{"id":12026,"date":"2007-07-13T20:57:00","date_gmt":"2007-07-13T20:57:00","guid":{"rendered":"https:\/\/masabidev.wpengine.com\/news\/problems-with-mobile-security-1\/"},"modified":"2014-11-25T15:23:03","modified_gmt":"2014-11-25T15:23:03","slug":"problems-with-mobile-security-1","status":"publish","type":"post","link":"https:\/\/www.masabi.com\/it\/news\/problems-with-mobile-security-1\/","title":{"rendered":"Problems with Mobile Security #1"},"content":{"rendered":"<div class=\"block-\">\n<div style=\"font-family: arial;\">Mobile ticketing, m-commerce, secure messaging, corporate applications, government communications, e-money, the list goes on of things that would be great to do on mobile &#8211; as long as they really were secure.<\/p>\n<p>So, security on our phones, and we&#8217;d like to use publicly endorsed standards &#8211; 10 out of 10 security experts prefer it and describe any non-standard (proprietary) security as &#8220;<a href=\"https:\/\/www.interhack.net\/people\/cmcurtin\/snake-oil-faq.html#SECTION00050000000000000000\">Snake-Oil<\/a>&#8220;.<\/p>\n<p><span style=\"font-weight: bold;\">Q: <\/span>HTTPS\/SSL is used for e-commerce everywhere, why not use it for mobile-commerce?<\/div>\n<p><span style=\"font-weight: bold;font-family:arial;\" >A: <\/span><span style=\"font-family:arial;\">a number of issues make it impractical for mass-market mobile use: <\/span><span style=\"font-weight: bold;font-family:arial;\" ><br \/><\/span><\/p>\n<ol style=\"font-family: arial;\">\n<li><strong>Not available on all phones<br \/><\/strong>MIDP1 phones don&#8217;t support SSL connections. MIDP1 represents fewer than half of the JAVA enabled phones in circulation in the West, but a significant number and a greater proportion in the developing world where used handsets are popular. To develop systems that won&#8217;t run on these handsets is to needlessly cut down your potential user-base.\n<\/li>\n<li><span style=\"font-weight: bold;\">Out of Date Symmetric Ciphers<\/span><br \/>Some handsets have built in HTTPS\/SSL for their browsers and many handsets use the easiest to develop, and alas the oldest ciphers in their SSL\/HTTPS. Some of these ciphers have <span style=\"font-weight: bold;\">known vulnerabilities<\/span>, and should not be added to new systems, for example RC4. US Govt CERT Advisory: <a href=\"https:\/\/www.kb.cert.org\/vuls\/id\/565052\">SSL\/RC4 passwords easily crackable; solution: <b>Do not use RC4 encryption<\/b><\/a>.<br \/>This is alarming as <acronym title=\"all as far as I can tell, please correct me if I'm wrong\">most mobile browsers<\/acronym> which have SSH\/HTTPS only use RC4. Try connecting to your bank, and look at the page\/connection security details, and I&#8217;ll bet it says that you are using <span style=\"font-weight: bold;\">RC4<\/span>. It should be retired, not built into brand new systems.<br \/><span style=\"font-style: italic;\">&#8220;RC4 encryption algorithm is not a Federal Information Processing (FIPS) standard and probably won&#8217;t ever be because network professionals see RC4 as rather weak in terms of message authentication and integrity.&#8221;<\/span> &#8211; <a href=\"https:\/\/www.networkworld.com\/news\/2005\/011005nist.html\">William Burr of NIST<\/a>\n<\/li>\n<li><span style=\"font-weight: bold;\">Only secures TCP data<\/span><br \/>The built in SSL\/HTTPS cannot be used to add encryption to locally stored data, SMS, MMS, Bluetooth, IrDA or any other connections used by the mobile device, so anything you are doing on these channels is in the clear. This non-TCP data is important because many users don&#8217;t always have the correct data settings for java networking, or know how to use them, and you can greatly help them by being able to <a href=\"http:\/\/localhost:10003\/techUsability.html#networking\">&#8220;fall-back&#8221; to encrypted SMS<\/a> to make your purchase, as you will find in our latest apps. We will cover networking issues in a later blog post. Also people have <a href=\"https:\/\/www.hig.no\/content\/download\/3188\/69534\/file\/Egeberg%20-%20Storage%20of%20sensitive%20data%20in%20a%20java%20enabled%20cellphon.pdf\">attacked and opened the RMS data stores on phones<\/a>, so your stored details are not safe unless you have taken extra steps beyond standard MIDP behaviour.