Live data from Hacker News

MS Exchange “remote wipe” is a terrible, terrible bug

code.technically.us

31–40 of 117 posts

Re: MS Exchange “remote wipe” is a terrible, terrible bug

#31
Uhm. Data loss is a huge deal. HUGE.

This isn't an evil feature. It isn't a pointless feature. In fact it's a critical feature in the running of an organisation.

Email. Calendar. Address Book. A gold mine of absurdly sensitive data.

If you want corporate email on your phone, expect to have the possibility of a remote wipe.

It isnt Microsofts fault that people use it maliciously.

If you ask the user "do you wish to allow administrators to remote wipe your phone allow/deny?" what do you think they'll click ???

People don't care about data loss. Educate someone on how to not lose data, then a week later give them a laptop with a password protected screen saver/login - first thing they'll try to do is remove password.

The amount of company phones I see with no passcode lock is astounding - I can pick your phone up, forward emails to myself and have all your information. Bang.

Don't think data loss is a big deal? If you google "PA Consulting" a top link is how they lost a USB drive.

Re: MS Exchange “remote wipe” is a terrible, terrible bug

#32
post #28
post #9

Earlier quoted context omitted.

Don't connect personal devices to corporate exchange?

Look I have a degree in Computer Science, I wrote software to send the strings necessary to use IPOP, heck I even memorized the RFC number (1939). And in all this time, never did I once see anything on that protocol that could do anything more than download mail and delete the mail you had in your account. So I hear about Exchange and figure "oh just another protocol MS came up with, properly has extensions for calen…

No, it is not criminal, it is an essential component of ensuring security in lost devices. It would be completely useless if it asked if it was ok to wipe the device.

If you are unable to understand that Microsoft added a lot of stuff to the exchange protocol, and this is one of them, perhaps you are in the wrong field. This is not top secret information, it has been around since Windows CE, and is requested by all big businesses.

Re: MS Exchange “remote wipe” is a terrible, terrible bug

#33
post #29
post #25

He's blames the remote wipes on the local IT guys. Calls them sadists. But I bet they are just doing what their corporate policies require them to do. The policies are written by the suits in management, not the local IT guys. If you want to bitch, bitch at them.

Why not just bitch at them both? And then call the police on the IT guys, since they just hacked your device. Doing your job isn't an excuse.

As far as they new, someone was hacking their servers, downloading unauthorized emails. This is completely what you would expect them to do.

The fact you can't see this, and change your world view to understand what is really going on, suggests that you are very young and being unreasonable.

Re: MS Exchange “remote wipe” is a terrible, terrible bug

#34
post #26

Earlier quoted context omitted.

Sure, but you send out an Email warning people first. There's no reason to wipe people's devices unless they are willfully defying policy, and even then, you've got a list of the people doing it - just go to their office and talk to them in person (involve their manager if needed). Wiping a personal device to "send a message" is passive-aggressive and totally destructive to morale.

They typed "AGREE" to the policy on day one when they were hired. IT is 2000 miles away. No one from IT is going to visit their office. They are going to wipe the device per corporate policy.

They have the right to do that, perhaps, but it's still not very nice.

People don't do good work when their employer is mean to them, regardless of what they signed. What is your "destroying potentially confidential data" is their "leaving to improve your competitor's product while you spend nine months trying to find a replacement".

Balance is the key.

Re: MS Exchange “remote wipe” is a terrible, terrible bug

#36
Not sure about other Android versions, but my 2.2 warned me about this when I set up my Exchange account. It also warns me about this every time it first connects to Exchange after a reboot.

Not much I can do about it. I more or less trust my IT guys not to be dicks so I don't lose any sleep over it. But short of carrying two phones, there's no way for me to separate personal and work devices. I do keep a nandroid backup on my personal netbook though.

Re: MS Exchange “remote wipe” is a terrible, terrible bug

#37
post #27

Do folks here not work in a regulated industry? We went through a yearly course on How To Not End Up On Front Page of The Paper For Leaking Customer Information. One core part of that is putting up with a little hassle with regards to managing one's cell phone, such as a) not using it for work if at all possible and b) very carefully regulating what got saved on it if it was used for work. (Nobody at my office should…

> (Nobody at my office should have more than "P. McKenzie" and my phone number saved on their phone. Including full name, email address, a photo, my address, and the like would give me a cause of action against the company if the phone was ever lost or if that information were misused.)

That really can give you cause of action against a company?

In a similar matter what if I had all of that information on my personal phone, am I correct in assuming that it shouldn't give you the right to sue if that information were released. (As it assumes you either gave me that information, or it was obtained through you in some way)

And in the case of the email attachment, if you are sending radioactively sensitive customer data in any way through email isn't that the real problem and not that the phone could get out.

Re: MS Exchange “remote wipe” is a terrible, terrible bug

#38

If an IT department did this to me without warning, I'd quit that day , CC'ing my manager and the IT guy's manager telling them exactly why they'll now have to spend months finding and training my replacement.

I'd probably also send them a bill for the cost to me, in time and effort, or restoring all my data.

The simple answer is not to store company email on your phone. Then you shouldn't have to worry about this.

Re: MS Exchange “remote wipe” is a terrible, terrible bug

#39
post #19

Actually, this has existed since exchange integration was first added to PocketPC (a long time ago). It allows companies to control the security of their data. Joining your personal phone to exchange is much like joining your personal computer to the corporate domain. You don't do it unless you want corporate IT to administer it and corporate policy allows it. Edit: I sympathize with people who lost data, and do agre…

Wiping your company's email, sure. But you don't seem to have a problem with wiping the entire contents of someone's personal device and (if I read the article correctly) rendering that device unusable thereafter (after a restore it remote wipes again)

Would you be happy with just an email wipe, if that option were available?

Re: MS Exchange “remote wipe” is a terrible, terrible bug

#40
post #19

Actually, this has existed since exchange integration was first added to PocketPC (a long time ago). It allows companies to control the security of their data. Joining your personal phone to exchange is much like joining your personal computer to the corporate domain. You don't do it unless you want corporate IT to administer it and corporate policy allows it. Edit: I sympathize with people who lost data, and do agre…

Correct. Don't blame the feature. It's designed to protect from lost phones. Not only can IT wipe your phone (presumably at your request), but you can actually wipe your own phone from Outlook Web Access.

What's interesting is this: the ability to hook up a phone via ActiveSync (the protocol in question) can be configured per account. If IT did not want him to hook up his phone, they should have not given him those rights. Wiping devices like this is a bad idea.

But don't blame the feature.

(full disclosure: I work on the MS Exchange team)

Post reply on HN