Please create an account to participate in the Slashdot moderation system

 



Forgot your password?
typodupeerror
×
Iphone Microsoft Apple IT

When Your Company Remote-Wipes Your Personal Phone 446

Xenographic writes "NPR has a story about someone whose personal iPhone got remotely wiped by their employer. It was actually a mistake, but it was something of a surprise because they didn't believe they had given their employer any kind of access to do that. This may already be very familiar to Microsoft Exchange admins, but the problem was her iPhone's integration with MS Exchange automatically gives the server admin access to do remote wipes. All you have to do is configure the phone to receive email from an MS Exchange server and the server admin can wipe your phone at will. The phone wasn't bricked, even though absolutely all of its data was wiped, because the data could be restored from backup, assuming that someone had remembered to make one. But this also works on other devices like iPads, Blackberry phones, and other smartphones that integrate with MS Exchange. So if you read your work email on your personal phone or tablet, you might want to make sure that you keep backups, just in case."
This discussion has been archived. No new comments can be posted.

When Your Company Remote-Wipes Your Personal Phone

Comments Filter:
  • by queen of everything ( 695105 ) on Tuesday November 23, 2010 @05:37PM (#34324410)
    We have the same policy and will only allow smart phones to connect to exchange when they have the remote wipe capability. It's to protect the company's interests should a phone be lost or stolen. When the users sign up for ActiveSync they have to "read" the terms and conditions where it states that it may be remotely wiped. I don't think most people read it but when you think about the type of proprietary (and often confidential) data your email inbox has, you have to understand why the company does it.
    • by amicusNYCL ( 1538833 ) on Tuesday November 23, 2010 @05:52PM (#34324628)

      I don't think most people read it but when you think about the type of proprietary (and often confidential) data your email inbox has, you have to understand why the company does it.

      That's a perfectly acceptable policy for any company that provides smart phones to its employees. I don't know if it's true with your company, but I would consider that an overreach if you want me to connect my personal phone with your network and give you the ability to delete all of my pictures and other personal data solely at your discretion. I'm sure you would understand why the owner would find that objectionable.

      • by Capt.DrumkenBum ( 1173011 ) on Tuesday November 23, 2010 @06:05PM (#34324798)
        I have the same thing here. I always inform staff that I can and will wipe their phones. At their request, and that they should inform me at once if they lose of have their phone stolen.
        My personal iphone is connected to a gmail account that I forward a copy of all my work email.
        That way I get work email, but it is still my account.
        • by IshmaelDS ( 981095 ) on Tuesday November 23, 2010 @06:22PM (#34324982)
          That's a massive security breach, one I wouldn't allow on my network. You may want to check your corporate policies and make sure your still inline or you could be fired.
          • by macshit ( 157376 ) <[snogglethorpe] [at] [gmail.com]> on Tuesday November 23, 2010 @08:33PM (#34326128) Homepage

            Of course one reason such "massive security breaches" happen is that companies have stupidly draconian policies which make "normal" operation so annoying/dangerous that clueful employees bypass it as a matter of course.

            Yeah, they can threaten "you might be fired!", but threats are very rarely effective unless they coincide with common sense — which policies like "we can wipe whatever we want!" don't.

            I suppose the larger the company, the more likely they are to choose "draconian/bluster" over working with the employees to find an agreeable technical solution...

        • by jc42 ( 318812 )

          My personal iphone is connected to a gmail account that I forward a copy of all my work email.
          That way I get work email, but it is still my account.

          So you and your boss aren't worried that google's staff has full access to your company email?

          I wonder if you boss actually knows this ...

        • by PNutts ( 199112 ) on Tuesday November 23, 2010 @08:43PM (#34326200)

          I have the same thing here. I always inform staff that I can and will wipe their phones. At their request, and that they should inform me at once if they lose of have their phone stolen.

          My personal iphone is connected to a gmail account that I forward a copy of all my work email.

          That way I get work email, but it is still my account.

          I guess I'll pile on, too...