\n<p><strong><\/strong><\/li>\n<li><strong>Certificate Problems<\/strong><br \/>Many handsets don&#8217;t have a full complement of root certification authority certificates installed. This means that your HTTPS server certificate will often not be recognised as a properly authenticated cert (throwing worrying messages to the user, and completely voiding the <a href=\"https:\/\/mpt.net.nz\/archive\/2006\/02\/20\/certificates\">trust relationships that make SSL\/HTTPS useful<\/a>), and the phone will NOT CONNECT AT ALL to your server from Java as invalid and self-signed certificate warnings are not fed to the user when the connection is made. For example one of our test applications was unable to connect to the major and popular <a href=\"https:\/\/sales.oystercard.com\/oyster\/lul\/entry.do\">London Underground Oyster<\/a> site, or the <a href=\"https:\/\/ibank.barclays.co.uk\/\">Barclays bank<\/a> websites on most Nokias, because of certificate issues.<br \/>It is impossible on almost all handsets to install any new certificates, so regardless of the technical abilities of your users or support teams you will not be able to overcome this issue; the <a href=\"https:\/\/www.operamini.com\/help\/faq\/#security\">FAQ site for Opera mini<\/a> also acknowledges this issue.<br \/>One final confusion: the original phone model from the handset manufacturer may have contained a valid Verisign or Thawte root cert, but sometimes the mobile network operator will remove that and put in their own certificates instead at the customisation stage, so you can&#8217;t reliably know what certs are installed even if you are sure which model of handset you are talking to.<\/li>\n<p><\/p>\n<li><strong>Slow to initiate<\/strong><br \/>HTTPS and SSL require <a href=\"https:\/\/technet2.microsoft.com\/windowsserver\/en\/library\/2a9816ef-70bf-4bd7-a043-9ba721595e271033.mspx?mfr=true\">several connections<\/a> to establish a secure session. On a fast PC network with low ping times this isn&#8217;t much of a problem as the amount of data sent is tiny. However on a phone with two second ping times, commonly up to six seconds, each connection (regardless of amount of data) takes serious time to travel to the server and back. On many handsets the cryptography required on the handset side can also cause delays &#8211; in our experience up to eight seconds on the encryption alone, even on a recent MIDP2 Nokia.<br \/><img decoding=\"async\" src=\"http:\/\/localhost:10003\/tech\/ssl.gif\" \/><\/li>\n<p><\/p>\n<li><strong>Vulnerabilities in WTLS\/Secure WAP &#8211; also not end-to-end<br \/><\/strong>Most handsets implement WTLS (Wireless Transport Layer Security protocol). This is similar in intent to SSL, but with some bits chopped out to make it easier for phones to use with their limited memory and small CPU. Once the data gets to the <a href=\"https:\/\/www.orangepartner.com\/site\/enuk\/develop\/v_devcentre\/network_technologies\/wap\/p_wap.jsp#architecture\">WAP gateway<\/a> it is decrypted and then re-encrypted into an SSL\/HTTPS session to the destination server on the internet.<br \/>Unfortunately the protocol allows the use of <strong>very weak<\/strong>, or <strong>no encryption at all<\/strong> between the phone and the WAP gateway. There are several known cryptographic attacks on WTLS too, detailed <a href=\"https:\/\/www.jyu.fi\/%7Emjos\/wtls.pdf\">here<\/a>.<br \/>Worse, the data is all in plaintext within the WAP gateway i.e. this does not constitute end-to-end encryption &#8211; it relies on network engineers not to read or sell your data, unknown 3rd parties to maintain the server security, and defend the WAP gateway from compromise.