securing_your_devices
Differences
This shows you the differences between two versions of the page.
Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
securing_your_devices [2019/08/08 17:18] – neil | securing_your_devices [2021/07/06 09:26] (current) – external edit 127.0.0.1 | ||
---|---|---|---|
Line 2: | Line 2: | ||
====Key points: ==== | ====Key points: ==== | ||
- | * [[#Use a privacy screen / shield on your devices|Use a privacy screen / shield on your devices]]Â | + | * [[securing_your_devices# |
- | * [[#Replace sensitive identifiers with pseudonyms|Replace sensitive identifiers with pseudonyms]]Â | + | * [[securing_your_devices#Use a privacy screen / shield on your devices|Use a privacy screen / shield on your devices]]Â |
- | * [[# | + | * [[securing_your_devices# |
- | * [[#Cover your webcam when you are not using it|Cover your webcam when you are not using it]]Â | + | * [[securing_your_devices# |
- | * [[# | + | * [[securing_your_devices#Replace sensitive identifiers with pseudonyms|Replace sensitive identifiers with pseudonyms]]Â |
- | * [[#Only install software / apps from trusted sources|Only install software / apps from trusted sources]]Â | + | * [[securing_your_devices#Don't charge from public USB ports|Don' |
- | * [[#Enable remote wipe functionality|Enable remote wipe functionality]]Â | + | * [[securing_your_devices# |
- | * [[#Check your privacy and location settings|Check your privacy and location settings]]Â | + | * [[securing_your_devices#Cover your webcam when you are not using it|Cover your webcam when you are not using it]]Â |
- | * [[#Install software updates promptly|Install software updates promptly]]Â | + | * [[securing_your_devices#Disconnect your microphone or at least try to get a notification when it turns on|Disconnect your microphone or at least try to get a notification when it turns on]]Â |
- | * [[#Keep a log of your key software, and alternative options|Keep a log of your key software, and alternative options]] | + | * [[securing_your_devices#Only install software / apps from trusted sources|Only install software / apps from trusted sources]]Â |
+ | * [[securing_your_devices#Check what permissions your software is requesting|Check what permissions your software is requesting]]Â | ||
+ | * [[securing_your_devices#Enable remote wipe functionality|Enable remote wipe functionality]]Â | ||
+ | * [[securing_your_devices#Install software updates promptly|Install software updates promptly]]Â | ||
+ | * [[securing_your_devices#Keep a log of your key software, and alternative options|Keep a log of your key software, and alternative options]]Â | ||
+ | Â | ||
+ | ====Use strong passwords ===Â | ||
+ | Â | ||
+ | Whether you have a computer with a traditional password, or a mobile device with a PIN, make sure the password or PIN you use to login to your device is [[passwords|strong]]. Same applies for all passwords for your online services. | ||
====Use a privacy screen / shield on your devices==== | ====Use a privacy screen / shield on your devices==== | ||
Line 30: | Line 38: | ||
Most computer privacy screens come with sticky tabs, so you can drop them into place easily. | Most computer privacy screens come with sticky tabs, so you can drop them into place easily. | ||
+ | |||
+ | ====Put contact details on your device' | ||
+ | |||
+ | {{:: | ||
+ | |||
+ | If you lose your device, you can increase the chances of getting it back by putting your contact details on your device' | ||
+ | |||
+ | You could also state that it contains legally privileged information, | ||
+ | |||
+ | ===iOS === | ||
+ | * Create a custom wallpaper of the right size for your device, containing the information you want (perhaps an email address or phone number (but not a phone number which only rings the device in question!)) | ||
+ | * Transfer it to your device (e.g. AirDrop, or email, or iTunes file transfer) | ||
+ | * Make it your device' | ||
+ | |||
+ | ===macOS === | ||
+ | |||
+ | * System Preferences / Security & Privacy | ||
+ | |||
+ | ====Limit what is shown on your lock screen ==== | ||
+ | |||
+ | Many applications will let you preview messages when your device is locked — for example, the content of a text message, or the first line or two of an email. | ||
+ | |||
+ | If you lose your device, someone can still see information about you or your clients. | ||
+ | |||
+ | In particular, if you use your phone for [[two-factor_authentication|two-factor authentication]] via a message, if that message pops up on the lock screen, someone who has stolen or found your phone would see that code. | ||
+ | |||
+ | ====Enable auto-wipe ==== | ||
+ | |||
+ | If your device offers it, set it up to wipe automatically after sufficient incorrect password entries. However, make sure you take regular backups, as an annoyed child or curious toddler could, if left alone with your phone, wipe your device. | ||
