the privacy cockpit for smartphones · mobile devices smartphones handle information: generate...

19
The Privacy Cockpit for Smartphones Configuration of Data Secrecy made easy Thomas Maier, Jörn-Marc Schmidt, Lukasz Kubik, Thomas Mohnhaupt, Corinna Lingstädt secunet Security Networks AG

Upload: others

Post on 19-Aug-2020

1 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: The Privacy Cockpit for Smartphones · Mobile Devices Smartphones handle Information: Generate Store Process and Share data. Who knows about / controls the data flow?

The Privacy Cockpit for SmartphonesConfiguration of Data Secrecy made easy

Thomas Maier, Jörn-Marc Schmidt, Lukasz Kubik, Thomas Mohnhaupt, Corinna Lingstädt

secunet Security Networks AG

Page 2: The Privacy Cockpit for Smartphones · Mobile Devices Smartphones handle Information: Generate Store Process and Share data. Who knows about / controls the data flow?

Mobile Devices

Smartphones handle Information:

Generate

Store

Process and

Share data.

Who knows about / controls the data flow?

Page 3: The Privacy Cockpit for Smartphones · Mobile Devices Smartphones handle Information: Generate Store Process and Share data. Who knows about / controls the data flow?

of users would pay for privacy

Page 4: The Privacy Cockpit for Smartphones · Mobile Devices Smartphones handle Information: Generate Store Process and Share data. Who knows about / controls the data flow?

Data Protection

Privacy Protection of Business Data

Page 5: The Privacy Cockpit for Smartphones · Mobile Devices Smartphones handle Information: Generate Store Process and Share data. Who knows about / controls the data flow?

Data Protection

Mobile Device Management

Protecting (company) data

Central configuration

Policies defined by experts

Requires appropriate infrastructure

Manual Configuration

Page 6: The Privacy Cockpit for Smartphones · Mobile Devices Smartphones handle Information: Generate Store Process and Share data. Who knows about / controls the data flow?

„MDM: Enterprises-Only“ - ?

Page 7: The Privacy Cockpit for Smartphones · Mobile Devices Smartphones handle Information: Generate Store Process and Share data. Who knows about / controls the data flow?

„MDM for Everyone“

Page 8: The Privacy Cockpit for Smartphones · Mobile Devices Smartphones handle Information: Generate Store Process and Share data. Who knows about / controls the data flow?

The Privacy Cockpit

Privacy Cockpit Web-Portal

YOP-App(YourOwnPrivacy)

Page 9: The Privacy Cockpit for Smartphones · Mobile Devices Smartphones handle Information: Generate Store Process and Share data. Who knows about / controls the data flow?

Privacy Cockpit Web Portal

Awareness

Explain risks

Dos & don’ts

Expert know-how

Explain possibilities

Discus impact of solutions

Pre-configured rule-Sets

Device configuration

Page 10: The Privacy Cockpit for Smartphones · Mobile Devices Smartphones handle Information: Generate Store Process and Share data. Who knows about / controls the data flow?

Impact on Privacy

The user

Is informed about risks and solutions

Is able to make well-grounded decisions

Is in control of the policies

Easy generation of policies

Starting with pre-defined policies

Relying on knowledge of an expert database

Adapting policies

Page 11: The Privacy Cockpit for Smartphones · Mobile Devices Smartphones handle Information: Generate Store Process and Share data. Who knows about / controls the data flow?

Impact on BYOD

The user configures his phone

Privacy Cockpit certifies security level

based on the user‘s configuration

Company decides whether to allow access

based on the certificate

Trust in the Privacy Cockpit as third party

Company must be informed about changes

Page 12: The Privacy Cockpit for Smartphones · Mobile Devices Smartphones handle Information: Generate Store Process and Share data. Who knows about / controls the data flow?

HOW COULD IT LOOK LIKE?

Page 13: The Privacy Cockpit for Smartphones · Mobile Devices Smartphones handle Information: Generate Store Process and Share data. Who knows about / controls the data flow?

„Work Flow“

Page 14: The Privacy Cockpit for Smartphones · Mobile Devices Smartphones handle Information: Generate Store Process and Share data. Who knows about / controls the data flow?

Configuration of Policies

Page 15: The Privacy Cockpit for Smartphones · Mobile Devices Smartphones handle Information: Generate Store Process and Share data. Who knows about / controls the data flow?

Configuration of Policies

Page 16: The Privacy Cockpit for Smartphones · Mobile Devices Smartphones handle Information: Generate Store Process and Share data. Who knows about / controls the data flow?

Limits

Restricted OS APIs

No access to low-level features

System app are excluded

Page 17: The Privacy Cockpit for Smartphones · Mobile Devices Smartphones handle Information: Generate Store Process and Share data. Who knows about / controls the data flow?

Next Steps

“Blur” requested data

One-time rights

Complex rule-sets

Analytics of data/sensor access

Page 18: The Privacy Cockpit for Smartphones · Mobile Devices Smartphones handle Information: Generate Store Process and Share data. Who knows about / controls the data flow?

Privacy & BYOD: A „Hot-Topic“

Data protection:

Private information

Business data

On lost phones

Awareness!

Usability-concept

The OS is the limit

“Certificates” for BYOD

Page 19: The Privacy Cockpit for Smartphones · Mobile Devices Smartphones handle Information: Generate Store Process and Share data. Who knows about / controls the data flow?

The Privacy Cockpit for SmartphonesConfiguration of Data Secrecy made easy

Thomas Maier, Jörn-Marc Schmidt, Lukasz Kubik, Thomas Mohnhaupt, Corinna Lingstädt

[email protected]

secunet Security Networks AG