If you’re an Apple iPhone user and security’s not on your mind, you’re at risk; at risk of having a Web mail account hacked ; at risk of having your online identity stolen; and at risk of losing valuable personal information, such as wireless service account data, that could result in financial losses, among other disasters.
When it comes to mobile devices, security tops the list of IT security managers’ concerns. And rightly so: Computing Technology Industry Association (CompTIA) survey of 2,024 information security professionals earlier this year, more than half of respondents say risks related to mobile devices and remote workers are up significantly compared to 2007.
Whether you’re using the iPhone for work or play, it pays to ensure that you’re checking your e-mail, surfing the Web via Wi-Fi and accessing various content and services in the safest possible ways. You can follow these six tips in a matter of minutes, and potentially save yourself weeks of damage control.
iPhone Security Tip 1: Enable Auto-Lock
One of the most basic iPhone security functions is the Auto-Lock feature, which locks the device’s touch screen after not being used for a preset time period. Users can choose to set their iPhones to lock after not being used for one, two, three, four or five minutes. Auto-Lock can also be disabled altogether.
Auto-Lock is turned on by default, but you can change the settings by first clicking the main iPhone Settings icon, tapping the General tab and then hitting Auto-Lock. Then select the desired time period by tapping the on-screen value. Finally, exit the Auto-Lock and Settings screens by tapping the box in the display’s top left corner.
Though Auto-Lock is not exactly a security function on its own, when combined with the Passcode safeguard described below, it’s an essential iPhone security feature.
iPhone Security Tip 2: Enable Passcode Lock
The iPhone Auto-Lock disables the device’s screen after a preset time period of non-use, but the Passcode Lock feature takes that a step further. Whenever the device’s display locks, whether due to Auto-Lock or because you’ve hit the iPhone Sleep button–found on the top right of the device–Passcode Lock requires a four-digit code to be entered before the device can be employed again.
To turn on Passcode Lock, simply click the main iPhone Settings icon again, hit General and then tap Passcode Lock. On the Passcode Lock menu screen, enable the function by tapping Turn Passcode On. You’ll then be prompted to enter in a new passcode. Good passwords are completely random and should not be chosen based on birthdays or other dates or numbers that could be uncovered by would-be hackers.
You can also specify when a passcode is required. To do so, tap Require Passcode and then choose whether or not you want to be prompted for a code immediately upon using the device, after one minute, five minutes, 15 minutes, one hour or four hours. Setting the passcode prompt to Immediately is the most secure, as users won’t be able to access the iPhone at all without entering the appropriate passcode.
The Passcode Lock screen also has options to Show SMS Preview and Erase Data. When enabled, the SMS preview function allows the first sentence of new text messages to appear on-screen even when a passcode has not been entered. If you’d like the highest level of iPhone security–or just some more privacy–you probably want to disable Show SMS Preview.
The Erase Data function lets you completely wipe your iPhone after 10 failed passcode attempts. After six failed attempts, the iPhone locks out users for a minute before another passcode can be entered. And the device increases the lock-out time following each additional failed attempt–one minute, five minutes, 15 minutes, etc.–so an attempted passcode bypass could take miscreants hours.
iPhone Security Tip 3: Use Wi-Fi Safely on the iPhone
One of the iPhone’s most valuable features is its Wi-Fi support, which lets you connect to high-speed wireless networks for faster Web browsing and better data coverage in spots where cellular coverage is less than stellar. However, employing Wi-Fi networks without taking the proper security precautions can leave your device–and everything on it–open to crafty hackers.
First things first, you want to make sure your own personal Wi-Fi networks is secured using Wi-Fi Protected Access (WPA) or another wireless security protocol. (Refer to the product literature that accompanied your wireless router for more on how to enable Wi-Fi security.) When you connect your iPhone to that network for the first time, you’ll be prompted for the network’s password–assuming you’re using some sort of Wi-Fi security.
You should also modify the name of your personal Wi-Fi network to something custom, to help reduce the chance of coming across another network with the same name.
To ensure that you don’t unknowingly connect to Wi-Fi networks while on the go, you should enable the iPhone’s Ask to Join Networks function. You can turn this feature on by once again tapping the main iPhone Settings tab and then choosing Wi-Fi. On the main Wi-Fi settings screen, turn the Ask to Join Networks function on by simply tapping the on/off button next to the option. After the feature is enabled, you’ll never connect to an open Wi-Fi network without first being asked to confirm the connection. (The device will still automatically connect to recognized networks, or networks to which you’ve connected in the past.)
It’s also a good idea to disable Wi-Fi whenever it’s not in use. This reduces the chance of accidentally connecting to an unsecured or suspect network and saves iPhone battery life. To turn Wi-Fi off, just hit the iPhone Settings icon, tap Wi-Fi and then click the on/off button on the Wi-Fi screen.
iPhone Security Tip 4: Securely Access Corporate, Web Mail
If you’re a corporate iPhone user, the most secure way for you to access your e-mail, at least your business mail, is most likely through a Microsoft Exchange Server–assuming your organization uses Exchange. Lotus Notes users can also securely receive their corporate mail via iPhone thanks to the recent introduction of Lotus iNotes ultralite. (For more on how to receive Outlook and Notes mail on the iPhone, consult your IT administrator.)
For non-business iPhone users, receiving Web mail, like Gmail, AOL and Yahoo Mail, is a breeze; however, the process is not always secure–especially if you’re not aware of how to ensure that secure sockets layer (SSL) protection is enabled, where available. SSL encrypts mail that’s sent and received via iPhone. If you’re unable to connect to your Web mail using the iPhone and SSL, consider using another mail account that does support the safeguard–I’ve setup a number of Gmail accounts using SSL on the iPhone. Or, if you choose to access mail without SSL, be aware that your messages are not secured–think post card vs. sealed letter.
To ensure that you’re using SSL when retrieving Web mail, click the main iPhone Settings tab, choose Mail, Contacts and Calendar and then select one of your active mail accounts. While on the mail account screen, click Advanced, scroll down to the Use SSL option and ensure that it’s set to On.
iPhone users can also access Web mail via their mail provider’s portals, but it pays to be security smart when using thi