+ | |||
+ | ===iOS === | ||
+ | |||
+ | * Settings / Face ID & Passcode / Erase Data | ||
====Replace sensitive identifiers with pseudonyms==== | ====Replace sensitive identifiers with pseudonyms==== | ||
Line 54: | Line 95: | ||
===Device-based protection === | ===Device-based protection === | ||
+ | |||
+ | {{:: | ||
Recent versions of the iOS software require you to put in your passcode before " | Recent versions of the iOS software require you to put in your passcode before " | ||
+ | ====Only use your own cables==== | ||
+ | |||
+ | Although a cable may seem harmless, some cables are small computers in their own right, and some contain enough space in the housing (the plastic bits covering the connectors) to contain a malicious computer, which attempts to access your computer or phone when you connect it. (For example, see [[https:// | ||
+ | |||
+ | Some even contain tiny microphones, | ||
+ | |||
+ | Only use your own cables — do not borrow cables to charge your device — and, if you need a replacement cable, get it from a trusted source. | ||
==== Cover your webcam when you are not using it ==== | ==== Cover your webcam when you are not using it ==== | ||
Line 97: | Line 147: | ||
For example, for macOS or iOS, this is Apple' | For example, for macOS or iOS, this is Apple' | ||
- | ====Check | + | If you do want to install software from outside a trusted source — and there is lots of great software which is not available through app stores — consider testing it on a spare machine first, and consider looking at its network traffic, to see if it is phoning home unnecessarily, |
+ | ====Check | ||
When you install software, it may request your permission to access certain data or functionality of your device. For example, it might ask to access your address book, or to use your location. | When you install software, it may request your permission to access certain data or functionality of your device. For example, it might ask to access your address book, or to use your location. | ||
Line 112: | Line 163: | ||
====Enable remote wipe functionality==== | ====Enable remote wipe functionality==== | ||
- | If the facility is available to you, set it up. Learn how to use it. Ideally, set up a test device and run through the process of wiping it. Write down what you did, and keep copies of that somewhere accessible. | ||
- | Routinely check it is up to date. | + | If remote wipe functionality |
- | Probably have a monthly compliance checklist, of things you do each month to check your firm is running in a healthy manner: add this to the list. | + | Ideally, set up a test device and run through |
- | You’re hoping that you’ll never have to use it, of course, but the last thing you want to be doing is panicking about how you do that remote wipe thing if you lose a device: follow a tested procedure, with which you are familiar. | + | Remote wipe requires communication |
- | ==== Check your privacy and location settings====Â | + | Because of this, make sure you have a [[securing_your_computer# |
- | Which applications | + | |
- | Often very granular, precise location data. | ||
- | For example, you may have your iPhone set to include location in all images that you take. | + | ====Install software updates promptly==== |
- | Take a look in Settings | + | Responsible developers fix security problems |
+ | Â | ||
+ | There is a balance between security and usability, and software updates may break software functionality. So while the [[https://www.ncsc.gov.uk/ | ||
+ | Â | ||
+ | Before you install a major update | ||
+ | Â | ||
+ | ===Enable auto-update if there is a low risk of incompatibility ===Â | ||
+ | Â | ||
+ | For devices where an update is unlikely to break your workflow — perhaps your mobile device — consider enabling auto-update. That way, you never need to think about installing software updates yourself. | ||
- | ====Install software updates promptly==== | ||
- | Balance between security and usability | ||
- | Software updates may break software functionality: | ||
- | So I tend to wait and see what other users experience when Apple releases a new software update before applying it to my machine. | ||
====Keep a log of your key software, and alternative options ==== | ====Keep a log of your key software, and alternative options ==== | ||
- | Worth keeping a log of what software you rely on, and identifying an alternative so that, if your chosen software suddenly became unavailable, | ||
- | May make you shy away from file types which can only be opened | + | From a business continuity perspective, |
+ | Â | ||
+ | Your fallback may not be perfect, but it should keep you working rather than panicking. | ||
+ | Â | ||
+ | By the same token, be aware of locking yourself |
securing_your_devices.1565284695.txt.gz · Last modified: 2021/07/06 09:26 (external edit)