Don’t Put Your Work Email on Your Personal Phone
onezero.medium.com
onezero.medium.com
After hearing about that, I never attach anything work related to my personal equipment. There is too much liability. Anytime that anyone even whispers about me using anything I own for company use, the answer is a resounding "No." You honestly, don't know who you are really working with/for and what they are actually like.
So, for example, we try to choose names for applications that aren't going to give people the wrong idea, eg don't call your market manipulation tool TurboMarketManipulator, call it EnhancedOrderManager.
Good advice. I am somewhat surprised at times on what the media doesn't uncover and try to spin as a conspiracy theory. For example, we had this open source project publically available https://gfiber.googlesource.com/kernel/prism/ around at the same time as the Snowden leaks about "prism" and nobody wrote any articles about it. Of course, it's completely unrelated... but I feel that that normally doesn't stop people.
I found the whole thing very interesting.
I'm guessing the law isn't that forward thinking though. Maybe I should keep a <$200 mini-PC, just to RDP into work so I have no problem giving up that machine.
Doesn't help you. Either your personal devices are in scope or not. If they are, then they all disappear and you're unlikely to get them back.
Investigators don't trust the subjects of the investigation to tell them what devices are in scope or not. If your devices are in scope, they'll take everything that has any chance of having data on it.
(Source: many many reports from subjects of such investigations.)
Not at all. Many companies actually do the opposite. A previous company I worked for had a 30 day email deletion policy, though we could setup special folders for 13 month retention on emails.
At another company, we were in the backup space and some enterprises had very restrictive backup and archive policies. One was to the point that our backup software was pretty much useless.
To limit liability, files that are not involved any ongoing legal issue such as a lawsuit are deleted as soon as possible without interrupting the business. Once there is a lawsuit, any relevant documents or emails can be deleted. This is all from the point of view for civil lawsuits. I assume gov't investigations are similar.
* A warning banner is displayed when you connect to the VPN / network / asset that states that use of the resource voids your expectation of privacy, you consent to monitoring, and you acknowledge they can inspect personal devices etc
* You signed a policy document acknowledging that they can monitor you and that connecting to a company resource brings your personal device in scope of monitoring and seizure
* You committed a crime, the police become involved, and a search warrant is issued.
If you do not sign such a policy document, they do not have evidence of a criminal (ie not civil) infraction, and they do not display a warning banner, then you can claim reasonable expectation of privacy (meaning you were ignorant of their policy), refuse a search, and there isn't much they can do to my knowledge. In this specific case you would have to talk to a lawyer, but I would just be safe and use only work assets for work.
The only safe and sane thing to do is refuse to have any work touch devices you own, and likewise don't let any of your personal affairs touch work systems.
if they're going to arrest you, there's nothing you're going to say to talk them out of it. all you can do by talking is convince them to arrest you.
you can't talk them out of anything they were already going to do; they're just talking to you because so many folks think the way you do, that they're somehow clever enough to say the thing that prevents the arrest.
> Winning an argument about your personal device's admissibility in court six months later isn't really winning is it?
it is if that means you don't go to jail.
your advice is wildly dangerous, please stop.
If you refuse to speak without a lawyer there, they'll either a) move on because they're out fishing and you're not biting, or b) arrest you because they already have evidence but were looking for an easy confession to make it a slam dunk case for the prosecution. Once arrested, you can hire/be assigned a criminal defense attorney who will figure out if you have a good chance of being found innocent or can minimize prison time through a plea deal.
>Winning an argument about your personal device's admissibility in court six months later isn't really winning is it?
Not taking their bait and running your mouth will minimize the chances of the FBI being able to get a warrant for your device to begin with. It's not just about the phone, it's about your freedom, financial stability (you will lose your job and you can't pay your bills from prison, so say goodbye to your credit score), and employment opportunities (federal convictions don't bode well for job hunting).
Look up "don't talk to the police" on YouTube if you want more reasons why letting the FBI look at your phone is a bad idea.
