Mobile Device Security Checklist
Intro¶
For many of us, smart phones are our primary means of communication, entertainment and access to knowledge. But while they’ve brought convenience to a whole new level, there’s some ugly things going on behind the screen. Geo-tracking is used to trace our every move, and we have little control over who has this data - your phone is even able to track your location without GPS. Using a smart phone generates a lot of data about you - from information you intentionally share, to data silently generated from your actions.
Checklist¶
Essential Activities¶
-
Set a Strong Passcode
Priority: Essential
Use at least a 6-digit PIN or, preferably, an alphanumeric password. Avoid simple patterns or 4-digit PINs. This will mean if your device is lost or stolen, no one will have access to your data. -
Turn off Connectivity Features that Aren't Being Used
Priority: Essential
When you're not using WiFi, Bluetooth, NFC etc, turn those features off. There are several common threats that utilise these features. -
Keep OS Updated
Priority: Essential
Install iOS or Android security updates as soon as they are released to patch vulnerabilities. -
Keep App Count to a Minimum
Priority: Essential
Uninstall apps that you don't need or use regularly. Apps often run in the background, slowing your device down and collecting data. -
Review App Permissions
Priority: Essential
Don't grant apps permissions that they don't need. Review what each app has access to and revoke anything unnecessary. -
Only Install Apps from Official Sources
Priority: Essential
Applications on Apple App Store and Google Play Store are scanned and cryptographically signed, making them less likely to be malicious.
Basic Activities¶
- Enable Biometrics Carefully
Priority: Basic
Use TouchID/FaceID for convenience, but know that in some jurisdictions, you can be legally compelled to provide a fingerprint but not a password.
Optional Activities¶
-
Use Offline Maps
Priority: Optional
Consider using an offline maps app, such as OsmAnd or Organic Maps, to reduce data leaks from map apps. -
Opt-out of Personalized Ads
Priority: Optional
You can slightly reduce the amount of data collected by opting-out of seeing personalized ads in your device settings. -
Restart Device Regularly
Priority: Optional
Restarting your phone at least once a week will clear the app state cached in memory. When crossing borders, you may also want to shut down your device. -
Avoid Public Charging Stations
Priority: Optional
Use your own power brick or a USB data blocker to prevent juice jacking malware attacks via public USB charging ports.