Live data from Hacker News

Apple is making corporate ‘BYOD’ programs less invasive to user privacy

techcrunch.com

21–30 of 148 posts

Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy

#21

> Using the per-app VPN feature, traffic from the Mail, Contacts and Calendars built-in apps will only go through the VPN if the domains match that of the business. Shame that Apple doesn't take this one step further and do it system-wide.

If you mean you want a VPN to auto-connect when certain domains are used, I'm pretty sure this feature already exists since at least iOS 8.

See https://developer.apple.com/business/documentation/Configura... and go to page 95, where it describes the OnDemandRules key for VPN configuration, which supports matching criteria based on domain names, SSID, interface type, and server reachability.

EDIT: I misunderstood. The point is not to get the VPN to auto-connect, but to use the VPN for only certain domains.

Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy

#22

> Using the per-app VPN feature, traffic from the Mail, Contacts and Calendars built-in apps will only go through the VPN if the domains match that of the business. Shame that Apple doesn't take this one step further and do it system-wide.

Given their commitment to privacy as a selling point, it would be nice if Apple provided an integrated VPN service (say included with the upper iCloud tiers). For now I’m on the waitlist for Cloudflare’s offering - their DNS works fantastic.

I doubt if Apple would start a VPN service. Even if it did, it’d have restrictions, like not allowing the user to break out of their geography since that could allow users to violate policies of content sellers on Apple’s store and also any geographical content segregation that Apple may do for its own shows and movies in the future.

Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy

#24
This is nice and all, but I really wish that Apple would allow some real multi-account functionality. Especially for iPads, but also for iPhones.

When I hand my phone to my kids to play a game, I don't want them to have access to my email / text messages / contacts etc.

It's ridiculous that a 1000€ device is restricted to single user mode.

It's even worse for iPads -- they are perfect devices for sharing in the family, but only a single person can use them for Email / iMessage / Whatsapp / Facetime / ...

But I don't have any hopes that Apple will fix this. They want everyone in the family to own their own set of iDevices.

Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy

#25

This is nice and all, but I really wish that Apple would allow some real multi-account functionality. Especially for iPads, but also for iPhones. When I hand my phone to my kids to play a game, I don't want them to have access to my email / text messages / contacts etc. It's ridiculous that a 1000€ device is restricted to single user mode. It's even worse for iPads -- they are perfect devices for sharing in the famil…

You don't need multiaccount functionality for the use case you describe, just app pinning.

Of course, Android has both.

Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy

#26

An obvious solution is to carry two devices: one for work, on which the company can install whatever corporate spyware they want, and one for personal use. There's no way I'm letting my employer administer or install unknown programs on my personal laptop and cell even with this enrollment option. This has nothing to do with trusting or distrusting Apple. It's due to avoiding complexity: having to think about a zilli…

It is a burden however, and one that isn't necessary if your company has a sane BYOD policy that protects them while not being too invasive. The reality is, convenience wins again here. I, for one, don't give a shit what control my company has over my phone. Not only has nothing ever happened as a result of me using a BYOD policy, the overall rate in the industry seems acceptably low too. I only have 24 hours in my d…

What do you consider an acceptably low rate, and what is the actual rate? I hear stories all the time about companies that are tracking their employees' GPS locations. Many of the stories involve people getting fired.

Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy

#27

This is nice and all, but I really wish that Apple would allow some real multi-account functionality. Especially for iPads, but also for iPhones. When I hand my phone to my kids to play a game, I don't want them to have access to my email / text messages / contacts etc. It's ridiculous that a 1000€ device is restricted to single user mode. It's even worse for iPads -- they are perfect devices for sharing in the famil…

You don't need multiaccount functionality for the use case you describe, just app pinning. Of course, Android has both.

"App Pinning" sounds like it's similar to "Guided Access" which has been available on the iPhone forever. That is not what I want. My kids are old enough to navigate the phone on their own, and they use multiple apps.

I just want Face ID to recognize that it's my kid, and not show them notifications for my work related stuff, and just let them play Minecraft and Monument Valley or whatever they want.

Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy

#28
It feels like an over engineered solution for a simple problem. If Apple were instead to add multi-users support to iOS then it would be as simple as having a work identity with dedicated apps and segregated data, and a personal identity as such, invisible to IT.

Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy

#29
post #13

An obvious solution is to carry two devices: one for work, on which the company can install whatever corporate spyware they want, and one for personal use. There's no way I'm letting my employer administer or install unknown programs on my personal laptop and cell even with this enrollment option. This has nothing to do with trusting or distrusting Apple. It's due to avoiding complexity: having to think about a zilli…

Naturally. I never got the BYOD thing. My employer should provide the required tools, if not, then the work is done within the constraints of what is available.

The problem with employer-provided tools is that they sometimes barely meet the minimum requirements. Sure it gets the job done, but it’s no fun.

I’d rather buy and manage my own device, which is then powerful enough for my needs.

Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy

#30

An obvious solution is to carry two devices: one for work, on which the company can install whatever corporate spyware they want, and one for personal use. There's no way I'm letting my employer administer or install unknown programs on my personal laptop and cell even with this enrollment option. This has nothing to do with trusting or distrusting Apple. It's due to avoiding complexity: having to think about a zilli…

Why buy a phone for your employer surly its up to them to provide the right equipment.
Post reply on HN