Live data from Hacker News

Show HN: MicroMDM – Open Source MDM Server for Apple Devices

micromdm.io

31–40 of 48 posts

Re: Show HN: MicroMDM – Open Source MDM Server for Apple Devices

#31

Earlier quoted context omitted.

Anyone can use DEP, just need a DUNS number to enroll into the program, and then to purchase devices from apple direct, or from an approved reseller. Unfortunately you cannot retroactively add devices that were already purchased. DEP is not required for the VPN profile configs, that can be applied with just MDM (or even manually). The VPN payloads are documented here https://developer.apple.com/enterprise/documentati…

> purchase devices from apple direct, or from an approved reseller. Unfortunately you cannot retroactively add devices that were already purchased. So you need to provide a DEP-authorized account number to the salesperson in an Apple store? Is this possible when buying online from apple.com? Any idea why Apple does not provide a service to test whether a device serial number is DEP-managed? It would deter attempts to…

You must buy your devices through the enterprise store, and then it is automatically linked to DEP.

Any idea why Apple does not provide a service to test whether a device serial number is DEP-managed?

Because once you know the serial number of a DEP device you can enroll into the MDM. There is virtually no security. See https://duo.com/labs/research/mdm-me-maybe

Re: Show HN: MicroMDM – Open Source MDM Server for Apple Devices

#32
post #2

I'm curious do any HN readers manage their personal devices through MDM with their own profiles, and what benefits are you seeing from that?

I don't, but I absolutely would for my children's devices (when I have children). Limiting time using certain apps, etc would be great.

Re: Show HN: MicroMDM – Open Source MDM Server for Apple Devices

#33
post #2

I'm curious do any HN readers manage their personal devices through MDM with their own profiles, and what benefits are you seeing from that?

I'm administrator for GSuite for the school I'm a trustee of, so my personal (Android) device is enrolled by virtue of me wanting to know how it works and also wanting my school email on that device. I'm not sure it would be worthwhile setting up for personal use -- the policies it lets you set aren't doing anything other than ensuring you're following best practices (like setting a screen lock) so you don't gain any…

If you don't care about the managed Google Play store, you could always use Google's TestDPC app (or create your own) to create a work profile ("do-not-use-in-production" warnings notwithstanding): https://play.google.com/store/apps/details?id=com.afwsamples...

That said, it might be more straightforward to just use another user on your device

Re: Show HN: MicroMDM – Open Source MDM Server for Apple Devices

#34

Earlier quoted context omitted.

> purchase devices from apple direct, or from an approved reseller. Unfortunately you cannot retroactively add devices that were already purchased. So you need to provide a DEP-authorized account number to the salesperson in an Apple store? Is this possible when buying online from apple.com? Any idea why Apple does not provide a service to test whether a device serial number is DEP-managed? It would deter attempts to…

You must buy your devices through the enterprise store, and then it is automatically linked to DEP. Any idea why Apple does not provide a service to test whether a device serial number is DEP-managed? Because once you know the serial number of a DEP device you can enroll into the MDM. There is virtually no security. See https://duo.com/labs/research/mdm-me-maybe

Thanks for the pointer, some good reasons there to avoid DEP.

Re: Show HN: MicroMDM – Open Source MDM Server for Apple Devices

#35

Earlier quoted context omitted.

> purchase devices from apple direct, or from an approved reseller. Unfortunately you cannot retroactively add devices that were already purchased. So you need to provide a DEP-authorized account number to the salesperson in an Apple store? Is this possible when buying online from apple.com? Any idea why Apple does not provide a service to test whether a device serial number is DEP-managed? It would deter attempts to…

You must buy your devices through the enterprise store, and then it is automatically linked to DEP. Any idea why Apple does not provide a service to test whether a device serial number is DEP-managed? Because once you know the serial number of a DEP device you can enroll into the MDM. There is virtually no security. See https://duo.com/labs/research/mdm-me-maybe

There is reasonable security. From your link:

> an attacker that obtains such a serial number ... will be able to enroll a device of their own as if it were owned by the organization, as long as it's not currently enrolled in the MDM server.

So, the rule is at-most-once enrollment.

And further down:

> some organizations elect not to require user authentication as part of MDM enrollment.

IOW, if you are not enabling authentication, you have only yourself to blame.