          Depending on where you live and what you do, HIPAA has some exciting new personal liability built right in at no extra charge! So when that claims processor blasts PHI out to the wrong e-mail list, you, sir, have just transferred and stored it in a manner that will have you in court by yourself. Just you in the "Little Old Lady Victim vs. Evil (your name here)" By this time your employment will be a distant memory and your former company has no obligation to defend you. Depending on the company's policies and compliance they will get dinged, but that is a cost of doing business and a separate process that has nothing to do with your personal liability. Have you planned financially for that scenario?

          /drama

      • by Dynedain ( 141758 ) <slashdot2&anthonymclin,com> on Tuesday November 23, 2010 @06:06PM (#34324800) Homepage

        Then don't connect your personal phone to the company network.

        It's that simple. It's the company's data, not your personal data, and they have measures in place to protect it. If you don't want to abide by those measures, you don't have to.

        At least in the US, if you're required to provide equipment required by your job, and your employer doesn't pay for it, then you can write it off on against your personal tax burden. So if you find yourself in that rare situation where work requires you have a smartphone, and won't pay for it, get one separate than your private phone and save on your taxes at the end of the year.

        • by fishexe ( 168879 ) on Tuesday November 23, 2010 @06:40PM (#34325170) Homepage

          It's the company's data, not your personal data, and they have measures in place to protect it.

          No it's not. He was talking about them wiping all your personal data. "Measures in place" to protect company's data that also wipe your personal data are a bit creepy.

          • Re: (Score:3, Insightful)

            by Dynedain ( 141758 )

            I meant the protection is for the company's data. It's their data, and their protection. You don't like what their protection does to your phone and your data? Then don't hook up your phone to their systems.

            It's just like having a personal laptop. Would you bind your personal machine to the company's AD environment, giving them full administrative control? No? Then don't use your personal machine on their network. Use a company-provided machine, or a work-dedicated machine that you can write off on your tax

            • by fishexe ( 168879 ) on Tuesday November 23, 2010 @08:32PM (#34326118) Homepage

              It's just like having a personal laptop. Would you bind your personal machine to the company's AD environment, giving them full administrative control? No? Then don't use your personal machine on their network. Use a company-provided machine, or a work-dedicated machine that you can write off on your tax return.

              I use my personal machine at work every day. I connect via standard protocols like ssh and smb, and never give up admin control, nor would I ordinarily do so. If they explicitly asked me to, I would say no, buy me a company machine instead, but if they said, "hey, if you install this software you can connect to our email servers" I don't really think it would occur to me to go check if the ordinary behavior of that software gives them root on my box. That wouldn't even occur to me.

        • Re: (Score:3, Interesting)

          by nitehawk214 ( 222219 )

          Then don't connect your personal phone to the company network.

          This.

          Furthermore, there is no way in hell I am going to spend my own money on a phone for work purposes. If they want me to pretend to have email access anywhere, they can very well buy me a phone that I can leave locked up in my desk at work, then pretend the network wasn't available when they tried to get in touch with me.

          Wait, what were we talking about again?

        • So if you find yourself in that rare situation where work requires you have a smartphone, and won't pay for it, get one separate than your private phone and save on your taxes at the end of the year.

          You're funny. Rare. Heheh. You don't really live in the USA, do you?

        • by sjames ( 1099 )

          It's fair enough if they have the ability to wipe the mailboxes that come from the exchange server, but any emails from a personal account, contacts, photos, etc should be off-limits to the employer. If that's not good enough, it should be on them to provide you with a phone for work use that can be wiped at will.

      • by Cylix ( 55374 ) *

        I don't believe I have known any company that requires you use your personal phone.

        However, where I work now it is difficult to get a crackberry (red tape) and I'll probably connect to the exchange server for the time being.

        I'm fully aware of what will happen and they actually make an effort to explain it.

        However, circumventing the wipe is pretty easy because it does not stop anyone from exporting the data prior to initiating the wipe. At my last place of work there was a trivial amount of work involved in

    • by Anonymous Cowpat ( 788193 ) on Tuesday November 23, 2010 @05:54PM (#34324660) Journal

      What do you do to protect your employees interests in not having their own data annihilated by accident?

      Also, are you expecting employees to take work with them, using their own devices; or is the company willing to bare the costs of either providing a device or the work not being done?

      It would seem most unusual to me for an employer to require their employees to provide expensive equipment for company use, and with the agreement that the company may treat it as its own.

      • by steppin_razor_LA ( 236684 ) on Tuesday November 23, 2010 @06:09PM (#34324838) Journal

        My $.02 on policy:

        Employees should backup their own data. If they are uncomfortable with the possibility of Employer wiping their personal phone, then they should not connect their personal phone to work email.

          If an Employer *wants* its Employees to be reading their email from cell phones and the Employee doesn't feel like using their own personal property to do so, then the Employer needs to buy the Employee a work owned device or "STFU". If the Employee doesn't want to carry around two devices then they either need to submit to their phone being wiped or "STFU" and carry around both devices.

        • Re: (Score:3, Insightful)

          If an Employer *wants* its Employees to be reading their email from cell phones and the Employee doesn't feel like using their own personal property to do so, then the Employer needs to buy the Employee a work owned device or "STFU". If the Employee doesn't want to carry around two devices then they either need to submit to their phone being wiped or "STFU" and carry around both devices.

          So you want me to have to carry around a second device because some dev is too lazy to isolate the e-mail stored on my p

          • I agree that the remote wipe behavior implemented by Apple is poor. I guess they didn't want to bother implementing a "user requested" remote wipe (i.e. all corporate and personal data) vs. a "sysadmin requested" remote wipe (i.e. all corporate data).

            Given that this is a flaw in the product, we have to work with what we have.

            If you are required to have access to corporate email, then you need to either:

            1. carry a second (corporate issued) device

            2. submit to having corporate data wiped off your device even i

      • Re: (Score:3, Insightful)

        by tlhIngan ( 30335 )

        What do you do to protect your employees interests in not having their own data annihilated by accident?

        Also, are you expecting employees to take work with them, using their own devices; or is the company willing to bare the costs of either providing a device or the work not being done?

        It would seem most unusual to me for an employer to require their employees to provide expensive equipment for company use, and with the agreement that the company may treat it as its own.

        Simple - don't give company access to

      • Re: (Score:3, Insightful)

        by Rich0 ( 548339 )

        It would seem most unusual to me for an employer to require their employees to provide expensive equipment for company use, and with the agreement that the company may treat it as its own.

        Why do you think the USA has such a high level of productivity? EVERYBODY expects their employees to do this stuff. Sure, it isn't written policy, but if you don't do it you "aren't competitive."

        Why would the employer pay for an employee to use a cell phone when they can just fire the slowest worker every year and pretty

    • by Monkeedude1212 ( 1560403 ) on Tuesday November 23, 2010 @05:59PM (#34324732) Journal

      We're actually dealing with a bit of backlash from having this policy - on both sides of the issue at the same time!

      I'll try to be as vague as possible to cover my butt - but basically someone who deals with Clients for their job was going to be let go. We wiped their phone, as standard policy. Not sure if they copied the data prior to leaving or if another employee helped them out, but they basically took contact information, pricing/quotes, certain client rates, etc etc and took that to help land another job with a competitor.

      Being in IT I know that it's going on as basically our "employee lifecycle" has come under review - but I'm not exactly on the legal team so I don't know how exactly it's progressing. But I know basically we pressed charges for selling trade secrets, and they are counter-suing for something along the lines of destruction of personal property for wiping EVERYTHING off of their phone.

      I am not aware of any actual "Agreement" to phone wipes besides possibly verbal ones between managers and their employees and/or IT - there isn't a lot of documentation on the subject matter anywhere - however since starting any time anyone has asked "Can you get my email sync'd on my phone?" My common response is "Yes, but you will be handing over control of ALL The phones data to the company so we can wipe it should you be terminated or leave the company, which includes all your personal phone numbers and appointments". I say it not only to actually warn people of the danger - but its actually a great deterrent and a lot of people reconsider and don't want it anymore, less work for me!

