Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 161 guests and 1 member online
Free Business and Tech Magazines and eBooks
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Mobile
Corporate Security: Android vs iPhone
EH-Net
May 23, 2013, 09:51:54 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Mobile
(Moderator:
don
) >
Corporate Security: Android vs iPhone
Pages: [
1
]
2
Go Down
« previous
next »
Print
Author
Topic: Corporate Security: Android vs iPhone (Read 24170 times)
0 Members and 1 Guest are viewing this topic.
cd1zz
Hero Member
Offline
Posts: 561
Corporate Security: Android vs iPhone
«
on:
May 05, 2011, 04:05:05 PM »
I need your opinions on Android vs iPhone in the enterprise. In my situation, we have to take Blackberry out, even though they still maintain the tightest control via BES. Don't ask questions, it is what it is.
It seems that iPhone does a better job vetting apps in the appstore, but I don't really have any solid proof. I know there was news in the last few months of a bunch of Android apps having security issues, but what is the real impact here?
I would love to hear what everyone thinks, put on all your hats here: security, admin, user.
Thanks,
C
Logged
OSCE | OSCP | GXPN | OSWP | CISSP
http://www.pwnag3.com
http://www.networkadminsecrets.com
sil
Hero Member
Offline
Posts: 549
Re: Corporate Security: Android vs iPhone
«
Reply #1 on:
May 05, 2011, 04:12:48 PM »
Researchers have already stated that the iPhone is more secure. I say, create a mobile policy from work and refrain from introducing N amount more possible entry points where N is the amount of phone users.
http://articles.timesofindia.indiatimes.com/2011-01-12/computing/28352068_1_android-security-software-mobile-devices
http://news.cnet.com/8301-27080_3-20009362-245.html
Logged
http://www.infiltrated.net/mgz/puppylecter.jpg
hayabusa
Hero Member
Offline
Posts: 1633
Re: Corporate Security: Android vs iPhone
«
Reply #2 on:
May 05, 2011, 04:54:02 PM »
sil++
My only complaint with iPhones is that AppStore isn't perfect, either, based heavily on those who write their apps. For instance, on my wife's iPhone, the latest Facebook app she pulled from updates clearly says, after installing, that it's an 'employee only' build. It crashes her whole phone frequently, when she uses it, and uninstall / reinstall brings back the same 'busted' / 'employee only' build... Facebook has yet to respond to me with a fix.
Logged
~ hayabusa ~
"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'
OSCE, OSCP , GPEN, C|EH
cd1zz
Hero Member
Offline
Posts: 561
Re: Corporate Security: Android vs iPhone
«
Reply #3 on:
May 05, 2011, 05:06:57 PM »
I understand limiting exposure by only allowing folks with a business reason to have phones. That I totally agree with.
My problem with iPhone is that now there is another 3rd party app that you have to introduce to the environment (Itunes) and now you have to worry about patching another 3rd party product.
With Android you get some notification of what an app will do after you install it, however I know that no regular user is every thwarted by that information.
So here we are again, back to the point where its almost even in my mind. And at the point where you might earn some points with users giving them an option..... please tell me I'm crazy and please shoot me down. I want more of your opinions....
Logged
OSCE | OSCP | GXPN | OSWP | CISSP
http://www.pwnag3.com
http://www.networkadminsecrets.com
yatz
Full Member
Offline
Posts: 222
Re: Corporate Security: Android vs iPhone
«
Reply #4 on:
May 06, 2011, 08:38:29 AM »
We're going through this too, which I'm sure is not at all uncommon. Biggest problem we seem to have right now is having to link iTunes to a credit card since very few employees have company issued credit cards.
There was an announcement from RIM recently about a product that works with BES to administer/control iPhone and Android devices in the same way BES does with BlackBerry devices. No release date yet though.
Logged
"Live as though you would die tomorrow, learn as though you would live forever."
CCNA, MCSA, MCTS, Sec+, Net+, Linux+, CEH
millwalll
Guest
Re: Corporate Security: Android vs iPhone
«
Reply #5 on:
May 06, 2011, 09:53:33 AM »
When I was InfoSec Europe a week or so ago they had live demo of setting up a Access point. They changed the name to BTopenZone what is a free wireless network in the UK. and sat back and watched how many people used this network. They also said I don't know how true this is but most Iphone will try connect to a BTOpenZone by default.