That is just fraud and the board of directors should be all over it (they would have visibility into the hiring of executive staff). Now if the company has no board, or the board is composed entirely of founders, this sort of stuff slides by. Best to avoid working in the future with anyone associated with the senior staff in future companies.
Any ideas on what happens in such cases?
In addition, all IMSIs and IMEIs are registered in a whitelist and tied to identity.
If we want to do work email on our phone, we do have to submit to MDM. 99% of the employees I know refused to allow MDM on their personal phone, and the company was OK with that. They made a few managers carry work issued 2nd phones.
We also use Slack and are allowed to use that without MDM so that works for a lot of us.
My wife has to carry a 2nd phone for work, she's got 2 iPhones and it's very annoying, but preserves the separation.
See, I'm the computer geek in the family, and that means that I'm the family MDM manager. Which means I already have an MDM on my phone, and since you can only ever have one MDM on a mobile device like that, well the conclusion is inevitable.
If they don't want to buy me a second phone, then they're going to have to decide which of those two policies they actually want to enforce.
That doesn't mean that the company will provide any such thing, much like they're clearly not providing company cell phones to the GP.
Wait, didn't you just softly admit to some (any?) wrongdoing?
Here's the thing about lawsuits, even if you're innocent, you're still probably ruined. It's not like on T.V., lawsuits take years, even criminal ones. If you encounter a law enforcement agent (say a prosecutor), that wants to make a career off of something you're involved in, you're screwed. At best, you'll probably be bankrupt and emotionally destroyed. Imagine this, they bring charges against you, and if you get a public intoxication, or heaven forbid a DUI, you go to jail for the next 3 years while awaiting trial and for something that you might not have even committed. Don't believe me, read a case document on conditions of release. They list off a ton of things that can send you back to jail while awaiting trial.
Edit: don't break the laws when you being prosecuted; and BTW: I don't drink alcohol at all. Period.
Yep. And you can sit in jail for a year or so while they figure that out at your trial. Of course you’ll have lost your job by then. And paid your lawyer a fortune so you’re broke. And your family is kind of screwed up over the whole thing and the hardship it caused.
But you were innocent. And that’s all that mattered.
> Edit: don't break the laws when you [sic] being prosecuted;
What? The whole point is you can't help but break a law.
I call that "you can beat the rap, but you can't beat the ride."
Strong anti-SLAPP legislation can help with some of that, but it's far from 100% and it's far from universal.
Please also understand that when you say "No, never" to a FBI agent, you myst be pretty sure that it is accurate, as if they (still hypothetically) find even a single interaction they could accuse you to lying to a government officer.
Anyway, yours is the right approach, never, and I mean never mix personal with work relatd activities.
If there's an emergency, they can always call, but I don't like being "always on".
When I got a new phone, I simply didn't install the email or slack clients. It's led to occasional text messages, when I really needed to communicate with a team member, but all in all has been a fantastic experience. Highly recommended.
Personally, I choose the opposite: you need to email me to tell me you want to call me (so that I’ll turn on my softphone app), otherwise you’ll just automatically go to voicemail (which will also go to my email.)
I notice that with Gmail’s inbox categories, you only get push-notified when something lands in Primary or Updates; so as long as you’ve trained the system to push the irrelevant/lifecycle stuff into the other categories, your phone won’t ding all that often. (Mine doesn’t, and I get a good amount of raw email.)
I have hundreds of rules for email filtering. With most mailing lists never hitting my inbox. But it's still way too much for individual email push notifications.
Personally I need to be able to put everything to the side when I'm out of office.
How do you even lose days off to some work emergency? If I was scheduled to be on vacation but I have to come in for some emergency, I don't lose those days, and you shouldn't either, since you never actually took those days off.
If you want me after hours you call. Thats the only option you have.
[1] https://newatlas.com/right-to-disconnect-after-hours-work-em...
[2] https://legistar.council.nyc.gov/LegislationDetail.aspx?ID=3...