      • Re: (Score:3, Funny)

        by amicusNYCL ( 1538833 )

        From TFA:

        Someone in the IT department had sent out what's called a "remote wipe," a kind of auto-destruct command that's delivered by e-mail.

        I'm really, really looking forward to the first story we get of an admin accidentally sending the message to a contact list, such as the entire company, and wiping everyone's data from the CEO down. Future computer science students will learn about the lessons of the Therac-25, the Ariane-5 rocket, and the Exchange/smart phone integration that brought a fortune-500 company to a standstill for a week.

    • Ditto.

      If someone wants to connect their personal device to our servers and store corporate data on it, then they must submit to their phone being remote wiped. There have been a few people who have had issue w/ this (i.e. mostly around terminations), but the alternatives (i.e. loss of sensitive data, risk to customers, etc) far exceeds the risk that someone might lose some photos they didn't backup.

      • Risk to the company. To the employee/ex-employee the risk of losing their photos far outweighs the risk to your sensitive data because your data means nothing to them.
        Of course, that being as it is, it really ought to boil down to who the phone belongs to. Judging by a lot of comments on this, an awful lot of companies think they can swap that around by merely informing the owner of a phone that the company intends to treat it as its own.

        A lot of this conflict could be resolved if people used this rule of t

        • I suppose it depends on the work environment, but we regularly deal with sensitive customer information (i.e. financials, SSNs, credit cards, etc) and this sort of information ends up in internal emails.

          I care more about protecting the identities of the people that do business with us then protecting the personal assets of employees that were careless (i.e. by not backing them up) with them.

          I suggest thinking of it less as Employee vs Employer and more in terms of information risk.

          Implications of having som

    • Re: (Score:3, Interesting)

      by Hatta ( 162192 )

      We have the same policy and will only allow smart phones to connect to exchange when they have the remote wipe capability. It's to protect the company's interests should a phone be lost or stolen.

      Do you have the same policy for PCs?

      • by guruevi ( 827432 )

        Or how about flash drives etc.

        The primary reason these technologies exist is for theft or loss of company property aka encryption. They are not going to prevent intentional data theft. If a company wants to connect using Exchange with these features, they should give company property to do so. In all other cases use IMAP or so.

    • Comment removed (Score:5, Insightful)

      by account_deleted ( 4530225 ) on Tuesday November 23, 2010 @06:22PM (#34324980)
      Comment removed based on user account deletion
    • Our policy is stricter, we explicitly prohibit someone from connecting to the company E-Mail system with a personally owned device, of course we provide BlackBerry or iPhone devices (user/manager preference) to anyone with even a halfway reasonable explanation.

    • Re: (Score:3, Insightful)

      by md65536 ( 670240 )

      It's to protect the company's interests should a phone be lost or stolen.

      I don't think that wiping the entire phone's data goes far enough to protect their interests. Every company should have the ability to remotely wipe your smartphone, and your home computer, and the computers of all family and friends within 6 degrees of separation. Also, they should be able to kill you, because your brain contains precious precious data, too. Really, they ought to be able to take off and nuke the entire site from orbit. It's the only way to be sure.

      Way too far is not enough, I say, when it

    • by fishexe ( 168879 )

      We have the same policy and will only allow smart phones to connect to exchange when they have the remote wipe capability. It's to protect the company's interests should a phone be lost or stolen. When the users sign up for ActiveSync they have to "read" the terms and conditions where it states that it may be remotely wiped. I don't think most people read it but when you think about the type of proprietary (and often confidential) data your email inbox has, you have to understand why the company does it.

      Even so, I wouldn't give my employer the capacity to remotely wipe my notebook PC's hard drive, and all the same proprietary and often confidential data is in my PC's email inbox.

    • by nurb432 ( 527695 )

      We make sure they understand that it gives us that power. We also enforce passwords, even if they didn't have one on their phone before.

      And like the OP says, it doesn't brick your phone so no real harm done, but it will ruin your day.

    • I can certainly understand and appreciate those company interests. But it completely tramples the interests of the owner of the phone. On the other hand, if the company was also the owner of the phone, that would be perfectly acceptable and I would certainly encourage it.

