Live data from Hacker News

MS Exchange “remote wipe” is a terrible, terrible bug

code.technically.us

91–100 of 117 posts

Re: MS Exchange “remote wipe” is a terrible, terrible bug

#91
I once lost my phone, with work email on it. I used the remote wipe as soon as I knew the phone wasn't coming back.

Someone had gone to the trouble of keeping the phone charged; it got the wipe a good 24 hours after the battery should have died.

I was very, very happy the facility was there.

Re: MS Exchange “remote wipe” is a terrible, terrible bug

#92
post #90
post #89

Earlier quoted context omitted.

This is crazy talk. If it's a major security risk, don't sync it to someone's pocket. By syncing it to someone's pocket... it's out. Especially if it's on their personal phone, you can't control what they (or an attacker) will do. Either that's an acceptable convenience / risk tradeoff, or it's not. If it's not, you need to focus your efforts on tagging confidential data and keeping it inside the "walls" of your orga…

syncing to someones pocket is fine if you can remote wipe it

But you can't guarantee that you can wipe it. What if it's not connected to the 3G network? What if the data has already been pulled off? What if it's been copied to a memory card on the phone? What if the phone doesn't properly implement this feature?

Re: MS Exchange “remote wipe” is a terrible, terrible bug

#93
So our company will not let iPhones connect to the Exchange servers from outside the corp firewall. Solution: Set up a separate mailbox on an external web host and use an exchange rule through Outlook to redirect emails to that address, all the while filtering for things like confidential or classified documents, and check the mail from my phone.

Re: MS Exchange “remote wipe” is a terrible, terrible bug

#94
post #20
post #16

Earlier quoted context omitted.

If you are in the US, it's likely illegal for your boss to try to regulate microwave ovens based on causing wifi interference - that's solely the job of the FCC. The regulations that allow the use of 2.4Ghz ISM band require you to accept that interference....

... Not if the microwaves are in your control. You can certainly police microwaves on your own campus. (Not that this is an intelligent idea.)

I think it's an intelligent idea if you're providing blanket coverage and idiots are setting up their own linksys's that can't even dhcp on due to mac filtering.

Re: MS Exchange “remote wipe” is a terrible, terrible bug

#95

If an IT department did this to me without warning, I'd quit that day , CC'ing my manager and the IT guy's manager telling them exactly why they'll now have to spend months finding and training my replacement.

I parked my personal car in the company fleet car garage and they clamped it. I didn't understand what was happening and called the rescue company telling them it had broken down and wasted lots of time. This was so unfair I quit that day , causing a dramatic fuss pointing out exactly how much they'll suffer. That'll show them.

Imagine today one of your employees quits on the spot, tells you he's quitting because his car was clamped.

You have no idea who manages the parking lot, but now you just lost a resource on your project.

How did your manager end up reacting?

Re: MS Exchange “remote wipe” is a terrible, terrible bug

#97
post #56
post #53

Earlier quoted context omitted.

No, that's not the real problem. The transmission of sensitive information through corporate email is commonplace. Formally-classified protected information like HIPAA PI or payment card data shouldn't, of course, be emailed, but information that can be traced back to PI is sent routinely. Regardless of whether it should or shouldn't happen, IT controls people have to assume it will. The contract for syncing with a c…

> The contract for syncing with a corporate Exchange server, in many places, simply requires you to allow your phone to be wiped. > If you don't like it, don't sync with your company's Exchange server. What's so hard about that? The problem that the posts points out is that there's no warning about this "contract" whatsoever. No matter what mobile device I've ever used, I have never, ever had a dialog tell me that by…

> The problem that the posts points out is that there's no warning about this "contract" whatsoever.

But the post wrongly blames Microsoft and Exchange, when it's the person's workplace he should be blaming for supposedly not having clear enough policies.

Re: MS Exchange “remote wipe” is a terrible, terrible bug

#98
post #17

Earlier quoted context omitted.

Sure, but you send out an Email warning people first. There's no reason to wipe people's devices unless they are willfully defying policy, and even then, you've got a list of the people doing it - just go to their office and talk to them in person (involve their manager if needed). Wiping a personal device to "send a message" is passive-aggressive and totally destructive to morale.

It's also quite likely completely illegal - warning or not. It's a personal device - the company has no rights to it.

You handed the company rights to it when you added it to the Exchange domain.

The only issue at hand is whether a phone should be more explicit in telling you doing this will hand IT complete control of the device.

Re: MS Exchange “remote wipe” is a terrible, terrible bug

#99

Can someone confirm that the remote wipe actually works as described on each mobile OS? And that it can be done through a Google domain just by using their sync feature with a company account?

just had some fun with the phone of a coworker of mine (of course after warning him and making sure that he won't lose data).

His iPhone was connected to our Google Apps account and with one click I managed to wipe his phone (it rebooted and came up with the "connect me to iTunes to activate me" screen).

Re: MS Exchange “remote wipe” is a terrible, terrible bug

#100
post #56
post #53

Earlier quoted context omitted.

No, that's not the real problem. The transmission of sensitive information through corporate email is commonplace. Formally-classified protected information like HIPAA PI or payment card data shouldn't, of course, be emailed, but information that can be traced back to PI is sent routinely. Regardless of whether it should or shouldn't happen, IT controls people have to assume it will. The contract for syncing with a c…

> The contract for syncing with a corporate Exchange server, in many places, simply requires you to allow your phone to be wiped. > If you don't like it, don't sync with your company's Exchange server. What's so hard about that? The problem that the posts points out is that there's no warning about this "contract" whatsoever. No matter what mobile device I've ever used, I have never, ever had a dialog tell me that by…

Also, since we're in HN (startup city, what?) who has ever worked for a startup that DISCOURAGED working from home on a personal laptop or having access to email 24x7?

The policy where I work is: linux laptop (I imagine BSD might also be ok), access to code is via sshfs (or TRAMP) only. I don't think this is that unusual.

Post reply on HN