MS Exchange “remote wipe” is a terrible, terrible bug
code.technically.us
code.technically.us
Joining your personal phone to exchange is much like joining your personal computer to the corporate domain. You don't do it unless you want corporate IT to administer it and corporate policy allows it.
Edit: I sympathize with people who lost data, and do agree that the phone should warn you before completing the join. That said, as a business owner, I only allow exchange (and not POP or IMAP) for exactly this reason. I need to be able to wipe the company data if a phone is lost, or someone is fired (and not cooperative), etc. The real world isn't always nice.
Also, the full device wipe is by design, and the feature is called "Remote Device Wipe." The details can be found here:
http://technet.microsoft.com/en-us/library/bb124591.aspx
Note that the storage card is also wiped (where attachments and other sensitive data may be saved).
Would you be happy with just an email wipe, if that option were available?
In most cases there is more than just email, and the line between exchange and personal blurs. How do you remove the exchange data from a contact originating from exchange but updated with Facebook data? What about company restricted WiFi passwords? Attachments saved outside of the mail program?
It's complicated, and when properly used: a last resort.
Edit since I can't reply below: Linking with activesync is optional. The policies are part of the bargain. Your examples either weren't optional (RIAA) or were things you'd choose not to do (EA).
For the first scenario, I see no problem at all with remote wipe, but I do have a problem with the assumption that deliberate destruction of personal data is acceptable, for any reason. What if an employee had some paperwork at home? Would you condone burning their house to destroy it? Is a car bomb appropriate to destroy a briefcase left in a car?
What right does anyone have to destroy other people's property in the course of protecting their own? Would you support game manufacturers like EA being able to remote wipe your computer if they suspected you of running a pirate copy of a game? The RIAA if they suspect you of torrenting?
When you find the example of the company that requires you to purchase a personal phone and sync it with their corporate mail server, you be sure and let us know. Until then, by all means, scream from the rooftops that this feature exists... but don't pretend there's no valid reason for it.
Orrin Hatch: http://news.bbc.co.uk/2/hi/2999780.stm.
but don't pretend there's no valid reason for it.
If my house has been broken into before, there's a "valid reason" for me to install a tripwire that automatically fires a shotgun blast at the intruder. That won't go over well in court, and neither should this.
What's interesting is this: the ability to hook up a phone via ActiveSync (the protocol in question) can be configured per account. If IT did not want him to hook up his phone, they should have not given him those rights. Wiping devices like this is a bad idea.
But don't blame the feature.
(full disclosure: I work on the MS Exchange team)
The problem is, there is no way a user will expect that they are giving away that privilege merely by adding an Exchange account to their personal phone. This is a gaping security hole in the mobile client software and it's entirely the fault of the phone developers. Just giving the server the name of my device without telling me is a breach, as far as I'm concerned.
It's not about data ownership, it's about access. Your data being on a device does not authorize you to access that device.
In fact, I'd personally recommend employees not link their phones. Work isn't so important it should be always on.
Remote wipe is there for a good (regulatory) reason.
(Nobody at my office should have more than "P. McKenzie" and my phone number saved on their phone. Including full name, email address, a photo, my address, and the like would give me a cause of action against the company if the phone was ever lost or if that information were misused.)
A smart device capable of downloading an email attachment could cause a multi-million dollar incident if it was lost. All it would take is a bug tracking system report with an attached file showing e.g. the wrong number of lines printed per page of radioactively sensitive customer data.
That really can give you cause of action against a company?
In a similar matter what if I had all of that information on my personal phone, am I correct in assuming that it shouldn't give you the right to sue if that information were released. (As it assumes you either gave me that information, or it was obtained through you in some way)
And in the case of the email attachment, if you are sending radioactively sensitive customer data in any way through email isn't that the real problem and not that the phone could get out.
Regardless of whether it should or shouldn't happen, IT controls people have to assume it will. The contract for syncing with a corporate Exchange server, in many places, simply requires you to allow your phone to be wiped.
If you don't like it, don't sync with your company's Exchange server. What's so hard about that?
The problem that the posts points out is that there's no warning about this "contract" whatsoever. No matter what mobile device I've ever used, I have never, ever had a dialog tell me that by syncing my phone with an Exchange server I'm letting my company's IT department hold my personal information by the balls.
Additionally, we're talking about a lack of separation between two entities' data (personal & company-owned data).
If I had a user access clause for my website, "by accessing content on this website I am granted full access to indiscriminately wipe any and all data on your device, belonging to me or not" and was given the capability to do it - that would be ludicrous. The only difference I see is that I'm not in an employer relationship with my users. Even still, an employer-employee relationship with a company does not grant them the right to delete any and all data on any device of mine.
Also, since we're in HN (startup city, what?) who has ever worked for a startup that DISCOURAGED working from home on a personal laptop or having access to email 24x7? I've certainly never worked for one.
If I drank enough rye to kill the requisite number of brain cells required for me to allow people to sync their personal gear with our IT, I'd definitely tell people "we will be nuking your gear from orbit periodically as a precautionary measure".
Yes, but this lack of separation is caused by the employee choosing to sync their work email with their personal device.