\n<p>The risks of leaving your data in plaintext at the WAP gateway (or anywhere inside the mobile network) are wonderfully demonstrated by the recent revelations that hackers have gone undetected inside mobile networks for years &#8211; see stories of accidental discovery of long term hackers  in <a href=\"https:\/\/www.theregister.co.uk\/2007\/07\/11\/greek_mobile_wiretap_latest\/\">Vodafone Greece<\/a> and <a href=\"https:\/\/www.securityfocus.com\/news\/10271\">T-Mobile<\/a>, and also of network engineers <a href=\"https:\/\/www.theregister.co.uk\/2002\/11\/27\/sms_security_risks_highlighted_by\/\">snooping at user data<\/a> passing through their systems for romantic reasons.<\/p>\n<p>[<span style=\"font-weight: bold;\">Open question to readers, because I&#8217;m suspicious but not sure: <\/span>when using the default WAP Gateway, not an Internet Gateway, for your mobile data connection, are you able to use full end-to-end HTTPS or does the WAP\/UDP protocol drag everything down to WTLS? If it did, all your WAP based banking may well be clear-text in the Wap gateway.]<\/li>\n<\/ol>\n<p><span style=\"font-weight: bold;font-family:arial;\" >Q:<\/span><span style=\"font-family:arial;\"> What about <\/span><a style=\"font-family: arial;\" href=\"https:\/\/www.operamini.com\/help\/faq\/#security\">Opera Mini<\/a><span style=\"font-family:arial;\"> <\/span><span style=\"font-family:arial;\">&#8211; the advanced one for MIDP2 that has some security built in<\/span><span style=\"font-family:arial;\">, can&#8217;t we just do e-commerce through that?<\/span><\/p>\n<p><span style=\"font-weight: bold;font-family:arial;\" >A:<\/span><span style=\"font-family:arial;\"> It&#8217;s not <\/span><span style=\"font-weight: bold;font-family:arial;\" >end-to-end<\/span><span style=\"font-family:arial;\"> encrypted &#8211; so you have to trust Opera&#8217;s engineers, servers, sysadmins and maintenance contractors with your plain-text passwords and credit cards. Again they chose to use the <\/span><a style=\"font-family: arial;\" href=\"https:\/\/www.kb.cert.org\/vuls\/id\/565052\">RC4<\/a><span style=\"font-family:arial;\"> cipher of all things, which should be retired, not built into new products.<\/span><br \/><span style=\"font-family:arial;\">In good news though, they do seed their Random Number Generator correctly, which is disappointingly rare in mobile security.<\/span><\/p>\n<p><span style=\"font-weight: bold;font-family:arial;\" >Q:<\/span><span style=\"font-family:arial;\"> What about <\/span><span style=\"font-weight: bold;font-family:arial;\" >SMS<\/span><span style=\"font-family:arial;\"> &#8211; internet based hackers can&#8217;t see them, as they are all in the Mobile Network Operator&#8217;s walled gardens?<\/span><\/p>\n<p><span style=\"font-weight: bold;font-family:arial;\" >A:<\/span><span style=\"font-family:arial;\"> Same problems as WTLS, because <\/span><a style=\"font-family: arial;\" href=\"https:\/\/www.theregister.co.uk\/2002\/11\/27\/sms_security_risks_highlighted_by\/\">network engineers, 3rd party service technicians<\/a><span style=\"font-family:arial;\">, <\/span><a style=\"font-family: arial;\" href=\"https:\/\/http\/\/www.theregister.co.uk\/2007\/07\/11\/greek_mobile_wiretap_latest\">servers,<\/a> and base stations in the <a href=\"https:\/\/www.orangepartner.com\/site\/enuk\/develop\/v_devcentre\/network_technologies\/wap\/p_wap.jsp#architecture\">Mobile Networks<\/a> are not policed to <a style=\"font-family: arial;\" href=\"https:\/\/www.pcisecuritystandards.org\/tech\/\">PCI DSS<\/a><span style=\"font-family:arial;\"> standards (required for sending\/processing credit cards).