      If the company permits company data on personal property, then the company has already given it away, in my opinion and has waived all rights to the information within.

      I had my phone on the company's BES... my carrier wouldn't do anything

  • If you keep a ton of data you need on your phone, or anything, you should probably keep backups. There's plenty of ways to have your device wiped out or destroyed.
  • Bad photoshop? (Score:4, Informative)

    by bigredradio ( 631970 ) on Tuesday November 23, 2010 @05:38PM (#34324420) Homepage Journal
    Is it just me or does the iphone in the picture of the article look really small? Or the person has really large hands?
  • Sure, any phone or client that supports Exchange Provisioning will allow the server administrator to do it.

    Incidentally, I lost access completely to my work's Exchange server after they enabled provisioning, as did everyone using Android. All the iPhone users have access still, and they're all open to being wiped once someone flips the switch.

    • by colinnwn ( 677715 ) on Tuesday November 23, 2010 @05:52PM (#34324626)
      Unless your company specifically forbids it, I'd use TouchDown for Android. I've set it up for my mom and it seemed to work ok. I couldn't get her tasks to sync, but I'm sure I could have figured it out with some more effort. The email came down fine. It isn't quite as chic as having everything integrated into the native apps on your phone, but the interface seemed serviceable enough, and it keeps more of a firewall between your work and personal life.

      Many companies don't specifically check the client string. If they do, and you really want to, you can masquerade as an iPhone. It supports Exchange remote wipe (but only for the TouchDown data store), all your personal data on the phone will be unaffected. I have Prey on my phone to wipe my personal data in case it gets stolen.
      • I'll forward the TouchDown recommendation on to my co-workers that are using Android, however most of them are beta-testing software in development here (system level stuff) so they tend to get their devices reset frequently. I use an N900, so there's no real options for me short of my employer buying me a device, or reverse engineering the ActiveSync protocol such that I can lie and claim I support provisioning when I don't.

  • by growse ( 928427 )
    Company asserts remote-wipe control over devices that access company systems and data. News at 11.
    • You think this goes on all the time, huh? Do you have a laptop? Can you use your laptop to connect via VPN or wifi (or even wired) to your company's network? Does your company have the ability to delete all data on your laptop's hard drive remotely?

      • by vakuona ( 788200 )
        I can connect to the company's network via a VPN. I can't download anything from there to my PC. My laptop is just a dumb terminal as far as connecting to the work network is concerned. So no need to remote wipe there. Besides, the reason companies want to remote wipe your phone is because those are more easily lost or stolen.
  • Nonsense (Score:4, Interesting)

    by Anonymous Coward on Tuesday November 23, 2010 @05:40PM (#34324462)

    Wiping someones personal data is a felony. I think it likely that the employer prosecute if the tables were turned. Hacking tools are illegal in some jusridictions, I think anything providing this level of unauthorised access would be illegal under German law. Guess they don't use exchange there?

    • by tsj5j ( 1159013 )

      Would you prefer to be sued over loss of company data/secrets/etc in the event that you lose your phone?

      I would say that this is perfectly reasonable provided they let you know in advance.
      They aren't reading your personal data, they are simply given the ability to delete it when you are no longer an employee, or you lose your phone.

      It's also good to note that iTunes automatically backs up your phone/pad/touch device.
      So that actually covers the "keep a backup" part of the argument.

      • Would you prefer to be sued over loss of company data/secrets/etc in the event that you lose your phone?

        If I ran a company and were truly worried about this, I'd have all sensitive data stored on a secure server that can be accessed remotely. Of course some care would need to go into how this is implemented but it can certainly be done.

        It's amazing how infrequently you feel a need to litigate when you put a little thought into things.

    • She was in the 'States, which tends to ignore minor crimes and expect the victim to sue/shoot the culprit (;-))

      You're better off in Germany, and the Americans are better off than some of the third world, where our American cousins and we send volunteers to teach the concept of the rule of Law, as in http://www.lawyerswithoutborders.org/Pages/Default.aspx [lawyerswit...orders.org]

      --dave

  • This is common knowledge for most System Administrators (or should be).