That said, other than a handful of coworkers who I'm friends with outside of work, only my manager & HR have my personal number. This adds an extra step where the coworker should determine if getting in touch with me immediately is actually worth the effort.
So far, I've received one such phone call in 3 years. It was an actual emergency, and easily resolved by me at that time because they called me. If they had waited until the next working day, the issue would have blown up and taken much more effort for me to resolve.
This might alternatively be an argument for working with people who respect your time.
If I were to ever receive so many phone calls it becomes a problem I'll solve that problem. Right now I've had all of zero calls this year so I think I'll be right for the moment.
Furthermore, I don't find it particularly bright to host sensitive data by such a vague company. Bonus negative points for the infosec community using such.
Yes, a thousand times. People often write on company instant messaging just to ask things that can figure on their own.
People don't phone you for stuff that could have easily waited till tomorrow morning.
Also, if the employee has very marketable skills, they may be happy to leave a job whose hourly rate has suddenly dropped.
If you are highly skilled, you are highly in demand. Therefore, demand good treatment.
Tech industry compensation has never been higher: http://levels.fyi/comp.html
Google pays for on-call hours. You are credited with 33.3% time for each hour on call if you have a 30 minute response requirement, and 66.6% time for each hour on call if you have a 5 minute response requirement. These can be taken as extra holiday, or cashed out. [0]
[0] Among other public sources: https://www.reddit.com/r/cscareerquestions/comments/41v0ol/i...
The problem is companies where default on-call becomes part of the culture. They also have little incentive to fix terrible ops. I hear AWS can be like this, depending on the service.
If you're salaried then they are paying you for it based on the job requirements, it's part of the job and one of the things that separates hourly employees from salaried ones.
Unless you're talking about the cost of your cell plan or device? But even then, a lot of companies will pay for your plan and subsidize part/all of your device if they have a legitimate work reason to need to contact you and expect a fairly quick response outside the office.
EDIT: To be clear I'm referring to US law/practices. The entire point of salaried as opposed to hourly work is that it is based on performance rather than hours, and it's up to you and your employer to come to agreement on what performance means. At some companies salary might be for 40 hours, at others it's for 60 or 80 regularly. It's your own responsibility to find out before taking the job, and decide for yourself what you're willing to provide or not.
Salary is not 40 hours working + 128 hours on call per week.
Salary is a payment schedule, that's it. Anything else requires contractual agreement.
The fact that you think it gives companies the right to demand irregular hours is more about your mindset than reality.
Wish we had those laws here. Fortunately I work at a company where I am compensated extra for my oncall shifts that take place outside of normal work hours -- it ends up being a few extra tens of thousands of dollars per year. That should be the mandated standard though, not just for those who are lucky.
I'm not saying that's unreasonable, but I've heard of employees getting caught leaking by communicating through cell plans paid for by the employer.
My solution so far has been to just use the outlook web app. Sure it's not as nice as the app but it lets me get to the info I need while also preventing me from having to install any sort of profiles on my device, as an added bonus I do not allow the site to send me notifications so I do not have to worry about being bothered off-hours.
You must find a new employer—preferably while you make public this repulsive behavior.
Edit - looking at Settings->General->Profiles, there is one entry, which is for connecting to my Olympus camera. Nothing for the office.
During all communications, make it clear what your concerns are; perhaps even link to articles like this one.
Corporations that care about customer and employee privacy will take such inquiries seriously.
If it is your device, typically an employer will disclose in their policies what capabilities they use.
Now, does this prevent a rogue infosec person from deviating from the policy? No. Nor does it prevent the state from compelling the company to abuse their MDM technology. If these examples are part of your threat model, you should not use your personal device with your employer's infrastructure. I don't think this makes your employer's choice to use MDM a bad one, however. They are protecting the corporation, after all.
This is a good recommendation.
I personally was fine with this as I don't want to carry two devices, I like being able to check in via Slack (especially if I was on call), and we had several folks who had our security/IT team under a lot of scrutiny proving this wasn't overly invasive.
