Apple betrays the iPhone's business hopes
tech.yahoo.com
tech.yahoo.com
Given that the limitation (the ability to handle on-device encryption) only affects pre-3GS phones I would guess that it's a performance thing and therefore not an issue on the desktop.
This article is very hard to follow in that the author will reverse position each paragraph, in one condemning Apple for releasing something that is not secure and in the next complaining when non-secure functionality is eliminated.
The Palm Pre is mentioned as an alternative but no evidence is given to indicate the same problem doesn't exist on that platform as well, and it would be interesting to know if other remote-exchange-access devices (webmail, blackberry, etc.) provide client or device-side encryption of local files.
He's saying that Apple betrayed trust by implementing secure feature insecurely (while claiming that it was working correctly) and when they decided to actually do something about it, they just quietly pulled out the rug from under their users. There was no Apple announcement or apology. Just a checklist item burying deep in a list of changes in an OS update. That's why he says 'double betrayal.'
This may sound like a stretch, and Apple themselves have decided that it's not sufficient, but while the files themselves my not be encrypted the filesystem of the iPhone itself is protected from all but deliberate (and possibly illegal) fiddling by third-parties. In this way it's not completely dishonest for the iPhone's exchange client to report to the Exchange server that the local files are secured.
Like I said it's a stretch, but perhaps the original implementation wasn't pure malice/ignorance on Apple's part.
This is yet one more in a string of under-researched, hysterical articles from InfoWorld that are making that magazine the tech equivalent of US! Weekly.
I don't believe for a second that "everyone in corporate IT" knew this and yet allowed their users to connect with iPhones and endanger the security of the network.
Again, I don't know that the article's claims are accurate, but your comment clearly does not clash with the aforementioned claims.
Probably not many. Many products, including ones never patched without a paid upgrade, have had known security flaws. Including products like Windows, Exchange and Office. Hasn't stopped their acceptance as industry standard tools has it? In terms of how it effects the iPhone enterprise user base we should consider a couple facts:
iPhone OS 3.0 was released at the same time as the iPhone 3GS hardware (June 19th 2009)
iPhone OS 2.x did not support Exchange.
So I think you can make a reasonable case that before June 19th 2009 very few of these encryption-required companies were buying iPhones since they simply didn't support Exchange. Post June 19th 2009 how many companies were buying non-GS models? We could further sub-divide this based on the discovery of the encryption loop hole which you would hope any of these encryption-required companies were aware of. So by my crude calculations I think there is probably a month period where companies may have been buying non-GS iPhones with an expectation of pure encryption-required support.
This is factually incorrect. I've been using the Exchange integration on the iPhone since fall 2008.
Granted, as this article shows, Apple has been reporting false information to Exchange, but the Exchange support has been there.
echo 'here''s your problem'' | {
apple
exchange
}
hmmThis is like the don't "copy bit" for DRM if you don't follow it it doesn't matter. Apple never said their device supported on device encryption that I heard so why are all of these businesses suddenly surprised.?
Actually, their software made exactly that claim, and falsely, if I read the article correctly.
I don't know about the marketing materials, but for the past year, the software itself has made the claim.
Why bring marketing into it?
Well yeah, but does that really mean anything?
All that phrase says to me is "you're technically right, but I'm going to adjust my value system until it doesn't matter to me"
e.g:
Person 1: You said you'd love me forever!
Person 2: Well yeah, but does that really mean anything?
1) What Apple says the phone supported via product literature, aka marketing.
2) What the iPhone software does to implement exchange support.
Misrepresenting #1 is a crime that the FTC or some government body could fine them for. #2 on the other hand companies do all of the time to make their devices work with proprietary software. This article is implying a marketing lie while describing what is a software compatibility hack or perhaps an honest bug. Either way saying "I simply can't count on Apple to do the right thing." is way melodramatic.
yes, there was. Apple's software made that claim to exchange.