Mobile Device Management invades privacy
blog.cdemi.io
blog.cdemi.io
- prevent the installation of any other MDM profiles (such as a work profile)
- allow you to pair-lock your device, which will prevent any forensic tools from accessing your device (for instance if it gets taken by police or at a border crossing, even if you're forced to give up your password, they won't be able to image your device or do other scans).
iOS security researcher (now Apple employee) Jonathan Zdziarski has a blog post on it:
"Counter-Forensics: Pair-Lock Your Device with Apple’s Configurator": https://www.zdziarski.com/blog/?p=2589
queue the long nested thread of technical objections, policy objections, legal objections, objections on behalf of web publishers just trying to make it in this difficult internet and need your data to monetize, ...
I've been doing some testing on my end on how well the separation is using Google's "Android Enterprise" MDM which you can setup yourself (for free), then put your Employer's MDM inside a Work Profile.
It was at that point that I informed my manager that I would no longer be checking work e-mail and instant messages on my mobile device unless the company chose to pay for a company-owned device and require that I carry it. My manager told me that he intended to do the exact same thing. Informal surveys of my group show that about 80% of the group are not following work e-mail or IMs when away from work computers.
I am happy that this is the case but am also disappointed that the remaining 20% are almost entirely the "burn the candle at both ends" segment of our group and they're forever replying to threads and the like even when off work on weekend or vacation.
I have read on multiple places that MDMs on an iPhone have quite restricted access (no SMS/iMessage, pictures, non-MDM e-mail, and the like) unless the device has been wiped and redone under the All Powerful MDM mode but I don't know if those people are correct or if they're all going from the same (possibly inaccurate) source. Therefore, I keep the MDM stuff off of my iPhone because it is mine and I have data from other unrelated projects and companies on it that is none of my employer's business nor theirs to have access to hoover up.
Other industries are not going to give people the choice, and will force these policies on their captive users. So, we need to push back and make MDMs better to protect those users.
Interestingly enough, where I work is unthinkable to check your work email in your personal smartphone, both because workers won't accept working in their free time and because it goes against the company security policy (writing your password in a personal, spyware ridden device? _shrugs_). Maybe we should start outright refusing to perform work activities during personal time.
Really? Off work is off work.
The moment I step out the building door, work is done, finished.
Want to talk with me? Wait for the following day I am at work.
There is nothing the employer can do about it unless it specifically states it on the work contract, most European countries have laws about being contacted after work.
Here's my problem: I try to maintain a good work life balance. I devote time outside of work to passions, hobbies and relationships. But I am not dogmatic about hours. My company does not pay me to have my butt in a chair. They pay me to get the job done.
I am very dogmatic about hours, because when the next layoff round comes, HR won't care 1 second about how much overtime people were doing when considering who to fire.
I'll admit to more than a little envy!
The work profile apps and data are the only things the MDM can "see" at that point on the device.
You can also switch the profile on and off at will, which is nice for vacations.
The article makes it sound like once you accept one of these policies the policy server can subsequently push out an update with more permissions and the user doesn't get a chance to opt out. But surely that must not be right?
It seems like the article is trying to spread some fear, without checking what users can actually control on newer Android and iOS devices.
I'm sure you could find a shipping device that lacks them, but not from a major carrier in most of the world. Of Play-enabled devices, Google puts this at less than 5% worldwide
Maybe someone else can comment if it works the same with office365 or similar?
I have a separate phone (Nextbit Robin) that has my work MDM on it. Thankfully, I've got access to the console, so I can keep an eye on the audit log.
As an example, he found out there was a feature in the MDM service to block access to YouTube. He made sure that was ticked. Why? He didn't want people wasting time on 'his' phones. And the helpdesk would explode every time a new restriction was rolled out, but he didn't seem to notice or care. In his mind they were his phones.
I accept that trying to achieve privacy from my employer through technical means is essentially a losing battle. It would mean taking multiple laptops on all (frequent) work trips, never checking anything personal at work, and not being able to effectively check my work from home.
Plus even if I had that full isolation they already can technically access much of my personal data since they host my email and browser.
The second I lose faith in the security and privacy values of my company, I would leave—but trying to technically limit myself seems functionally impossible.
People probably don‘t expect their employer to be able to intercept eg. their Facebook messages or private email.
And it‘s trivial to protect against this: Just use your own device for personal stuff. You probably don‘t need to bring a second laptop on a work trip, just bring your own phone or tablet for stuff that you don‘t want someone at your company to track...
> And it‘s trivial to protect against this: Just use your own device for personal stuff.
I don't consider that trivial. Switching from work email back to personal email, or checking Facebook while coding is very common for me. More importantly, I don't particularly care if my employer has the ability to track my activity.
How I manage my personal productivity is my prerogative. Personally I find that I fluctuate between periods of intense focus (where hours of coding pass without me even noticing) and times where my brain is tired and I need a thoughtless distraction.
Well, yes, of course it's your decision. But I think his point stands: if you exercise your right to accept MDM on a personal device, you've made a wrong decision.
> I accept that trying to achieve privacy from my employer through technical means is essentially a losing battle. It would mean taking multiple laptops on all (frequent) work trips, never checking anything personal at work, and not being able to effectively check my work from home.
That's a bit strong. On work trips I'll sometimes bring my personal laptop, but even more often leave it at home. I don't need a personal laptop during my downtime — there's a whole big world out there! — but it can be nice. On personal trips I'll almost always leave my work laptop behind. Why would I work on a vacation?
Yes, you should never check anything personal at work. If you do, your employer is completely within his power (definitely) & rights (in many jurisdictions) to read your communications, store your passwords &c. Just Don't Do It™.
