The NSA advises you to turn your phone off and back on once a week
zdnet.com
zdnet.com
Rebooting your phone periodically removes zero day attacks that don’t persist on your device through a restart. People who are at risk of that are a vanishingly small fraction of the population. Those who are targeted with such attacks are often reinfected anyways because attackers are persistent and realize they’ve lost access to the device. Nothing about this is described in the recommendations, it’s just “oh you should do this” with zero threat modeling whatsoever. Then there’s stuff like “don’t use public Wi-Fi” which has been a bogeyman for probably longer than I’ve been alive. It’s not a problem anymore. Basically everything you do these days is using HTTPS. The author of this post goes on to shill VPNs, which are often snake oil that is even worse than the problem they aim to “cure”.
I have no problem with some parts of this list, including the NSA putting their name behind it. It’s good to keep your software up to date. Being cautious in unfamiliar contexts is usually a good trait to have. But when you throw in the other stuff it’s like if the NIH published a list like “oh you should exercise every day and also completely avoid shrimp”. Like yes some parts of it are good, some of this is only relevant to people who are allergic to shellfish. There’s no point, and actually I will say it’s actively harmful, to just publish stuff like this with explaining when it is applicable and the actual security it provides.
It's probably a million dollars cheaper to buy access to a non-persistent exploit than a full one but those are probably looking for a one-off exfil anyway. And like you said they can just run it again a couple weeks later for new stuff.
but regardless I think most peoples phones batteries die once a week anyway so it's not a big deal
Not anyone I know. I have actually never had my phone's battery drain so much that the phone had to be shut down.
Individuals: https://www.ncsc.gov.uk/cyberaware/home
Business: https://www.ncsc.gov.uk/collection/device-security-guidance/... & https://github.com/ukncsc/Device-Security-Guidance-Configura...
Apple Configurator can define WiFi SSID allowlist, so the phone will only connect to known access points.
iOS Lockdown mode blocks a class of attacks and is mostly invisible to UX. It can be disabled for trusted apps and websites.
Brave can disable Javascript by default, and allow on trusted sites.
Since iPhones no longer power off, a faraday bag can be useful in some contexts.
iVerify claims to check for malware, unclear if it's meaningful given iOS restrictions, but the app regularly reminds the user to reboot.
> First and foremost, iVerify Basic is a security scanner that ensures you are using the iPhone's basic security features such as Face/Touch ID and Screen Lock, and are running the latest iOS version. It also runs a device scan that looks for security anomalies and notifies you if something seems out of place.
https://iverify.io/post/clipping-wings-our-analysis-of-a-peg...
> For this analysis, we had access to the customer’s iTunes backups, crash logs, and sysdiagnose files. One of the best things about Threat Hunter is that we can gather these artifacts remotely without needing physical access to the device.
Is this true? I’m still using first se do i don’t know.
If you are referring to the “Findable After Power Off” functionality, that can be disabled in settings.
If non-lost phone location should not be broadcast for a short period, it can be put into a faraday bag.
Send location/signal/command to public cloud, to request non-tracking of location.
> put in a faraday bag
Local action. No network connection or location broadcast needed.
That way I don't have to touch the light switch three times and turn my phone on and off while turning in a circle to keep the bad actors away.
:|
Given how we generally only reboot our phones for system updates, this is good practice.
I was alerted to a garage break-in because a push to my phone went to my watch, and then I called the police immediately.
If I (bizarrely) got a message informing me that a tornado was about to hit my house, I'd a) assume it was a scam b) have no idea about what I was supposed to do about it anyway. Hold on to something solid to avoid getting sucked away?
Booting up takes a lot of battery power - I bet if you did airplane mode plus battery saver overnight, you would actually use less power than rebooting it. Try it!
While 'once a week' is very arbitrary, rebooting a device (especially an iPhone) will make it 'safer' than what it was before the reboot in theory at least.
iOS and Android are big and all vulnerabilities aren't reported as there are many in the wild just like any software out there.
Imagine you are at a cafe that had a compromised auth portal where you clicked a bunch of things and there was a payload that exploited a vulnerability and was doing something on your phone. If you rebooted, then likely it's not running again and you may not visit the cafe again either. That way a reboot likely fixed your problem. the alternative is that you wait for that vulnerability to become public, apple or google patch it and then you update it and your device reboots. This could take literally months and that payload is still active until then. I know many people who dont reboot their phones at all unless the battery is dead while updates are also not as common as people think. So many are running iOS 16 even today when their phone says update but they just ignore.
When someone reads all this on HN it sounds not very smart but these lists are designed for people who have no knowledge of tech. Hence you can sell VPNs to these people as well which is where its a bit of an issue on whats right and whats just advertising and selling you stuff. So the outrage is valid but a reboot is actually more beneficial than people think it is.
I had to learn the new reset sequence: quick volume up, quick volume down, hold power
https://s3.documentcloud.org/documents/21018353/nsa-mobile-d...
What is any of this supposed to protect against besides potential 0days being used by governments (both foreign and domestic)? It's not like phones are generally extremely vulnerable to the extent that this is necessary, and if you're legitimately under threat of being targeted by someone with access to an arsenal like that of the NSO Group's, this is very weak advice. Not connecting to public wifi and not downloading attachments isn't going to save you when you're hit with a zero-click exploit.
Powered off, how cute that you think you can actually power off your phone.
>How are iPhones still findable even when turned off >https://www.xda-developers.com/iphone-findable-turned-off/