Think your phone is safe? From sideloaded apps and spoofed software to malware and data leaks, mobile devices face real threats. In this video, you’ll learn how to identify and troubleshoot common security issues on mobile devices—exactly what you need to know for the CompTIA A+ Core 2 (220-1202) exam.
From the course: Software Troubleshooting for CompTIA A+ Core 2 (220-1202)
Watch my 100+ courses on Pluralsight
Video Summary
- Data Usage Limits: Set data warnings and limits on your device to avoid unexpected charges. Align these settings with your billing cycle for better management.
- Performance Issues: If your phone or apps are slow, try restarting your device and updating your software. Persistent issues might require a malware scan or a factory reset.
- Internet Connectivity Problems: Check basic settings like airplane mode and APN configurations. Malware might block internet access, so always run a malware scan if issues persist.
- Increased Ads: A surge in ads can indicate malware. Avoid clicking on suspicious ads and never install anything from pop-ups or notifications.
- Personal Data Breaches: If hackers access your personal data, immediately run a malware scan, identify the compromised app or site, and consider a factory reset. Change your passwords across all services.
For more information, read the transcript blog below, or watch the video above!
Transcript
Our phones store everything: messages, photos, passwords, but security threats are always lurking. Let’s deep dive into troubleshooting security issues on mobile devices, starting with the dangers of unofficial apps and rooted devices. As we have seen in previous demos, mobile devices do not give you direct access to the root operating system. They lock you into the experience that the manufacturer wants you to use, at least by default. However, as with every electronic device, there is a way to go around it. On Android devices, it’s called rooting, and on Apple devices, it’s called jailbreaking.
You might be wondering why people do it. One of the big reasons is being able to install applications from unofficial app stores. Another reason is to have full control of the device, whether it’s for customization, performance optimizations, or uninstalling some apps that came with the device. However, there are risks associated with doing it. First, it could void the warranty for some manufacturers. From a security point of view, apps from unofficial app stores can contain malware. Each phone and tablet manufacturer has their own way of checking if a device has been rooted or jailbroken. On my Samsung phone, I can go to see the device information, and if you see “official” under the phone status, it means you are good. But if you see “custom,” it means that it’s rooted. The best way to know is always to check the manufacturer’s documentation.
Another way to have more access is developer mode, which is a way for developers to test their app on a device. This gives the user access to some additional features such as faking the current geolocation, installing an app from an app package, deploying it directly from your laptop, or debugging via USB. The capabilities will depend on the device. Now, let’s talk about sideloading. Sideloading refers to installing apps on a device from an unofficial store. This is done differently depending on the operating system. For example, at the time of recording this course, only Apple devices in the European Union could sideload apps, but this can change in the future. For Android, it was always available. You simply download the APK file and then install it on your device. Remember that sideloading apps bypasses all the security and privacy features implemented by the manufacturer, so it’s very important to only install apps from trusted sources.
Continuing about apps, one risk we have these days is application spoofing. This is when you install what appears to be a legitimate app with high-ranking reviews, but it turns out to be a malicious application or an app that simply shows ads and does nothing useful. There is a recent trend where malicious actors create simple applications that do what they’re supposed to do and get them to rank high. It’s usually simple apps like a flashlight, camera filters, games, or QR scanners. After the app makes it to the top, they update the app to only show ads or add malware.
Let’s take a look at an example of sideloading apps. I recently bought a new camera, an Osmo Pocket, and started looking for the app to control it, but I couldn’t find it in the Play Store. I looked at the manufacturer’s website and saw that for Android, they provide it as an APK file. This is an example where DJI, a well-known brand for drones and cameras, provides the official app not available in the Play Store, so I needed to sideload it. I clicked the download Android APK file, and since I already had it, I clicked on the one I downloaded, and it asked if I wanted to install the app. I clicked install, and it was as easy as that. However, some devices do not allow this. For example, on my Samsung, I needed to allow apps downloaded from Chrome to be installed. I recommend turning this setting off after you use it to prevent malware from installing new apps without your knowledge.
The first step in fixing a problem is knowing that it exists. Let’s look at the signs that a mobile device might be compromised. You might see unusually high network traffic from an application, which might indicate something is wrong. It could be a bug or malware transferring data. Use built-in reports to investigate data usage, and if unsure, run a malware scan. You might also see a data usage limit notification. Most devices allow you to set a data limit and a warning to avoid big bills. Configure these settings to align with your billing cycle.
You might see degraded response time on your apps and phone. This can be caused by many things. Try restarting the phone and updating the operating system and apps. If it continues, run a malware scan or reset the phone to factory settings. Limited or no internet connectivity can also be a sign. Check if the phone is in airplane mode, and verify cellular settings like APN and roaming. Try connecting to Wi-Fi. Malware might block internet access to prevent you from removing it. Always run a malware scan if you suspect anything.
An increased number of ads is almost always malware. Bad actors make money by showing ads and more when you click on them. Some malware focuses on showing or replacing ads. Avoid clicking on suspicious ads and never install anything from pop-ups. If an app starts acting weird, displaying ads, asking for extra information, or using a lot of battery or data, check the app store for similar issues. Uninstall the app and monitor your phone and passwords.
Finally, if hackers access your personal data, determine the cause and fix it immediately. Run a malware scan, identify the compromised app or site, and consider a factory reset. Change your passwords across all services. For antivirus apps, use the one your enterprise already uses. Most devices have built-in ways to scan apps. On Android, you can use Play Protect, which scans all apps, including those installed from APK files. Manufacturers also provide ways to scan for viruses and malware.
Remember, mobile phones can have viruses too. Work with your enterprise admin to ensure all devices are monitored and protected. Protect your personal devices as well.