Now on Demand Ransomware Resilience & Recovery Summit - All Sessions Available
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Mobile & Wireless

NSA Layers Commercial Technology to Develop Secure Smartphone on Android Platform

RSA Conference News

RSA CONFERENCE 2012 – Starting with Android and a handset from Motorola, the National Security Agency (NSA) said they have essentially taken offerings from column A and some from column B and come up with an idea for a secure smartphone.

RSA Conference News

RSA CONFERENCE 2012 – Starting with Android and a handset from Motorola, the National Security Agency (NSA) said they have essentially taken offerings from column A and some from column B and come up with an idea for a secure smartphone.

“Project Fishbowl”, which is what the NSA is calling their initiative, seeks to develop a solidly secure smartphone, using commercially available designs and technology on the Android platform. The plan, the agency’s Margaret Salter explained, is to build the phone using off-the-shelf technology, strip out the unneeded components, and layer the protections in a way that lowers the attack surface.

NSA Logo“There are vulnerabilities in every OS,” Salter said during a talk at the RSA Conference last week, “The beauty of our strategy is that we looked at all of the components, and then took stuff out of the OS we didn’t need. This makes the attack surface very small.”

Android was selected over Apple’s iOS, Salter noted, not because there wasn’t any value in it, but that iOS didn’t have the controls needed. It’s just that Android allowed the NSA to make the modifications they wanted for this first generation of secure devices. In the future, Android will not be the only platform that the agency will use. At the show, while it was disclosed that Motorola made the handset being tested, the actual spec and model was kept out of the picture.

Developer Resource: 2011 Device Developers’ Security Report

The NSA is opening up the Fishbowl project, and the public website for it contains the draft release of the Secure Voice over IP (SVoIP) for the Enterprise Mobility Architecture.

“As a first step, this version contains guidance on the required procedures necessary to build and implement a SVoIP capability using commercial grade cellular mobile devices. Future releases will build on this architecture and will include mobile device management and data applications; and ultimately integrate the Wi-Fi service with an expanded list of end devices,” the overview explains.

Still in the development stages, Fishbowl hopes to set the standard for government and private sector mobile security. “…our hope is someone will show this to the vendors and say ‘I want that,’” Salter said.

Related: Department of Defense Makes Move Towards Android

Advertisement. Scroll to continue reading.
Written By

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Bill Dunnion has joined telecommunications giant Mitel as Chief Information Security Officer.

MSSP Dataprise has appointed Nima Khamooshi as Vice President of Cybersecurity.

Backup and recovery firm Keepit has hired Kim Larsen as CISO.

More People On The Move

Expert Insights

Related Content

Malware & Threats

Apple’s cat-and-mouse struggles with zero-day exploits on its flagship iOS platform is showing no signs of slowing down.

Mobile & Wireless

Samsung smartphone users warned about CVE-2023-21492, an ASLR bypass vulnerability exploited in the wild, likely by a spyware vendor.

Mobile & Wireless

Infonetics Research has shared excerpts from its Mobile Device Security Client Software market size and forecasts report, which tracks enterprise and consumer security client...

Fraud & Identity Theft

A team of researchers has demonstrated a new attack method that affects iPhone owners who use Apple Pay and Visa payment cards. The vulnerabilities...

Mobile & Wireless

Critical security flaws expose Samsung’s Exynos modems to “Internet-to-baseband remote code execution” attacks with no user interaction. Project Zero says an attacker only needs...

Mobile & Wireless

Apple rolled out iOS 16.3 and macOS Ventura 13.2 to cover serious security vulnerabilities.

Mobile & Wireless

Two vulnerabilities in Samsung’s Galaxy Store that could be exploited to install applications or execute JavaScript code by launching a web page.

Mobile & Wireless

Asus patched nine WiFi router security defects, including a highly critical 2018 vulnerability that exposes users to code execution attacks.