Live data from Hacker News

MS Exchange “remote wipe” is a terrible, terrible bug

code.technically.us

51–60 of 117 posts

Re: MS Exchange “remote wipe” is a terrible, terrible bug

#51
post #46

Earlier quoted context omitted.

You don't do it unless you want corporate IT to administer it The problem is, there is no way a user will expect that they are giving away that privilege merely by adding an Exchange account to their personal phone. This is a gaping security hole in the mobile client software and it's entirely the fault of the phone developers. Just giving the server the name of my device without telling me is a breach, as far as I'm…

We don't require employees to link their personal phones. It's their choice, and the activesync policy is part of the bargain. In fact, I'd personally recommend employees not link their phones. Work isn't so important it should be always on.

It's not part of the bargain if you don't tell them about it.

Re: MS Exchange “remote wipe” is a terrible, terrible bug

#52
post #31

Uhm. Data loss is a huge deal. HUGE. This isn't an evil feature. It isn't a pointless feature. In fact it's a critical feature in the running of an organisation. Email. Calendar. Address Book. A gold mine of absurdly sensitive data. If you want corporate email on your phone, expect to have the possibility of a remote wipe. It isnt Microsofts fault that people use it maliciously. If you ask the user "do you wish to al…

> If you ask the user "do you wish to allow administrators to remote wipe your phone allow/deny?" what do you think they'll click ???

They will probably click "deny", and then not be allowed to connect to the server. Problem solved!

Re: MS Exchange “remote wipe” is a terrible, terrible bug

#53
post #37
post #27

Do folks here not work in a regulated industry? We went through a yearly course on How To Not End Up On Front Page of The Paper For Leaking Customer Information. One core part of that is putting up with a little hassle with regards to managing one's cell phone, such as a) not using it for work if at all possible and b) very carefully regulating what got saved on it if it was used for work. (Nobody at my office should…

> (Nobody at my office should have more than "P. McKenzie" and my phone number saved on their phone. Including full name, email address, a photo, my address, and the like would give me a cause of action against the company if the phone was ever lost or if that information were misused.) That really can give you cause of action against a company? In a similar matter what if I had all of that information on my personal…

No, that's not the real problem. The transmission of sensitive information through corporate email is commonplace. Formally-classified protected information like HIPAA PI or payment card data shouldn't, of course, be emailed, but information that can be traced back to PI is sent routinely.

Regardless of whether it should or shouldn't happen, IT controls people have to assume it will. The contract for syncing with a corporate Exchange server, in many places, simply requires you to allow your phone to be wiped.

If you don't like it, don't sync with your company's Exchange server. What's so hard about that?

Re: MS Exchange “remote wipe” is a terrible, terrible bug

#54
post #41

Earlier quoted context omitted.

After the remote device wipe completes the device is usable again unless they try to link to exchange again. In the cases I talked about they shouldn't be joining again. In most cases there is more than just email, and the line between exchange and personal blurs. How do you remove the exchange data from a contact originating from exchange but updated with Facebook data? What about company restricted WiFi passwords?…

There seems to be two quite distinct scenarios where this could be used; when a phone is stolen, or when an employee is no longer trusted with company data (they're fired or leave) For the first scenario, I see no problem at all with remote wipe, but I do have a problem with the assumption that deliberate destruction of personal data is acceptable, for any reason. What if an employee had some paperwork at home? Would…

You're hyperventilating. Nobody has ever suggested that the RIAA or EA be able to wipe your phone. But plenty of companies have a policy that says that if you want to sync your phone with their corporate mail system, they need to be able to nuke your phone from orbit if something goes wrong.

When you find the example of the company that requires you to purchase a personal phone and sync it with their corporate mail server, you be sure and let us know. Until then, by all means, scream from the rooftops that this feature exists... but don't pretend there's no valid reason for it.

Re: MS Exchange “remote wipe” is a terrible, terrible bug

#55
post #6

Earlier quoted context omitted.

Well, if people are using un-approved personal devices on the corporate network, it seems there is some fault on both sides. Assuming there is policy addressing this issue.

No, not really. If using an un-approved device on the company exchange compromises corporate security, you need to either lecture me, take "disciplinary action", or both. Nuking my iPhone from orbit is neither.

You leave your phone in a bar. You tell your IT team about it the next day. You're holding out hope that it'll get turned in. Meanwhile, god only knows what's on it and who's got it. Sure, you're fired and all, but meanwhile: you handed a bunch of sensitive data out to the world, and firing you doesn't solve that problem.

Should you be told that this is the policy? Of course. But what's the rest of the complaint here?

Re: MS Exchange “remote wipe” is a terrible, terrible bug

#56
post #53
post #37

Earlier quoted context omitted.