    With Blackberry, you can remote wipe, or just lock the device and change the password. The iPhone can be wiped.

    By default, whenever you connect your iPhone to your computer it does a backup/sync. Blackberry does not.

    Most companies I know first lock the device with a new password, and give the user a chance to bring the phone in (or a # of days before it is remote wiped).

    If a company is unwilling to provide you with a phone for work, then

  • You'd be crazy to use your own phone for work related email or any other tasks. Work and business don't mix and this is a perfect example of that.
    • You'd be crazy to use your own phone for work related email or any other tasks. Work and business don't mix and this is a perfect example of that.

      This is sort of like the concept that "when you insist on using what you do not understand, and refuse to learn how to understand it, don't be shocked if you get bad results" (think computer security for a good example). It's like that concept in that it's simple, easy to understand, and people will go to great lengths to remain in denial of it.

  • Tell them to pay you $10,000 for your troubles or you will be suing them and pressing criminal charges for hacking your phone.
    • I'm assuming the response will be a curt letter informing you to read the agreement that you already agreed to, with said agreement attached, including an invoice for the lawyer's time to draft the letter and send it. Thanks for your business.

      What, you mean you didn't read the EULA? Whose fault is that? Is that the company's fault?

    • Tell them to pay you $10,000 for your troubles or you will be suing them and pressing criminal charges for hacking your phone.

      Great idea. Unless of course the company has a legal department, or access to an attorney. There is a reason you have to sign a contract, agreeing to the terms/policies of your employer.

      • 1) not everyone has a contract 2) not all contract terms are enforceable - ones which allow the employer to damage the employees personal property at will may fall into that category (IANAL).

  • by RollingThunder ( 88952 ) on Tuesday November 23, 2010 @05:45PM (#34324548)

    I don't think most folks are shocked at the remote wipe capability - they just expected that it would be confined to the exchange data only, not the MP3's, games, photos, etc.

    • by fermion ( 181285 )
      Which is what I was surprised about. If I connect to company email, then the company has the right to wipe the email.

      Sure, a person may have company documents on the phone, and therefore it is safest for the entire phone to wiped, but one thing mentioned in the program was that the reason they do is not only to protect against theft, but also against employee misconduct. A remote wipe does not protect insider misconduct. As long as the phone is backed up, the contents can be restored and secrets expose

      • Sure, a person may have company documents on the phone, and therefore it is safest for the entire phone to wiped, but one thing mentioned in the program was that the reason they do is not only to protect against theft, but also against employee misconduct. A remote wipe does not protect insider misconduct. As long as the phone is backed up, the contents can be restored and secrets exposed.

        I think it's intended to protect against the "thoughtless/ignorant/stupid fool" type of misconduct where people simply

    • by fishexe ( 168879 )

      I don't think most folks are shocked at the remote wipe capability - they just expected that it would be confined to the exchange data only, not the MP3's, games, photos, etc.

      Exactly. All the people saying "it's the company's data, don't like getting it wyped? tough!" should take heed of this point.

      • I don't think most folks are shocked at the remote wipe capability - they just expected that it would be confined to the exchange data only, not the MP3's, games, photos, etc.

        Exactly. All the people saying "it's the company's data, don't like getting it wyped? tough!" should take heed of this point.

        There's a really simple way to nullify that point.

        If a company wants that kind of control over a device, they can pay for it and issue it to their employees.

        The only reason this raises any concerns at all is because people want to take personal devices that they pay for and then submit to company control over those devices. That's simply unwise. I'm not shocked when people do something unwise and get an undesired result. Are you?

  • A marriage made in heaven.....

  • by rennerik ( 1256370 ) on Tuesday November 23, 2010 @05:48PM (#34324596)
    ... use IMAP. Connecting to Exchange via IMAP doesn't enable remote wipe, but still allows you to access your mail and get access to the GAL.

    But honestly, if you're needing access to a company's Exchange server, there's no reason why the company can't enforce a security policy, like a PIN or password on your phone, or remote wipe capabilities. There may be sensitive data in your emails or in your contact list, that should not be accessed on a device which has no protection (or even weak protection like a PIN). It's in the best interest of the organization to be able to remotely-wipe a device connected to their Exchange server.