<\/span><br \/><span style=\"font-family:arial;\">Additionally an SMS may not just be going through the UK networks that have familiar brand names. SMS&#8217;s are often transferred internationally across the Wild Wild Web through various companies that you have never heard of, and may originate or terminate in some very odd countries where you wouldn&#8217;t dream of leaving your credit card.<\/span><br \/><span style=\"font-family:arial;\">The infamous case of bored network engineers poking through other people&#8217;s MMS pictures of naked girlfriends (and forwarding them on) is nothing compared to what may happen when and if large amounts of credit card data start to get sent through SMS messages. After the case of O2 engineers abusing their access to SMS messages, analysts Gartner said <\/span><a style=\"font-style: italic; font-family: arial;\" href=\"https:\/\/www.theregister.co.uk\/2002\/11\/27\/sms_security_risks_highlighted_by\/\">&#8220;The contents of SMS messages are known to the network operator&#8217;s systems and personnel. Therefore, SMS is not an appropriate technology for secure communications. Most users do not realise how easy it may be to intercept&#8221;<\/a><span style=\"font-style: italic;font-family:arial;\" >.<\/span><br \/><span style=\"font-family:arial;\">If I was thinking like a hacker or spy, the first thing I would do is place logging hardware in a few base-stations, which see plenty of data passing through them. Lawyers, government ministers and top business people leak enough valuable information without throwing credit cards into the mix. It should also be pointed out that it is child&#8217;s play to  <\/span><a style=\"font-family: arial;\" href=\"https:\/\/www.google.co.uk\/search?q=sms+sender+anonymous\">fake the sender<\/a><span style=\"font-family:arial;\">  number of an SMS.<\/span><\/p>\n<p><span style=\"font-weight: bold;font-family:arial;\" >Q:<\/span><span style=\"font-family:arial;\"> What about the open source <\/span><a style=\"font-family: arial;\" href=\"https:\/\/www.bouncycastle.org\/java.html\">Bouncy Castle Light Crypto<\/a><span style=\"font-family:arial;\"> Libraries?<\/span><\/p>\n<p><span style=\"font-weight: bold;font-family:arial;\" >A: <\/span><span style=\"font-family:arial;\">A jolly good start, but they&#8217;re not THAT light. Adding a simple security system using Bouncy Castle with Asymmetric Key exchange, a Symmetric session cipher and a Random Number Generator (the bare minimum for secure comms) adds over 22Kb to the basic app, even after you&#8217;ve stripped unused code and obfuscated it. With the very oldest handsets having JAR size limits of 29Kb &#8211; such as the <\/span><a style=\"font-family: arial;\" href=\"https:\/\/www.forum.nokia.com\/devices\/6310i\">Nokia 6310i<\/a><span style=\"font-family:arial;\">, which despite its age is still very popular, people clinging to it like limpets and some major companies still issuing them NEW to their executives (we learned in a recent meeting).  Common MIDP1 handsets have 64Kb limits &#8211; Playtech saw more than 1 in 10 downloads go to these handsets in the first half of 2007, a substantial market share. Most of the work in mobile dev is making things small, and use as little memory as possible, so that you&#8217;ve got plenty of room for pictures and text and all that code that needs to glue it all together smoothly.<\/span><\/p>\n<hr  style=\"font-family:arial;\"><span style=\"font-family:arial;\">What a moaning session! I do apologise, but there&#8217;s no point beating about the bush.<\/span><\/p>\n<p style=\"font-family: arial;\"><strong>Solution: (a suggestion, not the only solution)<br \/><\/strong><\/p>\n<p><span style=\"font-family:arial;\">To reliably create encrypted sessions from mobile you have to build a truly lightweight encryption\/decryption system into your applications. This allows you to support every possible phone and also control the choice of cipher, the encryption strength, and eliminate certificate incompatibilities. It also allows you to encrypt data stored on the handset, SMS messages, or communication on other channels, which HTTPS and SSH do not.