Unless the employer requires this, then it's entirely the employees fault.
But the post wrongly blames Microsoft and Exchange, when it's the person's workplace he should be blaming for supposedly not having clear enough policies.
The policy where I work is: linux laptop (I imagine BSD might also be ok), access to code is via sshfs (or TRAMP) only. I don't think this is that unusual.
http://groups.google.com/group/nitrodesk/browse_thread/threa...
The app doesn't have permission to wipe the entire phone even if it wanted to.
If it's a major security risk, don't sync it to someone's pocket. By syncing it to someone's pocket... it's out. Especially if it's on their personal phone, you can't control what they (or an attacker) will do.
Either that's an acceptable convenience / risk tradeoff, or it's not. If it's not, you need to focus your efforts on tagging confidential data and keeping it inside the "walls" of your organization... but that's not a technology problem, it's a people problem.
I don't know if the Exchange devices do the same thing - our company requires this kind of security, so we still only allow Blackberry.
This isn't an evil feature. It isn't a pointless feature. In fact it's a critical feature in the running of an organisation.
Email. Calendar. Address Book. A gold mine of absurdly sensitive data.
If you want corporate email on your phone, expect to have the possibility of a remote wipe.
It isnt Microsofts fault that people use it maliciously.
If you ask the user "do you wish to allow administrators to remote wipe your phone allow/deny?" what do you think they'll click ???
People don't care about data loss. Educate someone on how to not lose data, then a week later give them a laptop with a password protected screen saver/login - first thing they'll try to do is remove password.
The amount of company phones I see with no passcode lock is astounding - I can pick your phone up, forward emails to myself and have all your information. Bang.
Don't think data loss is a big deal? If you google "PA Consulting" a top link is how they lost a USB drive.
They will probably click "deny", and then not be allowed to connect to the server. Problem solved!
All you've solved is the ability for IT to say "told you so". You haven't solved the careless didn't-read-it end user from losing their data and thinking their phone is faulty.
Google decided to do an end run around Apple's lack of support for push notifications by making Gmail an Exchange server. Until now, I had no idea that by going along with this I was granting Google remote wipe privileges on my phone.
Sure, Google do not appear at this time to want to wipe my phone for any reason, but how is it that I've been unknowingly trusting them with this power? This privilege is decidedly non-obvious. When I connect to an email server I kind of expect that I'm giving someone, somewhere the ability to read my mail. That's "obvious," and I don't need a warning dialog.
But what is obvious about granting Google the right to erase the pictures I've taken of my father-son Lego Jawa Sand Crawler project? Or my voice memos? Or the extensive notes I've been making of design ideas for my Javascript framework?
Let's stay on topic, folks. The question to be debated isn't whether companies should have remote wipe privileges, it's whether a device should allow a user to grant such privileges without putting up a simple warning dialog.
This was so unfair I quit that day, causing a dramatic fuss pointing out exactly how much they'll suffer. That'll show them.
You have no idea who manages the parking lot, but now you just lost a resource on your project.
How did your manager end up reacting?
Not much I can do about it. I more or less trust my IT guys not to be dicks so I don't lose any sleep over it. But short of carrying two phones, there's no way for me to separate personal and work devices. I do keep a nandroid backup on my personal netbook though.
Wiping a personal device to "send a message" is passive-aggressive and totally destructive to morale.
It's a personal device - the company has no rights to it.
The only issue at hand is whether a phone should be more explicit in telling you doing this will hand IT complete control of the device.
People don't do good work when their employer is mean to them, regardless of what they signed. What is your "destroying potentially confidential data" is their "leaving to improve your competitor's product while you spend nine months trying to find a replacement".
Balance is the key.
Seems to me how it should work is that the device's user defines a PIN number for his device. Should the device be lost, the user could provide the IT guys with that PIN number, which would be required for the "remote nuke" feature to be used.
Suppose the user is a remote employee who's just been sacked -- the boss and IT are hundreds of miles away and can't just take the phone from him. That phone has some product-related emails on it that, if they were to get out, would tank the company's stock price. They have to be able to wipe that data without waiting for the user to hand over the key.
Should you be told that this is the policy? Of course. But what's the rest of the complaint here?
I have a problem with them, having on their screen a message saying "User X connected an unapproved device to Exchange", choosing to clicking "wipe", knowing they might destroy my personal stuff, instead of writing an e-mail telling me to get off the Exchange within 24 hours, and don't ever do it again, or face a remote wipe.
Does anybody know how you disable that "feature"? Preferably in such a way that it causes maximum harm to the organization that uses it.
Of course, we know it's a bad idea to mix work-devices and private devices, and we probably also have little trouble procuring a work-smartphone if we need that. But for a non-IT person with his new iPhone, exited that pointing the Exchange app to mail.work.com just works, it's unacceptable.
And in all this time, never did I once see anything on that protocol that could do anything more than download mail and delete the mail you had in your account.
So I hear about Exchange and figure "oh just another protocol MS came up with, properly has extensions for calendars and stuff".
Now if I don't know this is going on, how can anybody know?