    That being said, if you don't want to give the company access to do that to your phone, then don't connect to Exchange. If IMAP isn't enabled, then you have to take the tradeoff.
    • And that is why server admins shouldn't (and typically do not) enable IMAP. :)

      • So that's why I met so much resistance when I was setting up a script to automatically check and process mail over IMAP. I thought it was still a standard default thing, but the server admin, who can design and set up entire Exchange systems, virtual servers, entire VPN infrastructures, etc, seemed confused when I asked him to enable and test IMAP.

        Is there some major flaw in IMAP, or has Microsoft simply already embraced and extended it, and now they're moving on with phase 3?

        • Some admins will not open IMAP or POP3 because they want to limit the attack surface in general.

          An additional reason to not allow IMAP and POP3 is that it allows for a variety of mail clients to connect and pull copies of corporate emails offsite without giving the admins the "remote kill" switch.

          Example -- you hook your gmail account up to your work email. It is now filled w/ all of your work emails. In internal correspondence, a CC or SSN number is discussed. Now a copy of that info is sitting (unsecured)

        • So that's why I met so much resistance when I was setting up a script to automatically check and process mail over IMAP. I thought it was still a standard default thing, but the server admin, who can design and set up entire Exchange systems, virtual servers, entire VPN infrastructures, etc, seemed confused when I asked him to enable and test IMAP.

          Is there some major flaw in IMAP, or has Microsoft simply already embraced and extended it, and now they're moving on with phase 3?

          I'm pretty sure that Lotus Notes already embraced-and-extended it, though I wouldn't be surprised if Microsoft has done that too. That practice is a page from Microsoft's playbook, after all.

    • My company still runs old Exchange servers (hell, we still run XP and until last month, IE6). We *do* have an official iPhone app for accessing the Exchange servers, though. Wow, does it *suck*! Luckily we have a lot of Unix boxes that need email access, so IMAP is enabled. When on the company WIFI, IMAP is good enough. When off the company WIFI, SecureID is just an extra step.

  • by Rhywden ( 1940872 ) on Tuesday November 23, 2010 @05:54PM (#34324644)
    ... they're using an Exchange-Server for all the students' email. Fun parts include: You're only able to install a Forwarding rule if you use the Internet Explorer (otherwise the button for rules is simply not there - something their FAQ omits.) SMTP does not work at all for some strange reason. I finally tried to configure my Android phone to use the Exchange account as an additional email account. That worked. However, whenever the screen went black to conserve power, I had to reenter my Exchange password to unlock the phone! With a nontrivial password containing special characters, numbers, small and big letters at a length of 10 characters, this became a serious pain in the ass. Normally, to unlock the phone I just have to swipe the on-screen button from right to left. Needless to say, I quickly removed the Exchange account. And it was only a month later that I actually got an answer from them regarding my problems. So, if our university of incompetent morons Exchange server means that they could erase my data, I won't touch their offering with a ten-feet pole. Fun fact: They're "offering" a user administration tool for all the dorms' routers based on PHP. This little "tool" does an include of remote PHP files based on the unsanitized GET request data. As a plus, this tool has to be run as root. Which means that any disgruntled dorm administrator could do a pretty powerful attack on nearly the whole dorm network infrastructure.
    • Re: (Score:3, Funny)

      by amicusNYCL ( 1538833 )

      This little "tool" does an include of remote PHP files based on the unsanitized GET request data.

      I don't believe that for a second. ..could you provide a URL to back up your claim?

  • It wasn't "not bricked" because the data was restorable from backup. The iPhone was still completely functional after the data wipe hence it was "not bricked" because nothing was done to render it inoperable, even without a backup.

  • was the first mistake.

    If your employer wants you to read work email on a mobile device, make them issue one.

    Don't run your personal mobile's wireless through the company access points. Use your damn 3g/4g data plan for that.

    Seriously. If it's your data, your employer has no business going anywhere near it or the devices that contain it, and you don't let them get that impression by never giving them a sniff of the thing.

