Apple quietly drops iOS jailbreak detection API
networkworld.com
networkworld.com
What will make it especially hard to accept is that they've had nothing but BlackBerries for a good decade now and that platform can more or less be trusted, but only because it's never been rooted. And the only reason it's never been rooted is because nobody really cares.
Really, I think IT will just have to adapt to the idea that a smartphone is a personal device and can only be trusted as much as its user, and it lives outside the firewall. It's probably for the best anyway because phones are very personal and I would find it creepy to carry one around that was controlled by my employer.
Actually, I'd assume that there are a few Blackberries are rooted and have rootkits on them. That's just too useful to not exploit. Someone doing industrial espionage or law enforcement has probably already done this.
This implies that the walled garden, by definition, is more secure. Non sequitur. One could argue that the opposite is true:
1) The walled garden is implicitly trusted. This naturally will mean many companies assuming that the applications which Apple approves need no further security review. Apples review is demonstrably far from perfect. One might even call it arbitrary.
2) If companies could create their own "app store" with only reviewed apps, this would be much more secure than Apple's walled garden. This is possible on a jailbroken device with a customized system image.
A jailbroken iPhone poses a risk in much the same way a Windows PC poses a risk — that’s why IT forces everyone to run McAfee. Jailbroken phones will also need malware detection!
For example, if you want to do any sort of real automated app black box testing for QA purposes, you really have jailbreak your phone.
If such an API existed I would say it is good that it has been removed, as asking a system 'hage you been compromised?' will not help you find out whether a system has been compromised.