Live data from Hacker News

MS Exchange “remote wipe” is a terrible, terrible bug

code.technically.us

101–110 of 117 posts

Re: MS Exchange “remote wipe” is a terrible, terrible bug

#101
post #54

Earlier quoted context omitted.

There seems to be two quite distinct scenarios where this could be used; when a phone is stolen, or when an employee is no longer trusted with company data (they're fired or leave) For the first scenario, I see no problem at all with remote wipe, but I do have a problem with the assumption that deliberate destruction of personal data is acceptable, for any reason. What if an employee had some paperwork at home? Would…

You're hyperventilating. Nobody has ever suggested that the RIAA or EA be able to wipe your phone. But plenty of companies have a policy that says that if you want to sync your phone with their corporate mail system, they need to be able to nuke your phone from orbit if something goes wrong. When you find the example of the company that requires you to purchase a personal phone and sync it with their corporate mail s…

Nobody has ever suggested that the RIAA or EA be able to wipe your phone.

Orrin Hatch: http://news.bbc.co.uk/2/hi/2999780.stm.

but don't pretend there's no valid reason for it.

If my house has been broken into before, there's a "valid reason" for me to install a tripwire that automatically fires a shotgun blast at the intruder. That won't go over well in court, and neither should this.

Re: MS Exchange “remote wipe” is a terrible, terrible bug

#102
post #72

Seems like we need something like vmware on phones. Then I can run the company's phone on my device. They can wipe, er, administer it any way they must. And I can still have one phone.

You appear to be talking about ARM's TrustZone technology.

I'm not. I'm just a dumb user waiting for my data to be unexpectedly wiped. Thanks for the pointer. What does it do?

Re: MS Exchange “remote wipe” is a terrible, terrible bug

#103
I'm confused by all the arguments that this feature should exist. Of course it should exist. Re-read the OP: The bug isn't the remote wipe ability, the bug is leaving it up to the administrators of the server to decide whether to inform users that the feature exists.

Google decided to do an end run around Apple's lack of support for push notifications by making Gmail an Exchange server. Until now, I had no idea that by going along with this I was granting Google remote wipe privileges on my phone.

Sure, Google do not appear at this time to want to wipe my phone for any reason, but how is it that I've been unknowingly trusting them with this power? This privilege is decidedly non-obvious. When I connect to an email server I kind of expect that I'm giving someone, somewhere the ability to read my mail. That's "obvious," and I don't need a warning dialog.

But what is obvious about granting Google the right to erase the pictures I've taken of my father-son Lego Jawa Sand Crawler project? Or my voice memos? Or the extensive notes I've been making of design ideas for my Javascript framework?

Let's stay on topic, folks. The question to be debated isn't whether companies should have remote wipe privileges, it's whether a device should allow a user to grant such privileges without putting up a simple warning dialog.

Re: MS Exchange “remote wipe” is a terrible, terrible bug

#104

Earlier quoted context omitted.

No, it is not criminal, it is an essential component of ensuring security in lost devices. It would be completely useless if it asked if it was ok to wipe the device. If you are unable to understand that Microsoft added a lot of stuff to the exchange protocol, and this is one of them, perhaps you are in the wrong field. This is not top secret information, it has been around since Windows CE, and is requested by all b…

In twenty years I have never seen any message in any publicly documented protocol that means "nuke yourself utterly", much less ever expect to see anyone knowingly implement such a thing. So I was also unaware of this appalling misfeature, as was the author of the article. I believe this has not been widely disclosed outside the sadistic IT control freak set, and that they are not getting informed consent that this i…

I wish I had more than one upmod to grant you for using the phrase informed consent. That's really the heart of this entire discussion.

Re: MS Exchange “remote wipe” is a terrible, terrible bug

#105

So, is there a way to safeguard against this? I assume when I connect to an exchange server at home it doesn't have root access to my laptop, right?

Amazed your question doesn't have upmods, it's very original.

Can my personal laptop be remotely wiped if I connect my email client to an exchange server? If not, why not? It seems to me that a laptop is even more likely to leak sensitive information out of email, like spread sheets and word documents.

Re: MS Exchange “remote wipe” is a terrible, terrible bug

#108

If an IT department did this to me without warning, I'd quit that day , CC'ing my manager and the IT guy's manager telling them exactly why they'll now have to spend months finding and training my replacement.

But you agreed to stick business data on your personal phone.

Re: MS Exchange “remote wipe” is a terrible, terrible bug

#109
post #20

Earlier quoted context omitted.

... Not if the microwaves are in your control. You can certainly police microwaves on your own campus. (Not that this is an intelligent idea.)

I think it's an intelligent idea if you're providing blanket coverage and idiots are setting up their own linksys's that can't even dhcp on due to mac filtering.

What does that have to do with hunting down microwave ovens?

Re: MS Exchange “remote wipe” is a terrible, terrible bug

#110
post #92
post #90

Earlier quoted context omitted.

syncing to someones pocket is fine if you can remote wipe it

But you can't guarantee that you can wipe it. What if it's not connected to the 3G network? What if the data has already been pulled off? What if it's been copied to a memory card on the phone? What if the phone doesn't properly implement this feature?

If you're using a Blackberry then you encrypt the entire device. The entire memory is encrypted with the device password and a wipe is triggered from too many incorrect passwords.

I don't know if the Exchange devices do the same thing - our company requires this kind of security, so we still only allow Blackberry.

Post reply on HN