Skip Links

Network World

  • Social Web 
  • Email 
  • Close

Mobile users face knotty security issues

By John Cox , Network World , 07/17/2006
Newsletter Signup
  • Share/Email
  • Tweet This
  • Comment
  • Print

High-profile security breaches may indicate that network executives are using trial and error to sort out the best ways to secure the brave new world of mobile computing.

In May, headlines blared that personal data on 26 million U.S. military personnel and veterans was at risk after a laptop was stolen from the home of a Department of Veteran Affairs employee.

Last month, the Federal Trade Commission contacted 110 people to tell them that two laptops containing their personal data were stolen from a locked vehicle. The group included defendants in current and past FTC cases.

These and a growing number of similar events show that secure mobile computing is a complex business. The physical devices themselves have to be protected, along with the data stored on them, the users and the network connections, especially wireless.

But network professionals walk a tight rope here. If security measures are unnecessarily strict, they're not cost effective for the enterprise. More importantly, users faced with needlessly complex or burdensome measures may ignore or bypass them.

A recent report by InfoTech, a unit of Telecom Intelligence Group, Parsippany, N.J., identified a variety of wireless security challenges:

Mobile client devices can be lost or stolen and then hacked;

Wireless networking creates an “open door” to the corporate net, and wireless data can be intercepted;

All of the elements — device, data, user, network — have to be secured to avoid a weak link;

Doing so adds costs and complexity, and may require changes to applications;

Experts speak

Tackling the complexity of securing mobile users is a work in progress, based on interviews with several network professionals.

Resurgens Orthopaedics, a leading U.S. orthopedic practice based in Atlanta, has more than 300 doctors and clinical staff using either Toshiba tablets or HP iPaq PDAs to gain access to a fully electronic patient medical records over a Cisco wireless LAN.

Initially, in mid-2005, the practice relied on a Cisco security protocol that included the Lightweight Extensible Authentication Protocol (LEAP) for user authentication. But LEAP proved cumbersome to IT staff and users. Physicians had to remember at least two logon combinations, and support staff constantly had to reset access points or user devices, says Vinnie Greaves, Resurgens’ CTO.

  • Share/Email
  • Tweet This
  • Comment
  • Print
Comments (1)
Login
Forgot your account info?

Securing mobile devices with micro-programs on the chipBy Anonymous on May 9, 2007, 11:18 amThe devices could be programmed with OEM micro-programs embedded in the memory chip that provide algorithms monitoring patterns of behavior. Re: Mobile users...

Reply | Read entire comment

View all comments

Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed