Risk
11/1/2011
01:59 PM
Connect Directly
LinkedIn
Twitter
Google+
RSS
E-Mail
50%
50%

MDM: To Sandbox Or Not To Sandbox?

Mobile device management systems take different approaches to sandboxing. Is mobile virtualization the answer?

Most enterprises must make a tradeoff when it comes to mobile device management, or MDM, systems, because providers fall into one of two camps: those, like Good Technology, that provide a single sandbox where all corporate data goes, and those, such as MaaS360 or MobileIron, where the device has some sandboxing (for email) but most of the MDM client's work is done in conjunction with the operating system's apps and features.

The two approaches have pros and cons, and some organizations have a very difficult time deciding which route to go. Well, life is set to get a bit easier now that Verizon has partnered with VMware and AT&T has linked up with Enterproid's new Toggle to bring mobile virtualization to the market.

While sandboxing is traditionally done at the application level, the new technologies from VMware and Enterproid focus on creating partitions, using virtualization, to sandbox the entire mobile device. That allows a user to run two versions of a mobile operating system at the same time on the same phone: one for work, one for personal use.

In a video from the Qualcomm QPrize event demonstrating Entreproid's technology, you can see how a mobile user can seamlessly switch between the two "phones" and have full access to all 250,000+ real apps within each partition, as if they were the only apps on the device. We can finally allow Angry Birds to be installed in the personal partition and prevent it from running in the corporate partition. Huzzah!

While you can't get your hands on the tech until later this year, it has been discussed since 2009 and has been securing a very well-known user's mobile phone for over a year: President Barack Obama uses this type of virtualization technology on his BlackBerry to separate the highly secure apps he needs to run from the rest of the phone.

The benefits to enterprises are pretty compelling, too. Mobile virtualization provides all the advantages of sandboxing--mainly, full encryption of all corporate data and easy wiping of that data--as well as the benefits of non-sandbox-based approaches; for example, employees can use native mobile apps, such as the calendar and mail clients, without having to be retrained on a quirky interface from a vendor such as NitroDesk TouchDown or Good. There are new benefits, too, such as allowing an end user to upgrade to a new version of Android while the corporate partition stays at a corporate-enforced version.

We don't recommend you hold off on your MDM or mobile strategy until these technologies are available, since all the vendors we spoke with say that'll take a few months. But definitely keep it on your radar. I think that mobile virtualization will be a game changer for the enterprise if phone manufacturers provide devices that will support the technology. The holdup there is that the phone must have enough processor power and should be a dual-core device. Almost all the new Androids are dual-core, and this is something to consider if you provide stipends or guidance for users on device selection.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
J to the C
50%
50%
J to the C,
User Rank: Apprentice
11/4/2011 | 5:26:36 PM
re: MDM: To Sandbox Or Not To Sandbox?
I just read about 3LM. Looks like it takes Android to the iOS security level(s). Have you read about Mocana as well? Eventually BYOD will become BYOA (bring your own apps).
GrantMoerschel
50%
50%
GrantMoerschel,
User Rank: Apprentice
11/3/2011 | 11:13:32 AM
re: MDM: To Sandbox Or Not To Sandbox?
These are interesting developments. As I've learned more about the MDM space, I've come to the conclusion that Good-type solutions are typically going to be a dead end because user's will revolt if they can. In high security environment they can't revolt but in most others they can. Also it'll be interesting to see how standardized OS mods like those done by 3LM.com will play into hopefully normalizing the major flavors of droid so that they can be consistently controlled. Or will these VM's simply fix it all by giving people two completely different interfaces both of which are friendly and not restrictive.

Grant Moerschel, InformationWeek contributor
jrapoza
50%
50%
jrapoza,
User Rank: Apprentice
11/2/2011 | 11:14:03 PM
re: MDM: To Sandbox Or Not To Sandbox?
I agree. Mobile VMs will be the key to managing BYOB devices in a corporate environment. As pointed out, it is probably the cleanest and easiest to manage approach.

Jim Rapoza is an InformationWeek Contributing Editor
Register for Dark Reading Newsletters
Partner Perspectives
What's This?
In a digital world inundated with advanced security threats, Intel Security seeks to transform how we live and work to keep our information secure. Through hardware and software development, Intel Security delivers robust solutions that integrate security into every layer of every digital device. In combining the security expertise of McAfee with the innovation, performance, and trust of Intel, this vision becomes a reality.

As we rely on technology to enhance our everyday and business life, we must too consider the security of the intellectual property and confidential data that is housed on these devices. As we increase the number of devices we use, we increase the number of gateways and opportunity for security threats. Intel Security takes the “security connected” approach to ensure that every device is secure, and that all security solutions are seamlessly integrated.
Featured Writers
White Papers
Cartoon
Current Issue
Dark Reading's October Tech Digest
Fast data analysis can stymie attacks and strengthen enterprise security. Does your team have the data smarts?
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-7407
Published: 2014-10-22
Cross-site request forgery (CSRF) vulnerability in the MRBS module for Drupal allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

CVE-2014-3675
Published: 2014-10-22
Shim allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted DHCPv6 packet.

CVE-2014-3676
Published: 2014-10-22
Heap-based buffer overflow in Shim allows remote attackers to execute arbitrary code via a crafted IPv6 address, related to the "tftp:// DHCPv6 boot option."

CVE-2014-3677
Published: 2014-10-22
Unspecified vulnerability in Shim might allow attackers to execute arbitrary code via a crafted MOK list, which triggers memory corruption.

CVE-2014-4448
Published: 2014-10-22
House Arrest in Apple iOS before 8.1 relies on the hardware UID for its encryption key, which makes it easier for physically proximate attackers to obtain sensitive information from a Documents directory by obtaining this UID.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Follow Dark Reading editors into the field as they talk with noted experts from the security world.