You can effectively check your work from home with your work laptop.
> Plus even if I had that full isolation they already can technically access much of my personal data since they host my email and browser.
Only if you use your work email & browser for personal purposes. Don't do that! Seriously, don't. Just don't. Sooner or later it will bite you, badly.
Work systems are the property of your employer; personal systems are your property. Work systems are the responsibility of your employer; personal systems are your responsibility. What your work wants, may not align 100% with what you want; what you want, may not align 100% with what your work wants. Don't cross the streams!
Only if I share your exact same values. You cannot tell me my decision is "wrong" when I know the consequences but decide that I'm comfortable with the risks.
Your response, and the original article, are incredibly patronizing.
> Yes, you should never check anything personal at work.
That's your view. Stop applying your personal views to my own.
Yes I know my employer can store my information and read my communications, but personally I don't care at all that my employer could read my texts with my girlfriend.
> Only if you use your work email & browser for personal purposes.
I work at Google. Of course I don't use my work account or browser profile for personal purposes, but at the end of the day my employer hosts my personal email and makes my personal browser. Given the vast amount of personal data which we have, I think trying to use technical measures to limit my exposure is foolhardy: my faith in privacy lies with the policies and actions of my fellow employees. If that faith ever falters, I have far bigger problems than the occasional Facebook message sent at work.
A carefully designed MDM solution could greatly simplify compliance and improve the security baseline for many of these businesses. As the market stands now, you either get easy to use with no safety rails on one end of the spectrum or all the power and flexibility and complexity in the world on the other.
I think there is definitely some opportunity in this area.
If an employer requires MDM to be installed, and verifies that it is installed, you can add a second user account and install MDM in there. The user is so separate that if MDM is used to remote wipe a phone, when MDM is installed in a secondary user, it doesn't actually wipe the phone, it just deletes the secondary user. Yes, I actually tested this remote wipe functionality with an employer's MDM.
On Android 7.0+ the "work profile" is probably a better option (https://support.google.com/work/android/answer/6191949).
The obvious intention here is to make sure there are reasonable measures in place in case my phone is lost or stolen. I think the main possibly-problematic permission here is "Set the device global proxy", which apparently could be use to intercept SMS messages (according to the article, I think). Other than that one, I'm pretty sure most of the scary capabilities listed in the article (the ones affecting privacy) don't apply here. Maybe other MDMs have those permissions?
My understanding of the Android security model is that permissions changes need to be explicitly approved by the user, so I think an app update or config change wouldn't be able to extend the permissions without my agreement. Also note that the app is written by Google, so my company isn't even running custom code on my phone. Even if the permissions do somehow change, I always have the option to remove the app, which un-applies the policy and disconnects my work Google account.
I suppose this sort of thing depends on the situation and how much you trust your employer, but I think that for many cases this article is a bit alarmist. Note that you run into similar problems if you ever log in with personal Google on your work computer. Since your employer owns the computer, I believe they have legal access your Google cookie and could use it to read your email and anything else associated with your Google account. But I do it anyway because it's convenient and I trust my coworkers, and I am quite certain that nobody is reading my personal email. But I also work at a small company where I know everybody. YMMV.
Can I run some sort of VM or a sandbox to make the server think they're MDMing my whole phone? I should be able to feed them enough garbage to keep the other end happy, right? If IT wants to be able to remote wipe my phone, they can remote wipe my VM instead. Anything less would be absurd.
https://technet.microsoft.com/en-us/library/aa998614(v=exchg...
Years ago this was one of the key features of the Nitrodesk software - work data was all kept within that app and could be wiped by the Exchange admin. The Exchange client I'm using now (Nine) has an option in settings for the security model and can either be device or application, with capabilities as you'd expect.
This guy has some more information.
https://practical365.com/exchange-server/exchange-best-pract...
http://mail-wise.com/faq/#bypass
But it is probably not wise to do that in a company setup, as it clearly undermines their control & security efforts.
Trusting me to be able to access my work e-mail from my own equipment without the need to monitor me is perhaps the lowest baseline of trust that I expect an employer to put in me. Afterall, if they can't trust me to be responsible with such data why bother giving me access to their systems at all?*
* The exception of course is in cases where they are required to monitor data use by law, e.g. medical. But prefer working in open environments anyways...
It's as much about ignorance as it is about malice.
They wanted MDM, I tried to deploy in my "secure folder"(formerly Samsung Knox), but would block my phone as incompatible platform.
They could enable this, but my company doesn't want to and no reason given
I am not required to access my work emails outside of my core hours, but it comes in handy if I could get notified of a new email directly to me (I get 100+ emails a day with maybe 10 requiring me to do something).
I like to be prepared knowing what I need Todo before I come into my office the next morning.
All I want as the admin is to (1) authorize if a device can be used to connect to company resources (2) require minimum level of security (pin/pass unlock) to be available to access company data and (3) de-authorize the device, which immediately deletes ONLY company data.
I don't want anything else. I don't want to sync photos, share clipboard, change security settings, send blaring lost-phone alerts. Those are not my problems. Just let me have an isolated VM-like area where I can allow/disallow the user's access to company data.
Good for Enterprise (now owned by Blackberry) does this. I do not know if it is really a secure enclave, but their app is its own universe and was the only part of my phone that was controlled by my employer at my last job. The drawback is that its their own universe - you are using their mail program, calendar, browser rather than your personal favorites. But it sure beats the MDM policy.
Fortunately (?) I can access schedule and email with iPhone app.
Can't you just factory reset your phone, login to your accounts and download your data again?