Caution: iOS 5, iCloud and the iPhone 4S in the enterprise
Beware these security pitfalls
Computerworld - Apple's iOS 5 and the new iPhone 4S, which went on sale Friday, are packed with new features, many of which should boost the productivity and on-the-road capabilities of professional users. But, as with many consumer-oriented mobile platforms making their way into the workplace, iOS 5 and Apple's new iCloud service present some serious challenges in business environments.
Security issues involving iCloud and several other features will likely be the first things IT professionals weigh when it comes to iOS 5, which Apple rolled out last week. That's good, because even though Apple quietly provided some new enterprise features in iOS 5 that should make iPhones and iPads better corporate citizens, new concerns have emerged.
What to worry about
Out of the 200-plus new features in iOS 5, there are really just three that pose new security challenges: iCloud syncing and backup, location-based services like the new Find My Friends app, and the Siri virtual assistant in the iPhone 4S.
iCloud -- too much sharing?
Apple's iCloud is a unique brand of cloud services that's geared more toward personal use than professional. It allows users to sync all their personal data -- contacts, calendars, emails, notes, iTunes media, photos, documents and so on -- across all their iOS devices and Macs (and to some extent Windows PCs). Users can also back up their iOS device data wirelessly to Apple's iCloud storage or to their Mac or Windows computer using iTunes.
This is a rich set of features for consumers, as it ensures easy access to virtually all data that's supported by Apple's iOS 5 as well as the security of having a backup of core iOS information that can be restored anytime, anywhere.
While that ease of access is great for end users, it raises serious questions for iOS devices used for work, be those devices company-owned or, as is increasingly the case, employee-owned. Given that the service debuted only last week -- and had a problematic rollout at that -- there are now more questions than answers. If iPhone users in the workplace start asking about using iCloud, ask yourself these questions:
Will confidential corporate data such as documents, global contacts and emails be synced to a user's home computer? Might they reside on Apple's iCloud servers after a user has left a company? What if someone gains access to a user's iCloud account by stealing a device or through a phishing or social engineering attack? Could photos taken with an iOS device in the office be pushed across a range on devices and computers by iCloud's Photo Stream feature?
Even more concerning is the uncertainty about whether users are putting business information onto their device(s) and into iCloud. At this point, how would an IT shop know?
What appears to be a great consumer feature could turn out to be a professional minefield. Caution is warranted.
Find My Friends -- or my unsecured iOS device
One extension of iCloud is the new Find My Friends app, which functions very much like Google's Latitude. If your friends or other contacts give the OK, you can see their current whereabouts on a map -- and vice versa.
Find My Friends offers a lot of useful potential in a business context. It can ensure colleagues can easily locate each other at a conference or some other event. It can help managers monitor employees assigned to mobile tasks like deliveries.
Unfortunately, it also allows anyone who is designated as a "friend" to locate a user or his/her iPhone or iPad. That could be a prelude to theft. Find My Friends could also be used to covertly monitor a user during off hours, which -- beyond being an invasion of privacy -- could open someone up to blackmail or other forms of coercion.
On a personal level, if you download and set up Find My Friends on an iDevice, I suggest you be extremely cautious about who is allowed to follow you. More on what to do about Find My Friends in an enterprise environment in a moment.
Siri -- say what?
The iPhone 4S's virtual assistant feature poses it own set of concerns. Since Siri is integrated into iOS 5, it has at least some level of access to all of Apple's built-in iOS apps, including Mail, Messages, Calendar, Notes and so on.
Thus, it's conceivable that when a user asks Siri to read business content such as an email, others nearby might be able to overhear confidential information. Similarly, and perhaps more concerning, a user sending a text message, making an appointment or dictating into any app on the iPhone 4S could be overheard.
Apple's iOS
- Microsoft sticks it to the iPad with Windows-first Office strategy
- 10 iOS 7 features that could make enterprises smile
- Why iOS is the future of Apple (and how we got here)
- Apple's WWDC set for June 10-14, hints at fall launch of next iPhone
- Apple sold 35-38M iPhones last quarter, analysts say
- Apple takes blame for iOS 6.1-Exchange battery-draining bug, promises patch
- Dropbox releases sync API for iOS and Android
- iOS 6 untethered jailbreak released, Cydia app store flooded
- Apple makes good on CEO's promise to expand iPhone 5's 4G carriers
- Microsoft can 'start printing money' as soon as it launches Office for iOS
- 10 Hot Big Data Startups to Watch
- 11 Unique Uses for Google Glass, Demonstrated by Celebs
- How to Export Your Google Reader Account
- How to Better Engage Millennials (and Why They Aren't Really so Different)
- Telltale signs of ATM skimming
- 20 security and privacy apps for Androids and iPhones
- Big screen con artists: 7 great movies about social engineering
- IT Certification Study Tips
- Register for this Computerworld Insider Study Tip guide and gain access to hundreds of premium content articles, cheat sheets, product reviews and more.
- Top Three Reasons Why Customers Deploy EMC VNX with EMC VPLEX What if you could build a cost effective, continuously available storage infrastructure? Learn the top reasons users are deploying EMC VNX with EMC...
- Clearing the Clouds for Midmarket Businesses The 10-point checklist included in this expert brief has been developed to help small and midsize businesses select the cloud model and cloud...
- Perforce Case Study Learn how EMC cost-effectively transformed their infrastructure and improved storage performance by 60% by unifying storage, deploying virtualization and leveraging Flash to meet...
- Data Center Transformation: Balancing user demands with IT mandates There's a flood of user requirements, computing trends, and new technologies driving the need for you to look closely at your IT infrastructure.
- Virtustream (Vayence) video taking a 3000-Seat SAP Environment to the Cloud How can public cloud services help your organization reduce costs and increase security for your mission
- Williams & Fudge on Transforming IT with EMC Watch Williams & Fudge Data Center Director Phillip Reynolds discuss why this accounts receivable management firm turned to EMC. All iOS White Papers | Webcasts