Re: Show HN: MicroMDM – Open Source MDM Server for Apple Devices

#36

Earlier quoted context omitted.

Do you know if a small business can use DEP features? Could per-app VPNs be used without DEP? If so, could they be used with MicroMDM, native iOS IPSEC client and an open-source VPN server, or is a 3rd-party VPN client like Cisco required for per-app VPN?

Anyone can use DEP, just need a DUNS number to enroll into the program, and then to purchase devices from apple direct, or from an approved reseller. Unfortunately you cannot retroactively add devices that were already purchased. DEP is not required for the VPN profile configs, that can be applied with just MDM (or even manually). The VPN payloads are documented here https://developer.apple.com/enterprise/documentati…

You can add iOS devices to DEP if they were not purchased when you had your business account set up using Apple Configurator.

https://support.jamfnow.com/hc/en-us/articles/360000004483-U...

Re: Show HN: MicroMDM – Open Source MDM Server for Apple Devices

#37

what other open source MDM software is out there that aren't Apple-only? Specifically I'd like to manage Android phones and maybe Linux laptops (but I doubt I'll find that)

I think you largely get what you pay for. Industry standard is either AirWatch or Soti.

Re: Show HN: MicroMDM – Open Source MDM Server for Apple Devices

#38

Hi, I'm the author(along with several other developers). MicroMDM is used in some enterprise environments and was recently mentioned in a number of security presentations regarding Apple's MDM and Device Enrollment Program services. https://duo.com/labs/research/mdm-me-maybe https://i.blackhat.com/us-18/Thu-August-9/us-18-Endahl-A-Dee...

I’m one of the security researchers that zalmoxes linked above (the Black Hat talk) =)

Duo very nicely gave multiple shout outs in their post. Including to zalmoxes (above), as well as my co-presenter and I. Sadly the traditional vendors in the space don’t have a track record of caring about security engineering. I’m glad that Duo’s latest research emphasizes the importance of authenticating the device enrollment process in particular. We touched on this in our whitepaper^, but it wasn’t a primary focus of our research and we didn’t tie it back to the shortcomings of DEP’s lack of verification around device identity. Extremely happy to see more focus on this stuff.

^See the vendor security checklist section of our whitepaper. Specifically, the bit about using an HMAC within the SCEP payload.

Full transparency: I’m cofounder/CSO of a security focused product in the MDM space (fleetsmith.com).

Re: Show HN: MicroMDM – Open Source MDM Server for Apple Devices

#39
post #14
post #7

Earlier quoted context omitted.

Apple has absolutely no desire to go into the device management business. They make the devices, they don't provide IT departments with any in house tools, the entire macOS management ecosystem has risen from a need and it's a mish mash of different vendors / open source tools / approaches to skin the cat that is device management.

They already took a baby step in by acquiring TestFlight. It's a more dev/QA-centric product, but it overlaps with MDM. Google is already in the MDM space for Chrome devices. Apple has already been remarkably successful in the enterprise space despite seemingly never going after it. Vendors like Square are deploying thousands of iPads to retail spaces. I think there's a huge opportunity there.

TestFlight helped solve very real problems iOS developers had back in the day when it came to managing beta testing etc, and the acquisition was clearly developer tools focused for Apple. I don’t think it’s sensible to read too much MDM ambition (if any really) on Apple’s part into that particular acquisition.

MDM is a very “enterprisey” market for Apple specifically, historically they’ve been more than happy to let others fight for the few dollars it typically brings in relative to their giant consumer/hardware businesses. Even Tim Cook has made the argument that letting businesses like IBM handle the enterprise cruft helps keep Apple’s focus on just making great consumer products.

> https://www.recode.net/2014/7/15/11628872/apple-and-ibm-ceos...

Re: Show HN: MicroMDM – Open Source MDM Server for Apple Devices

#40
post #2

I'm curious do any HN readers manage their personal devices through MDM with their own profiles, and what benefits are you seeing from that?

I manage the personal devices of my family members (wife, parents, in-laws) through MDM. My parents and in-laws are quite tech-illiterate, so it helps to be able to enforce some restrictions via profiles to prevent them from doing stupid things to their own devices, and thus reduce the time I have to spend on providing tech support (across the ocean no less). It's also useful for distributing Wi-Fi/VPN configs so I can enforce that VPN must be used on untrusted Wi-Fi, for example.
Post reply on HN