PPRuNe Forums - View Single Post - BA spied on staff
View Single Post
Old 2nd Mar 2015, 08:44
  #32 (permalink)  
mixture
 
Join Date: Aug 2002
Location: Earth
Posts: 3,663
Likes: 0
Received 0 Likes on 0 Posts
Corporate configured iOS devices that are centrally managed are not as secure as mixture's post might make you believe.
You've probably never even used Apple Configurator or the iPhone Configuration Utility, let alone MDM remote management.

As far as I am aware, putting an iOS device into supervised mode DOES NOT disable the sandbox or other iOS security mechanisms.

The sandbox in particular is an integral and fundamental part of the iOS security model and the only way anybody can disable it is by jailbreaking the phone !

Supervised mode may well allow the Administrator to bypass the lock screen when the Administrator has physical access to your device ... but as we all know in IT .... when an untrusted third-party has physical access to a device (be it laptop, phone or server), its game over as far as security goes.

Remote MDM commands don't allow Administrators to slurp data either !

The purpose of supervised mode and remote MDM is for ease of provisioning and device management in larger IT environments.

If I'm wrong, then please provide me a link to formal technical documentation on the Apple website that explicitly states that.

I'm not interested in something you heard from a friend of a friend. Because if I were to hazard a guess, what you have is a fundamental misunderstanding of the iOS managed accounts and/or managed apps features.

Last edited by mixture; 2nd Mar 2015 at 09:17.
mixture is offline