<\/span><\/p>\n<p style=\"font-family: arial;\">This is why <a href=\"http:\/\/localhost:10003\/\">Masabi <\/a>built <a href=\"http:\/\/localhost:10003\/techSecurity.html\">EncryptME<\/a>, a 3KB security component for J2ME that allows all phones to make encrypted connections over SMS, GPRS, WiFi or just about anything else. EncryptME is also US Government verified and certified, so you don&#8217;t have to take the our word for it that it does what it says on the tin. It provides 1024bit RSA, 256bit AES and an approved RNG, if you were wondering.<\/p>\n<p style=\"font-family: arial;\">Additionally, by being <a href=\"http:\/\/localhost:10003\/techSecurity.html#algorithms\">standards compliant<\/a> you can continue to use standard server cryptography components, for example those from Sun, Microsoft or our friends Bouncy Castle. Even against phones with built in SSL\/HTTPS, EncryptME is between 6 and 20 times faster on a mobile in live tests.<\/p>\n<p style=\"font-family: arial;\">And good choice of algorithms isn&#8217;t enough! You must use them in a wise way with user education, good seeding,  padding, key management, and protection against replays, insertions, concatenations, man in the middle, phishing and all manner of other attacks that cryptography alone will not solve &#8211; but that&#8217;s another story, to be entitled &#8220;When good crypto goes bad&#8221;.<\/p>\n<p style=\"font-family: arial;\"><strong>Good Examples:<\/strong><\/p>\n<ul style=\"font-family: arial;\">\n<li>Opera Mini Advanced: MIDP2 only, but has their own crypto with proper RNG seeding. Well done, apart from lack of end-to-end and use of RC4.<\/li>\n<p><\/p>\n<li>Playtech Online Casino: supports almost all MIDP phones, built in encryption, 1024bit RSA and 256bit AES, with player key-strokes during gameplay used to seed RNG.<\/li>\n<\/ul>\n<p style=\"font-family: arial;\"><strong>Bad Examples:<\/strong><\/p>\n<ul style=\"font-family: arial;\">\n<li>Opera Mini Basic: no encryption, but allows users to interact with their secure HTTPS banking sites while sending cleartext usernames, passwords or credit cards over the internet. To be fair they do admit it <a href=\"https:\/\/www.operamini.com\/help\/faq\/#enctyption\">here<\/a> with a good diagram.<\/li>\n<p><\/p>\n<li>Mobile java apps that rely on SSL or HTTPS &#8211; they won&#8217;t work in all cases, and slow down user interaction where they do work.\n<\/li>\n<li>Plaintext SMS apps which invite you to send Credit Cards or other sensitive data.\n<\/li>\n<li>Anything using &#8220;<a href=\"https:\/\/slashdot.org\/features\/980720\/0819202.shtml\">security through obscurity<\/a>&#8221; or &#8220;<a href=\"https:\/\/www.interhack.net\/people\/cmcurtin\/snake-oil-faq.html#SECTION00050000000000000000\">snake oil<\/a>&#8221; where they don&#8217;t reveal what they do to protect your data.<br \/>Also a special mention for the use of  the word &#8220;<span style=\"font-weight: bold;\">patented<\/span>&#8221; in security. It may help to raise a company&#8217;s valuation in the eyes of Venture Capitalists and investors, but to a cryptographer (or hacker) &#8220;patented&#8221; doesn&#8217;t mean safer, or correct, or even clever. It only really says that someone has sent it on a piece of paper to their local Patent Office and can be a good hint that very few people have had the chance to check it and test it, especially if this patented technology is only used by one or two companies.<br \/>In Java <a href=\"https:\/\/www.developer.com\/java\/article.php\/779831\">reverse compiling<\/a> (reverse engineering) end user applications is pretty straightforward, so the secrets will come out pretty quick as soon as someone takes an interest in your product.