> (Nobody at my office should have more than "P. McKenzie" and my phone number saved on their phone. Including full name, email address, a photo, my address, and the like would give me a cause of action against the company if the phone was ever lost or if that information were misused.) That really can give you cause of action against a company? In a similar matter what if I had all of that information on my personal…

No, that's not the real problem. The transmission of sensitive information through corporate email is commonplace. Formally-classified protected information like HIPAA PI or payment card data shouldn't, of course, be emailed, but information that can be traced back to PI is sent routinely. Regardless of whether it should or shouldn't happen, IT controls people have to assume it will. The contract for syncing with a c…

> The contract for syncing with a corporate Exchange server, in many places, simply requires you to allow your phone to be wiped. > If you don't like it, don't sync with your company's Exchange server. What's so hard about that?

The problem that the posts points out is that there's no warning about this "contract" whatsoever. No matter what mobile device I've ever used, I have never, ever had a dialog tell me that by syncing my phone with an Exchange server I'm letting my company's IT department hold my personal information by the balls.

Additionally, we're talking about a lack of separation between two entities' data (personal & company-owned data).

If I had a user access clause for my website, "by accessing content on this website I am granted full access to indiscriminately wipe any and all data on your device, belonging to me or not" and was given the capability to do it - that would be ludicrous. The only difference I see is that I'm not in an employer relationship with my users. Even still, an employer-employee relationship with a company does not grant them the right to delete any and all data on any device of mine.

Also, since we're in HN (startup city, what?) who has ever worked for a startup that DISCOURAGED working from home on a personal laptop or having access to email 24x7? I've certainly never worked for one.

Re: MS Exchange “remote wipe” is a terrible, terrible bug

#57
post #54

Earlier quoted context omitted.

There seems to be two quite distinct scenarios where this could be used; when a phone is stolen, or when an employee is no longer trusted with company data (they're fired or leave) For the first scenario, I see no problem at all with remote wipe, but I do have a problem with the assumption that deliberate destruction of personal data is acceptable, for any reason. What if an employee had some paperwork at home? Would…

You're hyperventilating. Nobody has ever suggested that the RIAA or EA be able to wipe your phone. But plenty of companies have a policy that says that if you want to sync your phone with their corporate mail system, they need to be able to nuke your phone from orbit if something goes wrong. When you find the example of the company that requires you to purchase a personal phone and sync it with their corporate mail s…

hyperboling might be a better verb :) Looks like cross-cultural communication via a text only medium has meant you've completely missed both the tone and the content I was trying to present. Sorry about that

Re: MS Exchange “remote wipe” is a terrible, terrible bug

#58
post #10
post #8

Earlier quoted context omitted.

Yeah, in this case you need to ban the devices, not wipe them...

There could be important data still on the device itself, I imagine the argument would be. Seems to me how it should work is that the device's user defines a PIN number for his device. Should the device be lost, the user could provide the IT guys with that PIN number, which would be required for the "remote nuke" feature to be used.

That assumes the user is a willing participant in that matter and will give over the PIN.

Suppose the user is a remote employee who's just been sacked -- the boss and IT are hundreds of miles away and can't just take the phone from him. That phone has some product-related emails on it that, if they were to get out, would tank the company's stock price. They have to be able to wipe that data without waiting for the user to hand over the key.

Re: MS Exchange “remote wipe” is a terrible, terrible bug

#59
post #56
post #53

Earlier quoted context omitted.

No, that's not the real problem. The transmission of sensitive information through corporate email is commonplace. Formally-classified protected information like HIPAA PI or payment card data shouldn't, of course, be emailed, but information that can be traced back to PI is sent routinely. Regardless of whether it should or shouldn't happen, IT controls people have to assume it will. The contract for syncing with a c…

> The contract for syncing with a corporate Exchange server, in many places, simply requires you to allow your phone to be wiped. > If you don't like it, don't sync with your company's Exchange server. What's so hard about that? The problem that the posts points out is that there's no warning about this "contract" whatsoever. No matter what mobile device I've ever used, I have never, ever had a dialog tell me that by…

We simply disallow people working on company projects with personal equipment.

If I drank enough rye to kill the requisite number of brain cells required for me to allow people to sync their personal gear with our IT, I'd definitely tell people "we will be nuking your gear from orbit periodically as a precautionary measure".

Re: MS Exchange “remote wipe” is a terrible, terrible bug

#60
post #52
post #31

Uhm. Data loss is a huge deal. HUGE. This isn't an evil feature. It isn't a pointless feature. In fact it's a critical feature in the running of an organisation. Email. Calendar. Address Book. A gold mine of absurdly sensitive data. If you want corporate email on your phone, expect to have the possibility of a remote wipe. It isnt Microsofts fault that people use it maliciously. If you ask the user "do you wish to al…

> If you ask the user "do you wish to allow administrators to remote wipe your phone allow/deny?" what do you think they'll click ??? They will probably click "deny", and then not be allowed to connect to the server. Problem solved!

Exactly. It astounds me how many people are managing to miss this point!
Post reply on HN