Live data from Hacker News

MS Exchange “remote wipe” is a terrible, terrible bug

code.technically.us

11–20 of 117 posts

Re: MS Exchange “remote wipe” is a terrible, terrible bug

#11
The problem is that right now there aren't granular enough controls of remote devices to allow people to adequately differentiate between approved ones and illicit ones. The fault lies on both the side of the client device software and the server side software.

The same goes for Gmail (Google Apps Premium Edition only) and Android (or anything else using Google Sync). You can enable/disable IMAP & POP for the domain and if you enable it you open the floodgates. You can selectively enable/disable users via API but they can toggle it back on their own. If you setup Google Sync instead of IMAP/POP you can remotely wipe devices but you can't do anything except wipe everything and there is no inbuilt method to notify the user first.

Exchange, as described in the blog post, is equally bad. I'm confident things will improve in 2011 but it's unpleasant right now. The best thing companies can do is to set a clear policy on what's allowed and what isn't based on their data security needs, and never violate the users' trust.

Re: MS Exchange “remote wipe” is a terrible, terrible bug

#12
post #6
post #4

In defense of this feature, it's very important for when a phone is lost. However, I agree, deleting peoples' data for reasons other than the device was compromised is just a sadistic thing to do.

Well, if people are using un-approved personal devices on the corporate network, it seems there is some fault on both sides. Assuming there is policy addressing this issue.

Their "approval" is insufficient. If they want me to carry a device with data which they have the power to destroy, it's not really mine, so they are going to have to buy one for me. Remote wipe is the kind of thing you could be prosecuted for … if you weren't doing it to a private citizen.

Re: MS Exchange “remote wipe” is a terrible, terrible bug

#13
This is one of the reasons I use a third-party app (NitroDesk TouchDown) for reading Exchange mail on my Android phone. If someone hits "remote wipe" it'll only delete your Exchange data, the rest of your phone remains untouched.

http://groups.google.com/group/nitrodesk/browse_thread/threa...

The app doesn't have permission to wipe the entire phone even if it wanted to.

Re: MS Exchange “remote wipe” is a terrible, terrible bug

#15
post #9
post #3

Bug? No this was done intentionally. Does anybody know how you disable that "feature"? Preferably in such a way that it causes maximum harm to the organization that uses it.

Don't connect personal devices to corporate exchange?

Bingo.

Re: MS Exchange “remote wipe” is a terrible, terrible bug

#16

I work in IT and my boss is precisely like this. We don't manage mobiles but wireless. He's talked about scanning the multi-campus network to find unauthorized microwaves that he can have removed. Because of course, it might cause _some_ interference for 30 seconds at a time right? Yeah.

If you are in the US, it's likely illegal for your boss to try to regulate microwave ovens based on causing wifi interference - that's solely the job of the FCC.

The regulations that allow the use of 2.4Ghz ISM band require you to accept that interference....

Re: MS Exchange “remote wipe” is a terrible, terrible bug

#17
post #6

Earlier quoted context omitted.

Well, if people are using un-approved personal devices on the corporate network, it seems there is some fault on both sides. Assuming there is policy addressing this issue.

Sure, but you send out an Email warning people first. There's no reason to wipe people's devices unless they are willfully defying policy, and even then, you've got a list of the people doing it - just go to their office and talk to them in person (involve their manager if needed). Wiping a personal device to "send a message" is passive-aggressive and totally destructive to morale.

It's also quite likely completely illegal - warning or not.

It's a personal device - the company has no rights to it.

Re: MS Exchange “remote wipe” is a terrible, terrible bug

#18
post #6
post #4

In defense of this feature, it's very important for when a phone is lost. However, I agree, deleting peoples' data for reasons other than the device was compromised is just a sadistic thing to do.

Well, if people are using un-approved personal devices on the corporate network, it seems there is some fault on both sides. Assuming there is policy addressing this issue.

No, not really. If using an un-approved device on the company exchange compromises corporate security, you need to either lecture me, take "disciplinary action", or both. Nuking my iPhone from orbit is neither.

Re: MS Exchange “remote wipe” is a terrible, terrible bug

#19
Actually, this has existed since exchange integration was first added to PocketPC (a long time ago). It allows companies to control the security of their data.

Joining your personal phone to exchange is much like joining your personal computer to the corporate domain. You don't do it unless you want corporate IT to administer it and corporate policy allows it.

Edit: I sympathize with people who lost data, and do agree that the phone should warn you before completing the join. That said, as a business owner, I only allow exchange (and not POP or IMAP) for exactly this reason. I need to be able to wipe the company data if a phone is lost, or someone is fired (and not cooperative), etc. The real world isn't always nice.

Also, the full device wipe is by design, and the feature is called "Remote Device Wipe." The details can be found here:

http://technet.microsoft.com/en-us/library/bb124591.aspx

Note that the storage card is also wiped (where attachments and other sensitive data may be saved).

Re: MS Exchange “remote wipe” is a terrible, terrible bug

#20
post #16

I work in IT and my boss is precisely like this. We don't manage mobiles but wireless. He's talked about scanning the multi-campus network to find unauthorized microwaves that he can have removed. Because of course, it might cause _some_ interference for 30 seconds at a time right? Yeah.

If you are in the US, it's likely illegal for your boss to try to regulate microwave ovens based on causing wifi interference - that's solely the job of the FCC. The regulations that allow the use of 2.4Ghz ISM band require you to accept that interference....

... Not if the microwaves are in your control. You can certainly police microwaves on your own campus. (Not that this is an intelligent idea.)
Post reply on HN