I have a Iphone and I am happy with it but they do have there security problems like any device.
As long as there was a good protocol for employes to follow then I think they would be fine.
Like don't connect to free wireless or even better disable wifi and use 3gs.
Just my 2 pence
Logged
AndyB
Full Member
Offline
Posts: 100
Re: Corporate Security: Android vs iPhone
«
Reply #6 on:
May 06, 2011, 02:42:23 PM »
Not having an i-phone myself (am an android man) I'd ask what security/av software is available for the i-phone?
I know a few of the mainstream AV houses have produced stuff for android and the stuff on my phone has picked up one rogue app so far.
Logged
Net+ Sec+ More to come
millwalll
Guest
Re: Corporate Security: Android vs iPhone
«
Reply #7 on:
May 06, 2011, 03:34:46 PM »
I have never seen any AV for the Iphone but according to Apple no Apple products would ever get a virus.
Logged
R3B005t
Newbie
Offline
Posts: 43
Re: Corporate Security: Android vs iPhone
«
Reply #8 on:
May 07, 2011, 02:09:50 PM »
Android while a great device os is open sourced, the major issue here is that there is absolutely 0 quality control by google over the Android Marketplace. This makes it extremely easy to introduce malicous software onto the device and potentially back into you environment. That reason alone was enough for me to make the Android a no go in my environment because why give your users an advanced device then deny them the ability to utilize it to its full potential by blocking the Marketplace (which is the only way I would allow Android in the enterprise).
In Nov. I was just awarded approval by our ISRB (information security review board) to introduce a fully functioning iPhone into the enterprise, by leveraging 3rd party software I am able to create an encrypted isolated segment on the device that does nothing but interact with the enterprise and it prevents external access from other applications on the device. By utilizing this method I'm able to give my users iPhones that are not restricted with policy only applying to the enterprise "container". I can help you out with some of the logistics and some good points of discussion that essentially help me convince the board that providing employees these powerful mobile devices while ensuring the integrity and security of our corporate data was viable let me know.
Logged
AndyB
Full Member
Offline
Posts: 100
Re: Corporate Security: Android vs iPhone
«
Reply #9 on:
May 07, 2011, 02:34:10 PM »
Quote from: Jamie.R on May 06, 2011, 03:34:46 PM
I have never seen any AV for the Iphone but according to Apple no Apple products would ever get a virus.
Thats not the sort of thing they should be saying really as it throws down the gauntlet -
Skype issue on the Mac
Logged
Net+ Sec+ More to come
millwalll
Guest
Re: Corporate Security: Android vs iPhone
«
Reply #10 on:
May 07, 2011, 03:02:23 PM »
I know its one apple key selling points that no Av is needed so they say!
Logged
R3B005t
Newbie
Offline
Posts: 43
Re: Corporate Security: Android vs iPhone
«
Reply #11 on:
May 07, 2011, 08:44:23 PM »
Thats not true at all, in fact if you search apple's support site they strongly recommend antivirus software on their machines. Apple has never said AV was unnecessary.
Logged
cd1zz
Hero Member
Offline
Posts: 561
Re: Corporate Security: Android vs iPhone
«
Reply #12 on:
May 07, 2011, 09:00:07 PM »
@R3B005t
How are you handling the iTunes issue? With the iOS exploit that is now in Metasploit, we can now pull all that juicy info right from the device, as long as itunes is installed on the box.
Logged
OSCE | OSCP | GXPN | OSWP | CISSP
http://www.pwnag3.com
http://www.networkadminsecrets.com
millwalll
Guest
Re: Corporate Security: Android vs iPhone
«
Reply #13 on:
May 08, 2011, 10:51:17 AM »
Insert Quote
@R3B005t
I have heard many Reps state that one the key benefits of buying a mac is you don't need to buy antivirus software as they don't get viruses.
