Totally backwards. As Mr Trump would put it, SAD!
Totally backwards. As Mr Trump would put it, SAD!
There is no evidence that jailbroken or rooted users have resulted in any significant compromises.
At least in the Android world, you must still approve any application which wants root access and rooting your phone allow you to gain access to some pretty impressive security tools you otherwise wouldn't have available to you. Generally speaking, users who are rooted or jailbroken are sophisticated enough to handle this on their own - and often use it to improve their security, not damage it.
You were given that device to do work on, not take apart and do whatever you wish with it. If you want your own dev device, buy your own phone. I see plenty of coworkers who carry around two devices each day.
Companies that lock down the employee computers to only allow whitelisted applications to run deal with a lot less reimaging and malware cleaning that those that give local admin access to the employee. It does result in employees having to request installation of things outside the standard core software but it still takes less time than dealing with typical malware.
It only "opens up access" to applications I allow explicitly. And I run things like XPrivacy which allow me to hook privacy compromising applications.
In reality it's much better for security to be rooted if you know what you're doing.
It's only a problem if you're allowing root for say, random games you download... and I don't think many people are doing that. Generally if you're rooted or jailbroken, you know what you're doing.
And if you don't, it's potentially much worse security. If your device is rooted, that's an attack vector that didn't previously exist. Since this tool is about informing and not enforcing, then if you really do know what you're doing then you can choose to take no action. If, however, you're not aware of the risks rooting a device exposes you too, then the tool provides an opportunity to learn that.
Further, this tool wasn't made with protecting an individual so much as protecting an organization. Yeah, you know what you're doing, but are you willing to bet your organization's security on that being true for everyone now and in the future? One compromised device can be all it takes for an attacker to get in. Not everyone who roots really knows what they're doing, it's very easy to root some phones, a quick download on a PC, run an app, click a button, and tada! Also, what about the non-techie person that asks their tech-savvy friend to root because they want to be able to <any single one of the things rooting allows>? Do you trust the judgement of every person tech-savvy enough to do this to never root another's phone without them really understanding the consequences?
</rambling>
Phones don't seem to be very popular attack vectors and many main attack methods could be performed without the need to root the device at all.
All in all, I'd be very surprised if rooting a device ever resulted in a significant compromise which couldn't have been done without root. Exploitation excluded obviously.
It's not what's being referred to here, but there's no weirdness in the language.