Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Mobile & Wireless

NSA Layers Commercial Technology to Develop Secure Smartphone on Android Platform

RSA Conference News

RSA CONFERENCE 2012 – Starting with Android and a handset from Motorola, the National Security Agency (NSA) said they have essentially taken offerings from column A and some from column B and come up with an idea for a secure smartphone.

RSA Conference News

RSA CONFERENCE 2012 – Starting with Android and a handset from Motorola, the National Security Agency (NSA) said they have essentially taken offerings from column A and some from column B and come up with an idea for a secure smartphone.

“Project Fishbowl”, which is what the NSA is calling their initiative, seeks to develop a solidly secure smartphone, using commercially available designs and technology on the Android platform. The plan, the agency’s Margaret Salter explained, is to build the phone using off-the-shelf technology, strip out the unneeded components, and layer the protections in a way that lowers the attack surface.

NSA Logo“There are vulnerabilities in every OS,” Salter said during a talk at the RSA Conference last week, “The beauty of our strategy is that we looked at all of the components, and then took stuff out of the OS we didn’t need. This makes the attack surface very small.”

Android was selected over Apple’s iOS, Salter noted, not because there wasn’t any value in it, but that iOS didn’t have the controls needed. It’s just that Android allowed the NSA to make the modifications they wanted for this first generation of secure devices. In the future, Android will not be the only platform that the agency will use. At the show, while it was disclosed that Motorola made the handset being tested, the actual spec and model was kept out of the picture.

Developer Resource: 2011 Device Developers’ Security Report

The NSA is opening up the Fishbowl project, and the public website for it contains the draft release of the Secure Voice over IP (SVoIP) for the Enterprise Mobility Architecture.

“As a first step, this version contains guidance on the required procedures necessary to build and implement a SVoIP capability using commercial grade cellular mobile devices. Future releases will build on this architecture and will include mobile device management and data applications; and ultimately integrate the Wi-Fi service with an expanded list of end devices,” the overview explains.

Still in the development stages, Fishbowl hopes to set the standard for government and private sector mobile security. “…our hope is someone will show this to the vendors and say ‘I want that,’” Salter said.

Advertisement. Scroll to continue reading.

Related: Department of Defense Makes Move Towards Android

Written By

Click to comment

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

SecurityWeek’s Threat Detection and Incident Response Summit brings together security practitioners from around the world to share war stories on breaches, APT attacks and threat intelligence.

Register

Securityweek’s CISO Forum will address issues and challenges that are top of mind for today’s security leaders and what the future looks like as chief defenders of the enterprise.

Register

Expert Insights

Related Content

Mobile & Wireless

Infonetics Research has shared excerpts from its Mobile Device Security Client Software market size and forecasts report, which tracks enterprise and consumer security client...

Mobile & Wireless

Apple rolled out iOS 16.3 and macOS Ventura 13.2 to cover serious security vulnerabilities.

Mobile & Wireless

Critical security flaws expose Samsung’s Exynos modems to “Internet-to-baseband remote code execution” attacks with no user interaction. Project Zero says an attacker only needs...

Mobile & Wireless

Technical details published for an Arm Mali GPU flaw leading to arbitrary kernel code execution and root on Pixel 6.

Mobile & Wireless

Two vulnerabilities in Samsung’s Galaxy Store that could be exploited to install applications or execute JavaScript code by launching a web page.

Mobile & Wireless

The February 2023 security updates for Android patch 40 vulnerabilities, including multiple high-severity escalation of privilege bugs.

Mobile & Wireless

Apple’s iOS 12.5.7 update patches CVE-2022-42856, an actively exploited vulnerability, in old iPhones and iPads.

Cybercrime

A digital ad fraud scheme dubbed "VastFlux" spoofed over 1,700 apps and peaked at 12 billion ad requests per day before being shut down.