Home > Ask the Information Security Experts > Data protection Questions & Answers > Are iPhone encryption features on the way?
Ask The Security UK Expert: Questions & Answers
EMAIL THIS

Are iPhone encryption features on the way?

>
QUESTION:
Should the fact that data can still not be encrypted on an iPhone disqualify the mobile device from an enterprise environment?


RELATED CONTENT
Data protection
How to detect if machines have been infected with Trojans, keyloggers
What are USB flash drive security best practices?
How to protect employees' personal information and passwords
What should be part of an employee termination checklist?
Are there keylogger monitors that can effectively spot malware?

Enterprise Data Storage
Safend expands data leakage prevention product to plug more gaps
TrueCrypt: How to get started with open source disk encryption
Report: Firms avoid encrypting backup tapes, databases
Encryption tips: How to secure a laptop
The real reason behind backup recovery disk failures
Infosec pros wake up to Excel spreadsheet security risks
How to enforce an enterprise data leak prevention policy
3ami allows employers to track use of USB storage devices
How to create a data classification policy
EMC adds configuration management with Configuresoft acquisition

Wireless Network Security: Setup, Issues and Threats
Configuring a Windows network infrastructure: Wired, wireless security
College learns lessons in choosing the right NAC appliance
GSM cell phone encryption crack may force operators to upgrade
How to keep networks secure when deploying an 802.11n upgrade
Researchers find thousands of flawed embedded devices
Wireless network guidelines for PCI DSS compliance
SMS attacks against BlackBerry certificate bug possible
Remote phone lock and GPS tracking counter smartphone security risks
Mobile device encryption a must, says Information Commissioner
MMS messaging spoof hack could have global ramifications

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
Serious Organized Crime Agency  (SearchSecurityUK.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary


Ken Munro EXPERT RESPONSE FROM: Ken Munro

Pose a Question
Other Security UK Categories
Meet all Security UK Experts
Become an Expert for this site
ANSWERED April 2009:
The iPhone should not be considered part of a secure mobile email environment. I believe Apple is working hard to improve its security and remote manageability right now, but today it is not suitable.

If an iPhone synced with an Exchange server is lost, there is currently no way to remotely wipe the device, or otherwise disable it, other than by changing domain credentials and contacting your telephone company to block the SIM card identifying the mobile user.

The stored data is not suitably protected by iPhone encryption, so any locally stored data (email and attachments, for example) is potentially accessible by the thief. Recent versions offer '10 strikes and wipe' for device passwords. This feature, though rarely implemented, allows the iPhone to wipe its user memory if too many incorrect PIN/passwords are entered. The BlackBerry has had the wipe function for a very long time, and Windows Mobile devices have had it more recently.

It is also trivial to spoof an OpenZone wireless access point and convince an iPhone user to part with their domain credentials over the air.

Several important vulnerabilities have been found in the iPhone, including some as part of the 50-vulnerability roll up patch released recently.

By contrast, BlackBerry and (to a degree) the Windows Mobile operating system offer significantly better remote management. This is why the BlackBerry is accredited for use in certain protectively marked environments as an enterprise mobile device. For instance, the Blackberry Enterprise Server (BES) offers the ability to manage almost every feature of a BlackBerry device remotely, including remote wipe. This is ideal for the corporate environment, where a lost/stolen device could lead to data theft. More recently, Windows Mobile devices have become almost as manageable remotely, without the need for an expensive BES.




Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice



Access Management: Authentication, Biometrics, Password Security
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2008 - 2010, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts