Live data from Hacker News

MS Exchange “remote wipe” is a terrible, terrible bug

code.technically.us

41–50 of 117 posts

Re: MS Exchange “remote wipe” is a terrible, terrible bug

#41
post #19

Actually, this has existed since exchange integration was first added to PocketPC (a long time ago). It allows companies to control the security of their data. Joining your personal phone to exchange is much like joining your personal computer to the corporate domain. You don't do it unless you want corporate IT to administer it and corporate policy allows it. Edit: I sympathize with people who lost data, and do agre…

Wiping your company's email, sure. But you don't seem to have a problem with wiping the entire contents of someone's personal device and (if I read the article correctly) rendering that device unusable thereafter (after a restore it remote wipes again) Would you be happy with just an email wipe, if that option were available?

After the remote device wipe completes the device is usable again unless they try to link to exchange again. In the cases I talked about they shouldn't be joining again.

In most cases there is more than just email, and the line between exchange and personal blurs. How do you remove the exchange data from a contact originating from exchange but updated with Facebook data? What about company restricted WiFi passwords? Attachments saved outside of the mail program?

It's complicated, and when properly used: a last resort.

Edit since I can't reply below: Linking with activesync is optional. The policies are part of the bargain. Your examples either weren't optional (RIAA) or were things you'd choose not to do (EA).

Re: MS Exchange “remote wipe” is a terrible, terrible bug

#43
post #29

Earlier quoted context omitted.

Why not just bitch at them both? And then call the police on the IT guys, since they just hacked your device. Doing your job isn't an excuse.

As far as they new, someone was hacking their servers, downloading unauthorized emails. This is completely what you would expect them to do. The fact you can't see this, and change your world view to understand what is really going on, suggests that you are very young and being unreasonable.

> This is completely what you would expect them to do.

And, sure, they expect evildoers to be using software that honors a remote-wipe command. Yeah, right.

Re: MS Exchange “remote wipe” is a terrible, terrible bug

#44
post #19

Actually, this has existed since exchange integration was first added to PocketPC (a long time ago). It allows companies to control the security of their data. Joining your personal phone to exchange is much like joining your personal computer to the corporate domain. You don't do it unless you want corporate IT to administer it and corporate policy allows it. Edit: I sympathize with people who lost data, and do agre…

You don't do it unless you want corporate IT to administer it

The problem is, there is no way a user will expect that they are giving away that privilege merely by adding an Exchange account to their personal phone. This is a gaping security hole in the mobile client software and it's entirely the fault of the phone developers. Just giving the server the name of my device without telling me is a breach, as far as I'm concerned.

It's not about data ownership, it's about access. Your data being on a device does not authorize you to access that device.

Re: MS Exchange “remote wipe” is a terrible, terrible bug

#45
post #28

Earlier quoted context omitted.

Look I have a degree in Computer Science, I wrote software to send the strings necessary to use IPOP, heck I even memorized the RFC number (1939). And in all this time, never did I once see anything on that protocol that could do anything more than download mail and delete the mail you had in your account. So I hear about Exchange and figure "oh just another protocol MS came up with, properly has extensions for calen…

No, it is not criminal, it is an essential component of ensuring security in lost devices. It would be completely useless if it asked if it was ok to wipe the device. If you are unable to understand that Microsoft added a lot of stuff to the exchange protocol, and this is one of them, perhaps you are in the wrong field. This is not top secret information, it has been around since Windows CE, and is requested by all b…

In twenty years I have never seen any message in any publicly documented protocol that means "nuke yourself utterly", much less ever expect to see anyone knowingly implement such a thing. So I was also unaware of this appalling misfeature, as was the author of the article. I believe this has not been widely disclosed outside the sadistic IT control freak set, and that they are not getting informed consent that this is possible before devices are reconfigured to permit it.

Re: MS Exchange “remote wipe” is a terrible, terrible bug

#46
post #19

Actually, this has existed since exchange integration was first added to PocketPC (a long time ago). It allows companies to control the security of their data. Joining your personal phone to exchange is much like joining your personal computer to the corporate domain. You don't do it unless you want corporate IT to administer it and corporate policy allows it. Edit: I sympathize with people who lost data, and do agre…

You don't do it unless you want corporate IT to administer it The problem is, there is no way a user will expect that they are giving away that privilege merely by adding an Exchange account to their personal phone. This is a gaping security hole in the mobile client software and it's entirely the fault of the phone developers. Just giving the server the name of my device without telling me is a breach, as far as I'm…

We don't require employees to link their personal phones. It's their choice, and the activesync policy is part of the bargain.

In fact, I'd personally recommend employees not link their phones. Work isn't so important it should be always on.

Re: MS Exchange “remote wipe” is a terrible, terrible bug

#47
post #28

Earlier quoted context omitted.

Look I have a degree in Computer Science, I wrote software to send the strings necessary to use IPOP, heck I even memorized the RFC number (1939). And in all this time, never did I once see anything on that protocol that could do anything more than download mail and delete the mail you had in your account. So I hear about Exchange and figure "oh just another protocol MS came up with, properly has extensions for calen…

No, it is not criminal, it is an essential component of ensuring security in lost devices. It would be completely useless if it asked if it was ok to wipe the device. If you are unable to understand that Microsoft added a lot of stuff to the exchange protocol, and this is one of them, perhaps you are in the wrong field. This is not top secret information, it has been around since Windows CE, and is requested by all b…

"No, it is not criminal, it is an essential component of ensuring security in lost devices."

You say that as if that is some sort of an argument. But there is no actual law or force in the universe that says that necessary steps to do something that you consider "securing your network" will therefore automatically not be "criminal". In fact once you start trying to think of what criminal activities someone might take in the name of "securing their network" it isn't that hard to come up with a very long list.

Something does not become legal merely because you have an excuse!

(Note I'm not saying this is illegal or not. That would take careful analysis of the law and probably a detailed specification of what jurisdiction we're talking about and the precise details of a specific hypothetical since it almost certainly goes both ways, depending. I'm just claiming the argument doesn't make much sense.)

Re: MS Exchange “remote wipe” is a terrible, terrible bug

#48
post #41

Earlier quoted context omitted.

Wiping your company's email, sure. But you don't seem to have a problem with wiping the entire contents of someone's personal device and (if I read the article correctly) rendering that device unusable thereafter (after a restore it remote wipes again) Would you be happy with just an email wipe, if that option were available?

After the remote device wipe completes the device is usable again unless they try to link to exchange again. In the cases I talked about they shouldn't be joining again. In most cases there is more than just email, and the line between exchange and personal blurs. How do you remove the exchange data from a contact originating from exchange but updated with Facebook data? What about company restricted WiFi passwords?…

There seems to be two quite distinct scenarios where this could be used; when a phone is stolen, or when an employee is no longer trusted with company data (they're fired or leave)

For the first scenario, I see no problem at all with remote wipe, but I do have a problem with the assumption that deliberate destruction of personal data is acceptable, for any reason. What if an employee had some paperwork at home? Would you condone burning their house to destroy it? Is a car bomb appropriate to destroy a briefcase left in a car?

What right does anyone have to destroy other people's property in the course of protecting their own? Would you support game manufacturers like EA being able to remote wipe your computer if they suspected you of running a pirate copy of a game? The RIAA if they suspect you of torrenting?

Re: MS Exchange “remote wipe” is a terrible, terrible bug

#49
post #14

So to connect to an Exchange server in iOS, Android or WebOS you have to give the server root on your phone? What sort of crazy security policy is that?

So you connect and store a bunch of confidential and important information on a device that you can leave at a bar?! What sort of security policy is that?

Re: MS Exchange “remote wipe” is a terrible, terrible bug

#50
post #28

Earlier quoted context omitted.

Look I have a degree in Computer Science, I wrote software to send the strings necessary to use IPOP, heck I even memorized the RFC number (1939). And in all this time, never did I once see anything on that protocol that could do anything more than download mail and delete the mail you had in your account. So I hear about Exchange and figure "oh just another protocol MS came up with, properly has extensions for calen…

No, it is not criminal, it is an essential component of ensuring security in lost devices. It would be completely useless if it asked if it was ok to wipe the device. If you are unable to understand that Microsoft added a lot of stuff to the exchange protocol, and this is one of them, perhaps you are in the wrong field. This is not top secret information, it has been around since Windows CE, and is requested by all b…

It's my phone, my property. Nobody gets to access it without my permission, period. If someone sneaks a back door onto my phone, that is criminal.

If experienced developers don't know about this feature, there is no earthly way that the average user can be considered to have consented to access.

My boss can't kick down my door and ransack my house to find secret documents he gave me. If I violate my NDA, he can seek to remedy that in civil court.

Post reply on HN