<\/li>\n<\/ul>\n<hr  style=\"font-family:arial;\"><span style=\"font-family:arial;\">I hope that gives you some idea about security on current generation mobiles. My next post will cover getting good <span style=\"font-weight: bold;\">Entropy <\/span>for your secure random number generator on mobile, a need highlighted in a timely fashion by Brian at <a href=\"https:\/\/mobilecrunch.com\/2007\/07\/13\/masabi-launches-world%E2%80%99s-first-mobile-java-security-app\/#comment-212223\">Mobile Crunch<\/a>.<\/span><\/p>\n<p><span style=\"font-weight: bold;font-family:arial;\" >Comments:<\/span><span style=\"font-family:arial;\"> there are no completely secure systems in the world, and security only gets better through challenging, discussion, testing, probing and questioning. Please post your questions or corrections if you have any, and I&#8217;ll do my best to respond, or correct mistakes\/omissions as they are pointed out.<br \/>Also please feel free to post good examples of clear and honest mobile security if you&#8217;ve seen some, but don&#8217;t be surprised if we start poking them and asking questions back at you!<\/span><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Mobile ticketing, m-commerce, secure messaging, corporate applications, government communications, e-money, the list goes on of things that would be great to do on mobile &#8211; as long as they really were secure. So, security on our phones, and we&#8217;d like to use publicly endorsed standards &#8211; 10 out of 10 security experts prefer it and [&hellip;]<\/p>\n","protected":false},"author":23,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[],"tags":[],"class_list":["post-12026","post","type-post","status-publish","format-standard","hentry"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.6 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Problems with Mobile Security #1 - Masabi<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.masabi.com\/it\/news\/problems-with-mobile-security-1\/\" \/>\n<meta property=\"og:locale\" content=\"it_IT\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Problems with Mobile Security #1 - Masabi\" \/>\n<meta property=\"og:description\" content=\"Mobile ticketing, m-commerce, secure messaging, corporate applications, government communications, e-money, the list goes on of things that would be great to do on mobile &#8211; as long as they really were secure. So, security on our phones, and we&#8217;d like to use publicly endorsed standards &#8211; 10 out of 10 security experts prefer it and [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.masabi.com\/it\/news\/problems-with-mobile-security-1\/\" \/>\n<meta property=\"og:site_name\" content=\"Masabi\" \/>\n<meta property=\"article:published_time\" content=\"2007-07-13T20:57:00+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2014-11-25T15:23:03+00:00\" \/>\n<meta property=\"og:image\" content=\"http:\/\/localhost:10003\/tech\/ssl.gif\" \/>\n<meta name=\"author\" content=\"Ben Whitaker\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Scritto da\" \/>\n\t<meta name=\"twitter:data1\" content=\"Ben Whitaker\" \/>\n\t<meta name=\"twitter:label2\" content=\"Tempo di lettura stimato\" \/>\n\t<meta name=\"twitter:data2\" content=\"11 minuti\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.masabi.com\\\/it\\\/news\\\/problems-with-mobile-security-1\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.masabi.com\\\/it\\\/news\\\/problems-with-mobile-security-1\\\/\"},\"author\":{\"name\":\"Ben Whitaker\",\"@id\":\"https:\\\/\\\/www.masabi.com\\\/it\\\/#\\\/schema\\\/person\\\/4e1cec25264fc99c9f550c98534911c5\"},\"headline\":\"Problems with Mobile Security #1\",\"datePublished\":\"2007-07-13T20:57:00+00:00\",\"dateModified\":\"2014-11-25T15:23:03+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.masabi.com\\\/it\\\/news\\\/problems-with-mobile-security-1\\\/\"},\"wordCount\":2261,\"image\":{\"@id\":\"https:\\\/\\\/www.masabi.com\\\/it\\\/news\\\/problems-with-mobile-security-1\\\/#primaryimage\"},\"thumbnailUrl\":\"http:\\\/\\\/localhost:10003\\\/tech\\\/ssl.gif\",\"inLanguage\":\"it-IT\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.masabi.com\\\/it\\\/news\\\/problems-with-mobile-security-1\\\/\",\"url\":\"https:\\\/\\\/www.masabi.com\\\/it\\\/news\\\/problems-with-mobile-security-1\\\/\",\"name\":\"Problems