Are PDAs back-door security threats?

  • warning: preg_match() expects parameter 2 to be string, array given in /var/www/html/includes/bootstrap.inc on line 684.
  • warning: preg_match() expects parameter 2 to be string, array given in /var/www/html/includes/bootstrap.inc on line 684.

Are PDAs back-door security threats?

By Robert Scheier | Jul 28, 2009

Are all those handheld devices your users keep dragging into the office the Next Big Security Threat? Or are they just smaller, less-capable versions of notebook computers that you can afford to pretty much ignore?

Gartner Inc.'s Vice President of Mobile Computing Ken Dulaney argues that Palms, BlackBerry mobile e-mail devices and Web-enabled mobile phones are opening dangerous back doors into your corporate networks -- and now is the time to start combating the threat. SearchSecurity columnist Robert L. Scheier asked Dulaney to outline the threat of personal digital assistants (PDAs) and Gartner's recommended response.

Q: Who buys and controls these devices -- the company or the users?

A: We don't believe any employer has control over these devices. They're too cheap; they're too accessible. If they [the employer] think they've been able to control it, they just don't know what's going on. People see them in the store or get them as Christmas gifts.

Q: Why is this a security threat?

A: When the firewall industry appeared, it was an attempt to put a line of delineation between the enterprise and what it needs to control, and unknown parties who wanted access to that data. Today we have a hole -- just as significant if not bigger -- at the back of the company, with all these PDAs, which are a combination of business and personal devices.

Q: How do these devices get to corporate data?

A: If you buy a Palm Pilot today, you get, with the device, enough software to be able to link to Lotus Notes, or Outlook Express . . . within a day. These are synched through the [user's] desktop PC. It's often a dual-step process: You sync to your PC from your server, and/or at least have an online connection, and then sync to your PDA. Once a user puts software from the [PDA] box on their PC, they basically create an open hole into the enterprise.

Q: Why is this a big threat, if the user is only sending data to their PDA, which is already on their notebook or desktop?

A: Notebook computers, because of their price, have traditionally been bought by the enterprise and would therefore be considered part of the network domain. PDAs are generally owned by consumers and used in business. The real issue here is one of discipline. Because the notebook is owned by the company, they can demand [the enforcement of] security standards. But once it's personally owned, they lose those rights.

Q: Still, the user could just as easily copy the data to their notebook and walk out of the building with it.

A: The company would know that has occurred. The information is on a machine (the notebook), which is controlled by management utilities. But [on a PDA] the software that permits the information to flow out has been put there . . . by the individual. There's no management control.

Q: Just like there's no management control over what I download to a floppy?

A: Sure. These are also challenges that need to be met. But the PDA . . . can so quickly upload its information to the Internet and make it public. If you carry around a floppy, it's not the same thing as being able to connect yourself to a lot of other PDAs via infrared links. It's the electronic definition of a sexually transmitted disease. The key thing we're talking about is the separation of church and state -- what's personal and what's enterprise -- is now fuzzier. The definition of ownership -- that's the big issue -- and the degree of exposure.

 
 
12

Add comment

Post a Comment

The content of this field is kept private and will not be shown publicly.
  • Web page addresses and e-mail addresses turn into links automatically.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd> <a> <p> <span> <div> <h1> <h2> <h3> <h4> <h5> <h6> <img> <img /> <map> <area> <hr> <br> <br /> <ul> <ol> <li> <dl> <dt> <dd> <table> <tr> <td> <em> <b> <u> <i> <strong> <font> <del> <ins> <sub> <sup> <quote> <blockquote> <pre> <address> <code> <cite> <embed> <object> <strike> <caption>
  • Lines and paragraphs break automatically.
  • Use <!--pagebreak--> to create page breaks.

More information about formatting options

 

Comments

Comments

Boots, UGGS 50-75% Off All

Boots, UGGS 50-75% Off All UGG Boots , 100% Australian Sheepskin. UGGS australia, Free Shipping! Money Back Guarantee! The origin of the Australian discount uggs has a variety of stories as to how and when the ugg sheep skin boots were actually invented. One of the versions has the sheep skin footwear as the boot worn by pilots during World War One. tiffany jewellery Ed Hardy UGG Classic Cardy Boots UGG Nightfall Boots UGG Classic Short Boots

WZZ cheap wow gold Nigerian

WZZ

cheap wow gold Nigerian Ministry cheap wow gold of Communications aion gold and China signed
metin2 yang a supplementary
aion4gold agreement to Aion Kina the railway

Have You ever thought about

Have You ever thought about bbetting online ?? have You ever asked yourself why the

Sports betting

is so popular around the world??. Have You ever thoght aboyt it. Sport betting is awesome to earn some exra cash especialy

Betfair

exchange platform.Betfair offers You best odds in all kind sports. Think about it and register just today. Dont wait. You can also get huge

Betting Bonus

up to $1000 don't You wanna get this money for free?? I don't think so. so registre and get Your

Free Bet

today. dont hesitate, it is not big problem use it within fw seconds. betfair is best

Bookmaker

in this market so feel free bet there everyoday. Just

bet home

and earn $1000 everyday. Be master of trading on betfair. Be rich be rich or die trying.

knowledge_central_tab

 
 
Knowledge Central
Today's top security priorities
Attacks based on vulnerabilities in websites are skyrocketing, and not many solutions are available to protect organizations against them. How do you deal with this and other key security issues today?
Taking a holistic business-centric approach to security
Today’s CIOs face multiple challenges, including the need to innovate in an extremely competitive business climate, address highly dynamic regulatory and compliance challenges, speed ROI to counter shrinking IT budgets, and secure their organizations against a wide barrage of sophisticated threats.
 
 
 
UTM product offers Logansport Savings Bank superior protection
Astaro Security Gateway’s IPS was able to block attacks that other intrusion prevention systems (IPS) missed at Logansport Savings Bank.
Hong Leong Financial opts for Juniper Networks at new Malaysia head office, data center
Hong Leong Financial Group Berhad builds complete and seamless data center and office network infrastructure with Juniper switches, security devices and Junos software.