Main menu

Pages

If you want to prevent your phone from being hacked, you better do this thing

Every once in a while, I have to dive back into the waters of mobile security and offer users a hard truth to swallow. More often than not, these truths are pretty easy to accept, like never installing software unless it’s in your ecosystem’s app store (Google Play Store and iOS App Store), using a password manager password or always make sure to keep both apps and the operating system updated.

Also: Top Phone Security Threats in 2022 and How to Avoid Them

Anyone can follow these best practices. They are simple, harmless and require very little effort from the user.

But there are other best practices that aren’t as easy to follow. Unfortunately, IT admins have had to constantly remind end users not to do certain things for years. And yet they still happen. No matter how adamant the IT admin is or no matter what the consequences of an action, end users continue to ignore these warnings, only to end up having to turn to IT to fix the issues.

When you’re dealing with your own personal device, you may not have an IT department to turn to. When this happens, you may need to go to your carrier and pay the cost of restoring your device to working condition (which could be expensive) or performing a factory restore (which may or may not fix the problem. ). And then you may have fallen prey to a ransomware attack, at which point all bets are off. Even if you can perform a factory restore, your data could be kept under threat of publication if you don’t pay.

You don’t want that.

And that’s probably where my most important piece of advice comes in, when it comes to mobile security and it can be summed up in one simple sentence.

If in doubt…don’t.

I have a very dear friend who calls me regularly with questions like “I received this SMS. I don’t know the sender. Should I click on the link?”

The answer, unequivocally, is always a resounding “no”! I then remind that person that if they don’t know the sender of an email, text message, Facebook Messenger message, Whatsapp communication, etc., they shouldn’t open it. , touch, click, copy, respond to, or otherwise interact with it.

And this is the heart of this problem.

So many users (and even publications) who very quickly want to blame the companies that provide mobile operating systems and/or mobile applications. Not only is this not fair, but it is also not helpful. You see, just like in desktop and laptop computers, the end user has to share the burden of responsibility. Google does not oblige you to exploit these links sent to you by unknown sources. Apple has never twisted your arm to respond to a strange text.

And yet, no matter how many times they are notified, end users continue to exploit these strange links and respond to messages sent by unknown users. The end results could be catastrophic for your data, privacy and identity.

According to Avast, global ransomware attacks are up 32% on businesses and 38% on individuals. These attacks come in the form of fake package delivery information, tech support scams, exploit scams, and phishing scams (when an attacker tries to trick you into giving up personal information to get a leverage effect on a victim).

You’ve seen those emails and text messages coming to your phones. I get them all the time. While I was writing this article, I received no less than five such scams and my wife forwarded me a phishing email attack that posed as an order for Geek Squad Gold Plus tech support at $499.19. In that email, there were phone numbers to be exploited which I guarantee would lead to endless trouble. I immediately told him it was a scam and deleted it. This type of attack is so common that I have reached the point where I automatically block (or mark as spam) any email containing certain phrases or companies frequently used in phishing scams.

I also get about 10 text messages a day on my phone that look like this:

Hey, I tried to call you but you don’t answer. What’s new?

The sender of this message is not in my contact list, which means I don’t know him. Over the past few years, I’ve developed a simple rule: If I don’t know you, I won’t answer the phone or your messages. Now I don’t hesitate to block and report these messages as spam. The sender may be legit, but I’m not taking my chances.

And that’s the attitude every mobile user should have. Err on the side of caution very well and you will avoid many common attacks on your privacy and data.

And that, my dear friends, is the hard and simple truth about phone security that you (and everyone you know) must accept.