with Mobile Security #1 - Masabi\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.masabi.com\\\/it\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.masabi.com\\\/it\\\/news\\\/problems-with-mobile-security-1\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.masabi.com\\\/it\\\/news\\\/problems-with-mobile-security-1\\\/#primaryimage\"},\"thumbnailUrl\":\"http:\\\/\\\/localhost:10003\\\/tech\\\/ssl.gif\",\"datePublished\":\"2007-07-13T20:57:00+00:00\",\"dateModified\":\"2014-11-25T15:23:03+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/www.masabi.com\\\/it\\\/#\\\/schema\\\/person\\\/4e1cec25264fc99c9f550c98534911c5\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.masabi.com\\\/it\\\/news\\\/problems-with-mobile-security-1\\\/#breadcrumb\"},\"inLanguage\":\"it-IT\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.masabi.com\\\/it\\\/news\\\/problems-with-mobile-security-1\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"it-IT\",\"@id\":\"https:\\\/\\\/www.masabi.com\\\/it\\\/news\\\/problems-with-mobile-security-1\\\/#primaryimage\",\"url\":\"http:\\\/\\\/localhost:10003\\\/tech\\\/ssl.gif\",\"contentUrl\":\"http:\\\/\\\/localhost:10003\\\/tech\\\/ssl.gif\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.masabi.com\\\/it\\\/news\\\/problems-with-mobile-security-1\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.masabi.com\\\/it\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Problems with Mobile Security #1\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.masabi.com\\\/it\\\/#website\",\"url\":\"https:\\\/\\\/www.masabi.com\\\/it\\\/\",\"name\":\"Masabi\",\"description\":\"Making shared transport the first choice\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.masabi.com\\\/it\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"it-IT\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.masabi.com\\\/it\\\/#\\\/schema\\\/person\\\/4e1cec25264fc99c9f550c98534911c5\",\"name\":\"Ben Whitaker\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"it-IT\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/6fa351f31ab7475616403fff980bf8f434c7c56dd3d1f7d4f228b56e5dd486bd?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/6fa351f31ab7475616403fff980bf8f434c7c56dd3d1f7d4f228b56e5dd486bd?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/6fa351f31ab7475616403fff980bf8f434c7c56dd3d1f7d4f228b56e5dd486bd?s=96&d=mm&r=g\",\"caption\":\"Ben Whitaker\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Problems with Mobile Security #1 - Masabi","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.masabi.com\/it\/news\/problems-with-mobile-security-1\/","og_locale":"it_IT","og_type":"article","og_title":"Problems with Mobile Security #1 - Masabi","og_description":"Mobile ticketing, m-commerce, secure messaging, corporate applications, government communications, e-money, the list goes on of things that would be great to do on mobile &#8211; as long as they really were secure. So, security on our phones, and we&#8217;d like to use publicly endorsed standards &#8211; 10 out of 10 security experts prefer it and [&hellip;]","og_url":"https:\/\/www.masabi.com\/it\/news\/problems-with-mobile-security-1\/","og_site_name":"Masabi","article_published_time":"2007-07-13T20:57:00+00:00","article_modified_time":"2014-11-25T15:23:03+00:00","og_image":[{"url":"http:\/\/localhost:10003\/tech\/ssl.gif","type":"","width":"","height":""}],"author":"Ben Whitaker","twitter_card":"summary_large_image","twitter_misc":{"Scritto da":"Ben Whitaker","Tempo di lettura stimato":"11 