It helped that we were a small startup, so our IT and security teams were 20 feet away :)
Also found under Settings -> General -> Device Management.
GPS toggle isn't doing much of anything besides application permissions enforcement.
This article provides a summary of MDM User Enrollment, including details about how Apple separates personal and business data on separate APFS volumes.
https://simplemdm.com/apple-user-enrollment/
Before User Enrollment there wasn't a great Apple MDM enrollment option that struck this privacy balance for employee-owned devices. App data couldn't be viewed per-se, though a list of apps is certainly available (as mentioned by cannonedhamster). Some companies would skip MDM and essentially "wrap" individual apps in order to have the ability to encrypt the app data and have some control over the binary, but that's about it.
I'm not sure of the story with Android, though I'm under the impression that there is a similar "sandbox" option for MDM, albeit the implementation and user experience is rather messy and obtuse.
Full disclosure: I work for an MDM software producer.
Here’s the big issue I still have even with all of these ‘legal’ protections. The definitions are not highly technical and thus open to interpretation. Also, to my knowledge none of the clauses have been tested in the real world. How in the world am I supposed to feel secure that a legal agreement stops them from doing what is still technically possible? Even if they can’t use the data collected against me as admissible evidence in a disciplinary action what’s to stop them from collecting data anyway and then if they find something they don’t like they harass me in other ways?
The issue is in MDM systems. Until we design them in a way preventing access to certain classes of information through technical means then no type of agreement or ethical code is safe. The device must be treated as hostile. We can’t simply rely on ‘ethics’ because, as we’ve seen play out time after time in America, corporations lose no sleep over saying one thing and doing another.
I’ll take that kind of risk with i.e. Google employees and my Google searches, because it’s fundamentally necessary to provide me good search. There is just no reason to do it with my corporate security team and personal SMS.
If I worked in an office environment and company wanted me to use tracking software I'd see no problems with it. But it should be installed on a company provided phone. Which in the best case I'd leave at office off work, or in other cases - carry home and store it there.
* Lack of trust that is uncalled for, especially if you are in a position with responsability anyway.
* Unappropriate tracking method for a creative work
Are two points that I see.
I think that would be such a red flag for me of how everything else is at that client that I would never agree to the contract in the first place.
Since most of my clients allow BYOD I sometimes get asked to ensure I have antivirus etc installed. Which is ok as long as they don't dictate which software. So far that has been fine for all clients.
I have some clients that insist on a locked-down laptop to access some parts of their network, and they happily send me one that I use it for mostly email only. Having tracking software on it would be pointless as it would only show 5 minutes of email checking activity every 2-3 hours.
Unless by tracking you mean webcam and slack status? That seems acceptable to me. And as I mostly encourage(insist) that my teams use webcams when they are remote pairing etc it would be hypocritical of me to say otherwise.
https://www.upwork.com/hiring/for-freelancers/using-the-upwo...
If you're a tech worker you can afford to buy your own personal equipment for personal use. If the company needs you to have equipment to do work, they can purchase it for you. Simple as that.
What do you do if you're lying in bed watching a movie when you remember that you need to schedule a meeting with X for tomorrow at 11am? Do you get out of your warm bed and pull out your work laptop and add the calendar entry and then climb back into bed or do you just pause the movie, log in to your work calendar and make the entry real quick before resuming the movie?
The closest I've ever had to making this a reality was when my work computer was an iMac so I'd just leave it on 24/7 and RDP into it from home (I lived within WiFi distance of the office so all this was done via LAN). Even then, when the work stuff was going to take more than ~5 minutes, I'd still end up doing it natively from my home computer rather than deal with RDP lag.
edit: I also really struggle with what IM programs to keep on my work laptop these days. Medium of communication doesn't map cleanly onto work/personal contacts so I either deal with friends pinging me while at work or missing vital messages from people expecting a business response/having long professional conversations using a phone keyboard.
Carry your work phone to bed and use the calendar app.
I schedule it when I get in the office at 8 AM.
