On TV.com: TOP 10 Shows CANCELED Too Soon
BNET Business Network:
BNET
TechRepublic
ZDNet

March 5th, 2008

iPhone insecurity leaves sour taste for enterprise IT

Posted by Richard Koman @ 5:15 am

Categories: Apple, Security, Wired & Wireless, iPhone

Tags: Apple iPhone, Security, Information Technology, SDK, Apple Inc., Richard Koman, It, Richard Koman

In Focus » See more posts on: iPhone

In its invitation to the media for Thursday’s iPhone Software Roadmap, Apple hints strongly that it’s working to get the iPhone into the enterprise. In addition to information about the iPhone SDK, Apple promises “some exciting new enterprise features.” The event graphic shows “Enterprise” as a major stop on the SDK highway.

iLounge, which is carrying “confirmed” rumors of the details, says the enterprise features are pretty much limited to announcing iPhone support for Microsoft Exchange and Lotus Notes.

But not being able to use Exchange on your iPhone is not what enterprise reluctance is all about. It’s about security. All that jailbreaking, buffer overflows, hardware hacks, and revelations about weak architecture, and proof-of-concept exploits galore leaves a sour taste in IT mouths, Andrew Storms, director of IT security at nCircle Network Security, told me.

This release of the SDK probably won’t do much to regain
the love of many enterprise IT and security departments. All the attention
drawn to the security of the iPhone in the last 9 months has driven too much
bad disclosure resulting in lowered trust among IT security groups. In the
world of IT security, once trust is diminished, its a steep narrow mountain
to climb in order to regain that dependability.

What about the fact that Apple will apparently server as gatekeeper, only allowing apps it approves of to be distributed through the iTunes Store? Rather than building confidence, Andrew said:

Enterprise IT sees this policy as an indicator of lacking good technical security controls on the iPhone. As has it been all throughout the iPhone jailbreak saga, Apple cannot play the demigod of creativity and coolness while enforcing these seemingly unfounded strict controls.

And speaking of Apple’s Good iPhoning Seal of Approval, does anyone think there won’t still be a vibrant “gray market” in unapproved apps? I asked my friend Damien Stolarz about that:

I’m pretty certain jailbreaking will be popular for the forseeable future. The SDK is better than nothing but a lack of over-the-air purchase/install will leave installer.app in business until Apple lets you buy on the phone.

In any case, the SDK will drive more enterprise apps and integration, which will only make things worse, Andrew said.

This will just continue to widen the chasm between
the company executive and the IT security personnel. Instead of playing to
the peril of allowing feature-functionality to outpace security, Apple needs
to first retrace its steps and spend some face-to-face time with enterprise
security teams in order to regain their trust.

When I talked to Andrew about this stuff last fall, when iPhone security holes were all over the headlines, he said this is what Apple needs to do: Provide centralized tools for managing configuration and compliance.

Until then it will continue to be shunned by enterprises. No matter how useful or ingenious the device may be, the enterprise simply cannot consume another device where private data could be leaked.”

  • Talkback
  • Most Recent of 16 Talkback(s)
RE: iPhone insecurity leaves sour taste for enterprise IT
Why don't they build a business only iPhone?

R (Read the rest)
Posted by: leboeufsurletoit Posted on: 10/26/09 You are currently: a Guest | | Terms of Use
The glass is half full... and rather sweet.  i8thecat | 03/05/08
Apple fanboys deserved reputation  tonymcs@... | 03/05/08
Apple fanboys?  grail@... | 03/05/08
I love my iPhone too...  MalumRegnat\ | 03/06/08
Lucid Dreaming?  Skullet | 03/06/08
Correction  Skullet | 03/06/08
Not to nit pick, but...  fhil28@... | 03/06/08
why your company buying your wife BB  xtrememorph@... | 03/06/08
???  fhil28@... | 03/12/08
Have you ever work as IT Support?!  xtrememorph@... | 03/06/08
RE: iPhone insecurity leaves sour taste for enterprise IT  davidwfox | 03/05/08
RE: iPhone insecurity leaves sour taste for enterprise IT  bdammann | 03/06/08
Most Enterprise IT security departments are clueless  Bruizer | 03/06/08
IT is all about  frgough | 03/06/08
And you do?  xtrememorph@... | 03/06/08
RE: iPhone insecurity leaves sour taste for enterprise IT  leboeufsurletoit | 10/26/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement
Click Here

Recent Entries

Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors
advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

  • Smart Tech Expert advice on innovations in healthcare and the green technologies that make it happen. Find out more
  • Smart Business Discussion and advice on management issues that revolve around making your world smarter and more useful. More Smart Advice
  • Smart People The best and worst moves in the management and strategy trenches. Learn More