minuti"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.masabi.com\/it\/news\/problems-with-mobile-security-1\/#article","isPartOf":{"@id":"https:\/\/www.masabi.com\/it\/news\/problems-with-mobile-security-1\/"},"author":{"name":"Ben Whitaker","@id":"https:\/\/www.masabi.com\/it\/#\/schema\/person\/4e1cec25264fc99c9f550c98534911c5"},"headline":"Problems with Mobile Security #1","datePublished":"2007-07-13T20:57:00+00:00","dateModified":"2014-11-25T15:23:03+00:00","mainEntityOfPage":{"@id":"https:\/\/www.masabi.com\/it\/news\/problems-with-mobile-security-1\/"},"wordCount":2261,"image":{"@id":"https:\/\/www.masabi.com\/it\/news\/problems-with-mobile-security-1\/#primaryimage"},"thumbnailUrl":"http:\/\/localhost:10003\/tech\/ssl.gif","inLanguage":"it-IT"},{"@type":"WebPage","@id":"https:\/\/www.masabi.com\/it\/news\/problems-with-mobile-security-1\/","url":"https:\/\/www.masabi.com\/it\/news\/problems-with-mobile-security-1\/","name":"Problems with Mobile Security #1 - Masabi","isPartOf":{"@id":"https:\/\/www.masabi.com\/it\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.masabi.com\/it\/news\/problems-with-mobile-security-1\/#primaryimage"},"image":{"@id":"https:\/\/www.masabi.com\/it\/news\/problems-with-mobile-security-1\/#primaryimage"},"thumbnailUrl":"http:\/\/localhost:10003\/tech\/ssl.gif","datePublished":"2007-07-13T20:57:00+00:00","dateModified":"2014-11-25T15:23:03+00:00","author":{"@id":"https:\/\/www.masabi.com\/it\/#\/schema\/person\/4e1cec25264fc99c9f550c98534911c5"},"breadcrumb":{"@id":"https:\/\/www.masabi.com\/it\/news\/problems-with-mobile-security-1\/#breadcrumb"},"inLanguage":"it-IT","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.masabi.com\/it\/news\/problems-with-mobile-security-1\/"]}]},{"@type":"ImageObject","inLanguage":"it-IT","@id":"https:\/\/www.masabi.com\/it\/news\/problems-with-mobile-security-1\/#primaryimage","url":"http:\/\/localhost:10003\/tech\/ssl.gif","contentUrl":"http:\/\/localhost:10003\/tech\/ssl.gif"},{"@type":"BreadcrumbList","@id":"https:\/\/www.masabi.com\/it\/news\/problems-with-mobile-security-1\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.masabi.com\/it\/"},{"@type":"ListItem","position":2,"name":"Problems with Mobile Security #1"}]},{"@type":"WebSite","@id":"https:\/\/www.masabi.com\/it\/#website","url":"https:\/\/www.masabi.com\/it\/","name":"Masabi","description":"Making shared transport the first choice","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.masabi.com\/it\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"it-IT"},{"@type":"Person","@id":"https:\/\/www.masabi.com\/it\/#\/schema\/person\/4e1cec25264fc99c9f550c98534911c5","name":"Ben Whitaker","image":{"@type":"ImageObject","inLanguage":"it-IT","@id":"https:\/\/secure.gravatar.com\/avatar\/6fa351f31ab7475616403fff980bf8f434c7c56dd3d1f7d4f228b56e5dd486bd?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/6fa351f31ab7475616403fff980bf8f434c7c56dd3d1f7d4f228b56e5dd486bd?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/6fa351f31ab7475616403fff980bf8f434c7c56dd3d1f7d4f228b56e5dd486bd?s=96&d=mm&r=g","caption":"Ben Whitaker"}}]}},"_links":{"self":[{"href":"https:\/\/www.masabi.com\/it\/wp-json\/wp\/v2\/posts\/12026","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.masabi.com\/it\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.masabi.com\/it\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.masabi.com\/it\/wp-json\/wp\/v2\/users\/23"}],"replies":[{"embeddable":true,"href":"https:\/\/www.masabi.com\/it\/wp-json\/wp\/v2\/comments?post=12026"}],"version-history":[{"count":0,"href":"https:\/\/www.masabi.com\/it\/wp-json\/wp\/v2\/posts\/12026\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.masabi.com\/it\/wp-json\/wp\/v2\/media?parent=12026"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.masabi.com\/it\/wp-json\/wp\/v2\/categories?post=12026"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.masabi.com\/it\/wp-json\/wp\/v2\/tags?post=12026"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}