>I also really struggle with what IM programs to keep on my work laptop these days. Medium of communication doesn't map cleanly onto work/personal contacts so I either deal with friends pinging me while at work or missing vital messages from people expecting a business response/having long professional conversations using a phone keyboard.
My advice is to separate your work and friend accounts. You can have whatever messengers you need for work on your work laptop, but make sure that none of your accounts you share with friends are logged in on that machine. Same for your personal machines - only log in the accounts for friends. Then you don't have that problem.
In most cases, all you need is an email address to make a new account, and you can slowly move all of your friends over to this new account where friends and work do not overlap.
This is changing with iOS 13 and the introduction of User Enrollment, which siloes off work data and adds restrictions to what corporate IT can access.
...what? The Outlook app containerizes your email accout specifically so that you dont have to do this. Your company can remotely wipe your work account and only your work account.
Of course MDM gives access to your phone - thats its whole purpose.
If you use the Microsoft apps, you don't need to have an MDM applied because those apps handle the remote management functionality themselves.
The use-case for MDM is not to get email on personal phones - thats the right tool for the wrong job. MDM is for simplifying the deployment and management of corporate phones.
Adding an Exchange account to an iOS device optionally allows the Exchange client to enforce password and screen lock requirements, encryption, and allow for remote device wiping.
It does not have any access to device location, data, photos, contacts, or anything else you can think of outside of device passcode, encryption, and remote wiping.
An MDM profile is a completely separate thing from Exchange. Also, unless the iOS device is supervised (which has to be done at time of setup and would require wiping the device if you want to supervise one that's already setup) you're extremely limited in what you can do and see.
Source: We provide employee's with iOS devices and use VMWare Workspace ONE (formerly AirWatch) along with their Secure E-Mail Gateway and also use Apple's Device Enrollment Program. This provides for as complete control over the device as you can get.
I use the Nine mail/calendar app[1] to keep all that contained. It integrates nicely with the native Android apps but keeps all of the security and control options within Nine itself. It looks like they are also beta testing an iOS app but I have no experience with that version of it.
For example, if the mail account security settings require a screen lock code, Nine will require a code to access the app but this won't affect the actual phone's unlock screen.
Similarly if a data wipe request is sent from the server it will only affect Nine.
This kind of sandboxing is one of the things third party apps like this have always been known for, going all the way back to a really old one whose name in blanking on which I believe maintained its own entirely internal calendar, files, etc. (Dataviz maybe?)
Edit: this may still be useful for some people, but the work profiles introduced in Android 5+ may make it less relevant at least for anyone at enterprise scale or otherwise using MDM through a service provider.
I've got multiple "work" (one is a volunteering role) office365 exchange accounts on my personal phone, using [https://sites.google.com/site/bikomobi/exchained](exchained). Seems to work well. I'm sure the respective IT departments would give me a stern talking to, but there is nothing in either job that is of any sensitive nature whatsoever so their blanket "ask for admin permissions on my phone" policies can get fd, frankly.
Of course MDM is not required for any of this. Worst case is on Android you're forced to use Microsoft's Outlook app.
I'd still freaking love this feature ten years later. I don't want app level segregation of work and play, I want them in entirely different "instances" of my phone.
> https://arstechnica.com/information-technology/2011/09/samsu...
> https://virtualizationreview.com/articles/2009/01/01/the-nex...
> https://gizmodo.com/vmware-for-mobile-devices-lets-you-run-w...
Application Streaming [1] is getting pretty solid, and I would love to see an integrated mobile solution for that.
It would be a good way to have the easy access to applications, but keep the code, manage the security, and keep the data on the server.
