the condom.)
im calling BS. NSO and others have demonstrated repeatedly they can (and do) bruteforce these pin based logins quickly and efficiently without triggering the wipe using sidechannel attacks on running services and software over the air and through USB. use a PASSPHRASE.
>Consider using Biometrics (e.g., fingerprint, face) authentication for convenience to protect data of minimal sensitivity
remember: the fifth amendment does not cover biometrics . if a DUI case can forcibly extract your blood, then you can and will be required to present your face to unlock a laptop. use passphrases.
>DO NOT jailbreak or root the device.
this often allows people to remove pre-installed spyware just as easily as it can be installed.
On the iPhone theres a neat trick: If you seem to be in a situation where you might be forced to hand over your phone (and unlock it with bio), hold down the power button for a second or two (secretly/inconspicuously in your pocket or wherever your phone is). This will disable fingerprint unlocking and you will be forced to enter PIN.
Doesn't seem to work on Android (11 at least) though.
I'd hold the power button a bit longer and turn off the device altogether. Granted, not as convenient.
But as another commenter pointed out you can hold the power button for a longer time (5+ seconds) and the phone will turn off or reboot, which achieves the same thing. Just quicker and stealthier on the iPhone.
Ideally I’d like both the mic and camera cover
On android, if I turn bluetooth off from the quick access menu, it stays off--which is what I expect.
Apple is notoriously allergic to putting toggles for every little thing, and that shouldn't be a surprise to software developers. We all know every user-configurable setting increases complexity.
Not to mention, some brief wordy nearby text display in tiny print after the fact, is the opposite of clear.
They can also mean the difference between a tool and a toy or even worse, a slave collar.
One of the good practices in programming is to not hardcode things. Where that is followed, often the hardest part about configurability is the UI for it, since under the hood it's already determined by a bunch of variables anyway, and it's mostly a matter of exposing them nicely to the user.
Besides, it's way more complex to have a timed toggle than just a toggle.
for real? because you have to go into the Settings app to turn off wifi permanently? Sometimes you people are delusional.
Oh, I forgot all about that.
I worked at a K-12 that deployed Apple devices awhile back, and this behavior was a nightmare for network management. Especially for travelling teachers who would take their device to several different buildings throughout the day (and, therefore, different IP subnets with the same WiFi name).
The worst part was that some of the devices would just... never emit a DHCPREQUEST. They'd either ignore the fact that there was an address collision confusing everyone else's ARP tables, or connect to the network but stick with an IP that had no route to a gateway. As I recall -- it's been awhile -- even setting the lease duration to something very low didn't seem to help. Indeed, I think that made it worse.
It was bad enough at one point that we had those devices with the worst behavior set up with reserved IPs and a hidden WiFi network that was a district-wide VLAN with a single subnet.
My guess is accidentally disabling those services via control center was a common issue.
I’d rather it be the other way, but that’s probably why it’s not.
Basically nothing else works like that.
In fact figuring out how to turn off wifi with the combination of Airplane mode and wifi button just about blows my mind every time I try. So complicated.
Imagine you're not good at using computers. I've seen people accidentally turn on do not disturb and be unable to figure out why their phone isn't ringing so they think it's broken.
We are in a small minority of 'power users' - iPhones have hundreds of millions (billions?) of users across the entire world.
IMHO, these are not good excuses to avoid a clear interface. If the rules are simple and clear, and presented clearly, even the dumbest of the dumb can learn them. Trying to guess and out-think the user only ends up in more confusion.
When you disable wifi/bluetooth via the control center, pop-up text appears saying exactly what that means. I'm not sure how they could make that more clear. It still may not be your (or my) desired default, but I at least understand the reasoning.
It's extra complexity in the form of rules added to what was previously a simple to understand toggle button. That it goes against historical norms, reduces privacy, and wastes a bit of power is the icing.
- the wifi is not connected to the internet or requires username/password
- user disables it
24 hours later, the user is racking up their mobile data plan because they forgot to enable the wifi again.
This prevents it.
Bluetooth,
- You disconnected from a speaker that was being used so someone else could connect
- The next day you go to get in your car in the morning and it didn't give you the directions through the radio. Whatever
- That afternoon it works and you don't think about it. It fixed itself.
Just different users.
The icon in the swipe up control center is for temporarily disconnecting it…which it literally tells you when you click it.
In general, try long-pressing everything: there's generally shortcuts or "power moves" afterwards.
And the actual Wi-Fi and Bluetooth sliders are decidedly in the ON position. I must've concluded that since it didn't do the "until tomorrow" message then it behaved as I wanted.
I stand corrected.
But otherwise this is great and I would probably add “reset and replace devices often.”
