|
|||
| Home | News | Reviews | Features | FREE Downloads | Forums | Compare PDA Prices | Compare SmartPhone Prices | |||
BlackBerryToday > Features > Handheld Security: Part IV The Mobile VPN Handheld Security: Part IV The Mobile VPN
By Laura Taylor
Transmitting data insecurely over wireless connections presents a security risk. If you use your Personal Digital Assistant (PDA) or smartphone to transfer sensitive information or files, you really ought to be using a VPN to ensure that the confidentiality and integrity of your data transfer is not exploited. In this article, part IV of our series on security, Laura Taylor helps you understand how to select a VPN for your handheld.
Handheld Use Vulnerable Wireless Networks With a wired network, the only way someone else can connect to your network is by physically connecting a device to your wire, or by hacking the authentication and logging in to an account or service on your network. With a wireless network, anyone who can pick up the signal can join it if you do not take precautions. In fact, it is so easy to join a wireless network that some users may end up connecting to your wireless network unknowingly and completely by accident. You should be concerned about basically two types of wireless networks: access point networks and peer-to-peer networks. Access point wireless networks are the kind that you setup at home and are available at your local airport and coffee bar. With an access point network, you join the wireless network by authentication through a wireless access pointa box with an antennae that transmits an 802.11 wireless signal to the surrounding area. With a peer-to-peer network, two wireless clients connect directly to each other without using an access point. The 802.11 wireless standard refers to peer-to-peer wireless networks as ad-hoc networks. (There are different types of 802.11 wireless networks, but that discussion is beyond the scope of this article.) If you're transmitting proprietary, confidential, or sensitive information using your PDA, you really should be doing it via a VPN. VPN stands for virtual private network, and transmitting data using a VPN means that you're transmitting your data over a secure encrypted channel. If you transmit your data using a VPN, a hacker cannot access your data by using a wireless sniffer such as NetStumbler. Without a VPN, you lose the ability to keep your data confidential, and you also open it up to the possibility that a hacker could modify it in mid-transmit and re-transmit modified data. Some VPNs come bundled with strong authentication, and others don't. Strong authentication means that the user authentication process itself is more robust and more secure than an ordinary clear-text password challenge-response application. If you use a VPN that does not come bundled with strong authentication, you'll want to deploy a strong authentication system in tandem with your PDA VPN. It makes little sense to transmit all your data securely if your password transmits the Internet in the clear leaving the potential for a wily hacker to hi-jack your VPN client account.
VPN Products Many "road warriors" often use VPN clients on their laptop to connect back to the home office over a cellular wireless network. Because your laptop runs a standard desktop operating system, it can use a standard VPN client. There doesn't have to be anything inherent in the VPN software to accommodate a wireless network. However, your PDA or smartphone uses a handheld operating system. Therefore you cannot use the same client software your laptop is using on your handheld If you the Palm OS on your PDA, the first question you should ask when shopping for a VPN client is, "Will this VPN client run on Palm platform?" The same goes for other mobile platforms, such as Windows Mobile and Symbian.
Table 1. PDA VPN Products
A variety of handheld VPN vendors are noted in Table 1. Leading PDA VPNs are either based on IPSec or SSL. While I won't be going into comparing IPSec VPNs against SSL VPNs for this article, it is worth understanding that mobile VPN clients often only support one or the other. You should o inquire whether the mobile client you are thinking of procuring offers SSL VPNs, IPSec VPNs, or both. Keep in mind that when you use a handheld VPN client for a site-to-site VPN, you need a VPN gateway at the remote end. Your handheld VPN client must work together with the VPN gateway to let you in the remote network. In some cases, you can purchase a mobile VPN client that works with your existing infrastructure. In other cases, you may need to buy an entire VPN gateway for the handheld clients to authenticate to and login to. To keep the cost down, first see if you can find a mobile VPN client that works with your existing infrastructure.
Selecting Your Wireless VPN Criteria
· Which PDA platforms are supported?
VPN Upshot If you're going to use them for data transmissions, you should do it securely. Even if the data you are transmitting is not sensitive, you could be exposing your organization to a security exploit simply by sending data through an unsecured link. If you are sending or connecting to an organization that deals with national security, financial matters, or sensitive personal information such as social security numbers, credit card numbers, or medical records, you need to use a VPN with your PDA or you shouldn't be transmitting anything at all. If you ask the right questions when shopping for a solution, you'll find just the right VPN to meet your needs. Related Links:
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||