It wouldn't allow access to data when offline, but I think that's actually a benefit when it comes to security. It could also be used by corporations to quickly secure lost devices since there would be no cached data, as well as lock down access at certain places such as when crossing the US border or when employees are on vacation (in other countries, especially). [1] https://en.wikipedia.org/wiki/Application_streaming
Mobile Reports: https://support.google.com/a/answer/6072773
Device Audit: https://support.google.com/a/answer/6350074
Mobile Alerts: https://support.google.com/a/answer/3230421
Edit: Furthermore, on iOS, you can go to Settings -> General -> Device Management -> <Select MDM Profile> -> More Details -> MDM Profile. The list of rights are listed there.
Considerations included not interrupting personal time or reminding people of work unnecessarily, location privacy, certainly not doing MDM of personal devices, security simplicity, etc.
The most interesting option was the old-school one-way radio alpha/numeric pager. It turns out that the Boston hospitals still use these heavily, as do some EMTs, and they're considered much more reliable than cellular- and WiFi-connected smartphones.
I'm imagining people on-call have their pager on, and it's only used for emergencies. There would be a couple/few numeric codes for the few different appropriate possibilities of importance/urgency/nature/modality, and what you should do. The most usual code might mean get on email/chat ASAP. Another code might mean phone devops ASAP. Code "666" apocalypse might mean call a car service immediately, get on phone/email/chat while you wait, don't delay to groom or anything.
As a matter of culture, all of the codes are worth bothering someone in their personal time. For example, maybe there's no code for "hey, if you have a second, it would save me half an hour if...". (Of course, we have to not raise the importance/urgency bar too much, or people might end up staying on chat or something, because the pager's bar is higher than their own.)
Don't mix your work and personal stuff. Keep it separate, keep it safe.
Which is why I only redirect my company phone regular voice calls to the private one when I'm out of office. If it's urgent, call. If it's not, I'll get to it when I'm in the office.
I'm not making this up, y'all; I've sat there with the other side's data collection party when my boss was telling me to let him collect the data.
FWIW when that happened I just started using the cruddy web interface.
What the article mentions about tracking is a legit concern though, IMO. Within a container it's still possible to access the GPS sensors. I'm not sure if the user can block this / opt-out? It's possible that an app may have to request permissions to use the GPS. In any case, I would say the situation is still better and more transparent on Samsung devices than this article would imply. I don't know about other devices but I can tell you Apple phones don't yet have an equivalent secure container solution (like Knox or Enclaves) so I'd be more concerned about the security situation on those devices.
Don't put your employer's MDM on your own phone. Make them buy you a work phone.
It may not be true for you personally, but I bet it is for most people who have on-call rotations.
Features like Android's separate profiles are critical. We need similar sandboxing on all platforms. I don't think we can change the 24/7 availability culture, but we can change things from a software side to make it less onerous.
So it is that I've given permission to confiscate my personal cellphone in the case of a breach. Otherwise, I literally couldn't do my job -- not because of anything particular about our field or technology, but because it was easier to set things up the way they are. We could spend a few days changing our alert structures, etc, and no-one would have to have "sensitive" data on their personal phones. But that's not going to happen for one employee.
I have my work slack and email on my phone, just with notifications turned off on both. There was nothing about installing an MDM.
Everywhere I've worked I've told my manager I turn off work when I leave (unless I'm oncall). I've never had this be a concern, across three large companies.
I have work apps on my personal device primarily for when I'm away from my desk during work hours. I disable notifications etc. outside of work hours.
I wouldn't say I'm really happy with it, but it does permit me some freedom to be away from my desk without the risk of missing something important during the day. It's a trade-off I've decided I'm willing to make.
Work also provides guest wifi which is conveniently configured by the Android for Work profile, so data usage while at the office isn't really a concern.
One employee who is logged in using office gmail in his/her android phone. The person (other employee) knowing the password can easily view most of the phone activity by visiting https://activity.google.com (which includes search history with location).
Something I've wondered: why do they only do this for native email? Why can I use Slack without it? In college even our student email accounts had MDM (which was pretty silly), but I worked around it by just viewing my email in the web browser. Are locally-stored emails somehow more vulnerable than my browser cache and the messages stored in the Slack app, or are those just loopholes?