It would be one thing if the device said "by connecting to this system, you allow it to removely wipe this device allow/deny?" but it doesn't.
And that is criminal.
If you are unable to understand that Microsoft added a lot of stuff to the exchange protocol, and this is one of them, perhaps you are in the wrong field. This is not top secret information, it has been around since Windows CE, and is requested by all big businesses.
You say that as if that is some sort of an argument. But there is no actual law or force in the universe that says that necessary steps to do something that you consider "securing your network" will therefore automatically not be "criminal". In fact once you start trying to think of what criminal activities someone might take in the name of "securing their network" it isn't that hard to come up with a very long list.
Something does not become legal merely because you have an excuse!
(Note I'm not saying this is illegal or not. That would take careful analysis of the law and probably a detailed specification of what jurisdiction we're talking about and the precise details of a specific hypothetical since it almost certainly goes both ways, depending. I'm just claiming the argument doesn't make much sense.)
If experienced developers don't know about this feature, there is no earthly way that the average user can be considered to have consented to access.
My boss can't kick down my door and ransack my house to find secret documents he gave me. If I violate my NDA, he can seek to remedy that in civil court.
And by connecting to ActiveSync you are telling your phone to "do ActiveSync things" and that includes letting it push policies such as "require a PIN/Password" and "be erased when needed". That you didn't know it meant that is not really grounds for saying it's criminal or whatever.
Hey, you know one earthly way you could know about this feature? Asked. "Hey IT people, can I connect my home phone to my work email? What should I know?".
POP3
IMAP
Exchange
What would I choose? With those options, one has more "features" and push email, but also allows my company to wipe my phone without asking me. This is not communicated to me through the UI.I think it would significantly affect my decision over which to use if that information was presented to me.
Corporations may not have national security in mind when they protect their data but to them their data is every bit as important.
What I want to know is, can Google wipe my iPhone if I have Exchange synching? Looks like that's a "yes". How about an option to wipe my device, myself? Wouldn't mind getting that without paying for Mobile Me.
Doing your job isn't an excuse.
The fact you can't see this, and change your world view to understand what is really going on, suggests that you are very young and being unreasonable.
And, sure, they expect evildoers to be using software that honors a remote-wipe command. Yeah, right.
- No corporate data on personal devices (not even email)
- I expect to be given a work smartphone
- I use my own phone and iPad for personal stuff
- Assume that anything you do through a device attached in any way (even a VPN) to a corporate network may have everything you do monitored
Of course, these rules apply mostly when you are working for a large company, but even when you are in a startup you occasionally may have to work at a client site - and often these are large corporates.
"When he turns it back on, it’s back to factory defaults. All the settings, apps, and data have been erased. wtf?"
Major case of Exchange over-reaching and wiping more than just Exchange data !?
It's saved our bacon in regards to stolen devices a few times.
The same goes for Gmail (Google Apps Premium Edition only) and Android (or anything else using Google Sync). You can enable/disable IMAP & POP for the domain and if you enable it you open the floodgates. You can selectively enable/disable users via API but they can toggle it back on their own. If you setup Google Sync instead of IMAP/POP you can remotely wipe devices but you can't do anything except wipe everything and there is no inbuilt method to notify the user first.
Exchange, as described in the blog post, is equally bad. I'm confident things will improve in 2011 but it's unpleasant right now. The best thing companies can do is to set a clear policy on what's allowed and what isn't based on their data security needs, and never violate the users' trust.
So there's a security by obscurity to start with: the average user doesn't know to ask for the Enterprise plan, let alone what Enterprise even means in context. So the scenario here requires that a) the salesman talked them into it, b) they bought into that service for the extra $15 on top of the data plan, or c) they consulted with the company's IT department or policies and knew they had to get that service. If they didn't, they simply cannot connect to the Exchange account. There's very little "oops, I didn't know what I was doing" here. I hope that most companies have a clear policy against checking your work e-mail from personal devices, and on your own time. There are legal implications for overtime pay. We may look the other way in startups, but this can't always be done.
Most law firms require this, unilaterally. It's part of the deal-- we'll pay your enterprise data plan in exchange for knowing that we may wipe the device, control which apps you can install [this is another can of worms], so on and so forth, per the requirements of malpractice insurance and data security.
In a perfect world this wouldn't be required, but I think we all know this can't possibly be the case in many industries.
Someone had gone to the trouble of keeping the phone charged; it got the wipe a good 24 hours after the battery should have died.
I was very, very happy the facility was there.
His iPhone was connected to our Google Apps account and with one click I managed to wipe his phone (it rebooted and came up with the "connect me to iTunes to activate me" screen).
Can my personal laptop be remotely wiped if I connect my email client to an exchange server? If not, why not? It seems to me that a laptop is even more likely to leak sensitive information out of email, like spread sheets and word documents.
The best compromise I have at the moment is an iPhone optimised web interface. This lets you get your emails on the device without (much) danger of them ending up saved there.
Because of course, it might cause _some_ interference for 30 seconds at a time right? Yeah.
The regulations that allow the use of 2.4Ghz ISM band require you to accept that interference....