    • was the first mistake.

      If your employer wants you to read work email on a mobile device, make them issue one.

      Don't run your personal mobile's wireless through the company access points. Use your damn 3g/4g data plan for that.

      Seriously. If it's your data, your employer has no business going anywhere near it or the devices that contain it, and you don't let them get that impression by never giving them a sniff of the thing.

      It doesn't matter how you are accesing your data - whether it's over the corporate WLAN or via 3G - if you have your phone configured as an ActiveSync client, it can be remote wiped from the server. Apple had to include this feature as it's part of the spec for ActiveSync, which they licensed from Microsoft. No amount of accessing data over a corporate (or any) network will give them the access to wipe your phone, unless you have an ActiveSync account configured.

      If you don't want your employer to wipe your

    • Many people would prefer to not carry two devices and would rather submit their personal device to the corporate rules. There is no "cake and eat it too" scenario here -- just informed user decision.

    • by fishexe ( 168879 )

      was the first mistake.

      If your employer wants you to read work email on a mobile device, make them issue one.

      Yeah, that'll go over real well. "I won't do my job until you buy me a smartphone!"

  • he phone wasn't bricked, even though absolutely all of its data was wiped, because the data could be restored from backup, assuming that someone had remembered to make one.

    Simply by plugging your device into iTunes, it automatically makes a backup. This is something you can turn off if you really try, but by default making a backup is a standard part of the sync process with iTunes.

  • If you don't want to risk such things happening, don't mix business and personal.

    Laptop, VPN, Cell Phone, etc. Keep your life separate from your work. Don't do work on personal equipment, and don't use work equipment for things you want kept private.

    If you chose to mix them (for convenience) then understand the risk.

    • by fishexe ( 168879 )

      If you don't want to risk such things happening, don't mix business and personal.

      Laptop, VPN, Cell Phone, etc. Keep your life separate from your work. Don't do work on personal equipment, and don't use work equipment for things you want kept private.

      If you chose to mix them (for convenience) then understand the risk.

      Yeah, 'cuz creepy backdoor capabilities surreptitiously placed into standard-issue corporate software is the natural risk of mixing work equipment with personal equipment, duh. This guy was just as dumb as that kid in Pennsylvania who took his school-issued laptop home and didn't expect to be videorecorded and monitored by the school. Idiots.

      Anyone who doesn't have at least 2 phones and at least 2 laptops is also an idiot.

  • Blackberry Enterprise Server and Blackberry Enterprise Server Express have the exact same capability to remotely wipe all data from an employee's Blackberry phone.
  • Wow, I had no idea that adding an Exchange email account for your iDevice would give sysadmins that power. Good thing my last company had ActiveSync disabled on their Exchange server forcing me to find alternate ways to get my emails, one of which was a tool that let me set a middle man server to act as a IMAP/LDAP/CALDAV server, sort of a proxy via the WebMail interface. This would keep the admin's off my phone while giving me full functionality.

  • I am not sure that many here understand this feature. Basically it is not a selective thing whereby it only removes certain data or administrators have any choice what it wipes - it has one option and that is to wipe the entire phone including the OS. The process leaves it in a state where it will not even boot up. You have to plug it into iTunes and download/install the OS/firmware back onto it before it can even be used again. See the link below on how the process works and what is required.

    Basically it c

  • This is a non-problem. You should have backups of your iPhone even if this weren't the case. Remote wipes from your office is not remotely (hah get it?) the most likely way to lose all of your iPhone data. I can think of a hundred more likely scenarios starting with dropping the phone on a street and moving on through my dog burying it.

    Back up all your data, or consider your data already lost. It's just a matter of time.

  • What about laptops? (Score:3, Interesting)

    by lullabud ( 679893 ) on Tuesday November 23, 2010 @08:10PM (#34325970)

    What's so special about a phone that they get extra special wipe privileges? Can an Exchange admin remote-wipe my laptop if I have it hooked up to my corporate account?

    No.

    Why my phone then?

White dwarf seeks red giant for binary relationship.

Working...