Regardless, if I installed their remote monitoring S/W on my phone or used their phone, I would abandon any expectation of privacy on that device.
[1] https://www.blackberry.com/us/en/forms/campaigns/q2_19/byo
At this point, especially if I’m working at a company that isn’t a startup, I will not work somewhere that expects me to have slack available at “all times”. After hours if I’m not on call I simply do not respond.
For this reason I’ll never do dev ops work haha
My wife was asked to do this, and (and a discussion with me explaining what that means) she told them they could buy her a phone if they wanted that.
The company I work for does not require it, and I agree to have email and slack on my phone. They don't reach out to me on off hours unless there's a very good reason.
This conflates two different things: work email and MDM on personal phone. While I would never install company MDM on my personal phone, many organizations allow you to access work email from personal phone, no MDM strings attached. My 2c.
But trying to search around I can't find anything about how to actually find out. Does anyone know?
I assume Settings >> General >> Profiles, but it is empty so not sure.
Unless I'm missing something, there's not an obvious way to "spy" on employees, which this article is claiming. Perhaps it's possible, but if it is, it would require a lot of deliberate effort to accomplish. For example, there's not an out of the box way to track employee location. There's not a way to track employee internet browsing history out of the box.
TLDR: using G Suite Advanced MDM, there are not out of the box solutions for tracking or spying on employees in the ways suggested in the article. It might be technically possible, but to accomplish it, your company would need to make a (large) deliberate effort to do this.
Some large enterprises use MDM to deploy certificates and proxy policies that essentially force you into a MitM situation, with the intention of tracking browser usage.
Location is a bit more tricky. I would say that's less common, but I've seen MDM solutions that offer location tracking as a feature
I'm speaking to what's possible to accomplish out of the box with G Suite's Advanced MDM offering, without an extreme amount of additional effort.
(This is relevant because, when prompted to install a MDM profile, the MDM provider such as G Suite is visible to the end user)
For g suite location is under Mobile management. They list it as a find my phone type of feature. There's even a picture of it on their marketing.
For an MDM solution on iOS there's a big list of supported profiles you can deploy after the MDM profile is installed ( see https://developer.apple.com/business/documentation/MDM-Proto... under "request types").
If the device belongs to the organization, you might not even know these profiles are installed, if it's a BYOD environment you know you are installing the MDM profile and if you open the settings page you can manually inspect which other sub-profiles have been installed by the MDM.
But you're right the MitM itself isn't built into the MDM, because that's a totally different product category ("Secure Web Gateway"). The MitM setup only works if you have an MDM to enforce the certificates and proxy setup upon the user.
I doubt any of these (call logs, SMS, web history) are possible on iOS even with an MDM profile installed, unless it's call logs from the company's own VoIP app or web history from its own browser app. SMS? Nope. On Android all these are possible for any app that's given the permissions, even without MDM.
Can anyone who knows more validate or confirm the veracity of this claim in the article?
Say WHAT? That's the entire premise of the article. Any sane person who have even a vague idea of what a MDM is will answer with a resounding NO.
Is there actually serious companies who ask their employees to install a MDM on their personal phone? The moment you install a MDM on a phone, that phone is no longer your own, it now belongs to the company.
Same reason that recent issue with all the Chrome extensions happens. A lot of people blindly click OK, just like we’ve been trained to do on privacy policies as well.
Every company that does BYOD?
I use Android so I'm relying on the Android for Work sandboxing, but truthfully I don't know the exact details of what that does and does not allow my employer to access. It does bother me, but I don't feel like I have a whole lot of choice. Being able to respond to Google Chat messages at any time (when away for lunch, for example), is feeling more and more like a requirement/expectation.
Also, commuting on the train pretty much requires mobile Hangouts support (which Google effectively makes impossible to use via a website if you're on Android), unless you want to always be at your desk in the office prior to the first meeting each day.
Very few people have even a vague idea of what a MDM is.
If an employer wants me to be reachable by phone they can give me a work phone. Why would I voluntarily turn my personal phone into a work phone?