It also prevents casual but intentional unauthorized access, just not a determined attacker.
As you note, there are other layers of security for that.
Remember this is for people working on sensitive information.
This is what the NSA's original mission was, to keep people safe and strengthen the American defense posture from the single person up to the entire infrastructure that we rely on day-to-day. The mission has shifted to offense after 9/11 so there's conflicting goals here (can't patch something we're using against the bad guys)
The only shift after 9/11 was getting the three agencies to actually talk to each other.
https://www.nsa.gov/about/cryptologic-heritage/historical-fi...
> The Brownell Committee suggested that the creation of AFSA could be seen as a "step backward," and recommended that the power of the director, AFSA, to centralize COMINT be increased.
> In October, Harry Truman authorized a reorganization and renaming of AFSA, and in November, the secretary of defense authorized the replacement of AFSA by the National Security Agency.
The NSA director even said they were appalled how the agents were portrayed and went on PR campaigns to defend them selves. They were always spying but not ruthless killers as depicted in the movie.
> requiring a defendant to expose his face to unlock a computer can be lawful, and is not far removed from other procedures that are now routinely approved by courts, with proper justification: standing in a lineup, submitting a handwriting or voice exemplar, or submitting a blood or DNA sample
Contrasting the logic used by a judge in a similar case in (2019) [2]:
> If a person cannot be compelled to provide a passcode because it is a testimonial communication, a person cannot be compelled to provide one’s finger, thumb, iris, face, or other biometric feature to unlock that same device
Ars has a summary of more cases [3]. It looks like in several instances state courts allowed the devices to be unlocked using biometrics, but the rulings were reversed at the federal level. In many cases a warrant was required.
3. https://arstechnica.com/tech-policy/2020/06/indiana-supreme-...
Biometrics is good for law enforcement but is it tougher for hackers?
Maybe by the NSA. Any defense attorney will tell you otherwise. If your fingerprint unlocks your phone then the cops will hold your finger to the phone. If you face unlocks your phone then they will do that too. A pin/password means you retain at least some control.
If this was an Archer episode, I'd point out that while dead people cannot divulge pins/passwords their fingerprints still work.
Passwords are better than biometrics for security; but between password validations, presuming some level of convenience is needed, using biometrics to check that the same person is still there is better than "just stay unlocked for a few minutes even after being put to sleep".
It's like HTTP Basic Auth (sending credentials with every request), vs. logging in, receiving a short-lived session cookie, and then sending that session cookie with your requests for a few minutes.
It’s not perfect, but I think it strikes the best balance.
Thoughts, HN? I can see how this might be good for performance, but how is it good for security?
That's my best guess.
As soon as you make changes have persistence you have proof and some operators are not oaky with that.
For a very recent example of this, see the NSO Pegasus scandal from the past couple of weeks.
A reboot "unloads" the malware (until the adversary sends another payload, anyway.)
For example, your running kernel space may be compromised but your on-disk kernel image may be still pristine due to a secure boot chain. That’s why rebooting can help remove such exploits.
1) even on mobiles you still get the occasional webview or other core library update and need to reboot to complete the patch.
2) modern versions of Android use per-file encryption. Periodically rebooting flushes unencrypted buffers.
Nothing electronic EVER arrived at the facility or left with you when you left the facility that wasn't accounted for. Nothing that ever entered that wasn't needed, NO phones allowed ever. You and your vehicle were searched on arrival and exit. We went through a lot of laptops...
With the complexity of hardware / software involved, I suspect that's the only way.
Why? I'm not seeing the connection
I think wrote my original post in a way that wasn't clear.
Thought they wouldn't let it in either. Makes sense now.
Send yourself a link by SMS, or some popular messenger like Whatsapp.
Your phone will automatically make you a browser page preview, and in the process run every browser exploit available.
Google added an extremely well hidden option to disable it it Messages few versions ago. Since there is no way to be sure Google does not remove it, and add some kind of another autoplay like feature in the future, I just replaced the SMS app altogether to one which does not peek into my conversations https://play.google.com/store/apps/details?id=com.simplemobi... (google straight tells they can get a copy of your SMSes as per their disclaimer if you use Google Messages for "improving service")
It turns out my Samsung candy bar phone with no camera, GPS and internet leads the way in security.
Useful to have if you are curious about protests or concerts and other gatherings of people with a significant criminal element who could get your IMEI stingray-ed and then palantir-ed.
Is the surgeon general's advice "Pregnant women should avoid alcohol" unclear?
Here's a long list of scholarly articles that use "Avoid Alcahol" when stating or re-stating health recommendations from various countries.
https://scholar.google.com/scholar?hl=en&as_sdt=0%2C5&q=wome...