Friday 25 April 2014

My heart doesn't bleed. I have Secure Spaces!

The pervasive use of the OpenSSL libraries in Android apps, mostly gaming apps, has seen a disproportionate amount of attention placed on Android for failing to prevent the Heartbleed attack. A recent report ( http://au.ibtimes.com/articles/549464/20140424/google-android-play-store-heartbleed-bug-security.htm#.U1pbA_ldV8E ) with research from FireEye states that nearly 150 million Android app downloads were vulnerable to the Heartbleed bug. 

Adding to this disturbing fact is that of 17 apps created to detect the Heartbleed issue, 6 of those apps did not include sufficient techniques to accurately detect the bug. 

The report goes on to state that while many apps do not have direct access to banking or credit card information those gaming apps do typically have cross-linked authentication to Google, Facebook, Twitter or other social media apps that may have access to other important credentials.

With Secure Spaces I maintain a "quarantine" Space into which I place all of my newly downloaded apps. I have anti-malware tools in my quarantine Space that let me scan those apps and other apps that let me review all of the permissions and resources used by the downloaded app. Once I am satisifed I can then use the App Manager in Secure Spaces to move the app to my Open Space or another personal Space.

Even if I didn't use a quarantine Space (I am a bit of a geek) by simply placing the newly downloaded app into a personal Space or Open Space that does not have any contacts records, no access to my email or other critical information I can prevent a malicious app, even with the Heartbleed bug, from doing any real damage. Secure Spaces allows me to isolate my important information that I need from the neat apps that I want and lets me do it all on one device.