I have just looked on Apple website and it says they do not get PC Viruses."And you never have to worry about PC viruses" of course you don't as PC viruses are for PCs but no where could I find them recommending me to buy anti virus. Even when I go to buy the item they offer me every other accessory with it Office,printer,iwork,final cut etc but no sign of any anti virus.
I also found this
http://news.bbc.co.uk/1/hi/7760344.stm
Please don't get me wrong I have an Apple machine and I love it. Apple products are amazing they just don't seem to illustrate the fact that you can get a virus on a mac. I would say there is a small chance of that happening at the moment but its still possible.
My only point was that no matter what device you decide on they all have there own security problems. Its a case of finding the right device for the company and finding a acceptable level of risk for the company.
cd1zz What exploit is that I just fired up my metasploit and I can only see a really old iTunes buffer overflow for 4.3. Is this on the free version of meta ?
«
Last Edit: May 08, 2011, 11:32:26 AM by Jamie.R
»
Logged
R3B005t
Newbie
Offline
Posts: 43
Re: Corporate Security: Android vs iPhone
«
Reply #14 on:
May 09, 2011, 08:02:51 AM »
Quote from: cd1zz on May 07, 2011, 09:00:07 PM
@R3B005t
How are you handling the iTunes issue? With the iOS exploit that is now in Metasploit, we can now pull all that juicy info right from the device, as long as itunes is installed on the box.
Simple we dont allow iTunes to be installed in the environment. As part of our user acceptance policy for the iPhones we state that:
1) All iOS updates must be applied within 7 days of release or we will disable access to enterprise mail. For those users unable to update their iPhone's in a timely manner we disable it, update it for them and then re-enable email access.
2) The end user is responsible for backing up any content on their device, we recommend they install iTunes on a computer at home for this purpose since we A) don't allow iTunes on any of our machines and B) My users don't have rights to install sofware, they don't have any elevated privilages beyond the standard user account.
The product we are using for enterprise mail requres that A) Any backup be encrypted by defualt and B)Does not back up data contained in the app only the application itself.
Logged
Pages: [
1
]
2
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
GCIH - GIAC Certified Incident Handler
: Passed my GCIH
(3) by
H1t M0nk3y
Greetings
: Hi from the UK
(3) by
UKSecurityGuy
GCIH - GIAC Certified Incident Handler
: GCIH Free Practice test attempt
(0) by
prats84
News Items and General Discussion About EH-Net
: Change is Coming to EH-Net!!
(27) by
don
Network Pen Testing
: AIX Vulnerability Assessments
(2) by
ras76
Tutorials
: Need guidance
(9) by
hanyhasan
Programming
: Finished Python Course in Codecademy now what?
(15) by
hanyhasan
Network Pen Testing
: Ruby on Rails Vulnerabilities / Attacks in BackTrack 5 r3
(0) by
SUdoctstudent
Network Pen Testing
: De-ICE 1.140 released!
(2) by
superkojiman
General Certification
: CPT Practical Submission
(1) by
UNIX
OSCP - Offensive Security Certified Professional
: Failed my first attempt at the OSCP exam
(94) by
azmatt
Tools
: Social-Engineer Toolkit (SET) Version 5.0 “The Wild West” Released
(2) by
m0wgli
Malware
: EICAR?
(3) by
UKSecurityGuy
Advisories
: HTB23154: Multiple Vulnerabilities in Exponent CMS
(0) by
AndyP
Advisories
: HTB23153: Multiple Vulnerabilities in Jojo CMS
(0) by
AndyP
Advisories
: HTB23151: Cross-Site Request Forgery (CSRF) in UMI.CMS
(0) by
AndyP
OSCP - Offensive Security Certified Professional
: Class Scheduled 6/8 - Linux n00b
(7) by
Taemyks
OSCP - Offensive Security Certified Professional
: OSCP exam scheduled
(6) by
gbhat
Incident Response
: LinkedIn Forensics
(0) by
AFENTIS_Forensics
General Certification
: Red Team/Blue Team
(1) by
ajohnson
Career Central
: Starter cert?
(3) by
Grendel
Network Pen Testing
: Beginner Ethical Hacker
(1) by
m0wgli
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
Free Business and Tech Magazines and eBooks
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.