Risk
11/1/2011
01:59 PM
Connect Directly
Google+
LinkedIn
Twitter
RSS
E-Mail
50%
50%

MDM: To Sandbox Or Not To Sandbox?

Mobile device management systems take different approaches to sandboxing. Is mobile virtualization the answer?

Most enterprises must make a tradeoff when it comes to mobile device management, or MDM, systems, because providers fall into one of two camps: those, like Good Technology, that provide a single sandbox where all corporate data goes, and those, such as MaaS360 or MobileIron, where the device has some sandboxing (for email) but most of the MDM client's work is done in conjunction with the operating system's apps and features.

The two approaches have pros and cons, and some organizations have a very difficult time deciding which route to go. Well, life is set to get a bit easier now that Verizon has partnered with VMware and AT&T has linked up with Enterproid's new Toggle to bring mobile virtualization to the market.

While sandboxing is traditionally done at the application level, the new technologies from VMware and Enterproid focus on creating partitions, using virtualization, to sandbox the entire mobile device. That allows a user to run two versions of a mobile operating system at the same time on the same phone: one for work, one for personal use.

In a video from the Qualcomm QPrize event demonstrating Entreproid's technology, you can see how a mobile user can seamlessly switch between the two "phones" and have full access to all 250,000+ real apps within each partition, as if they were the only apps on the device. We can finally allow Angry Birds to be installed in the personal partition and prevent it from running in the corporate partition. Huzzah!

While you can't get your hands on the tech until later this year, it has been discussed since 2009 and has been securing a very well-known user's mobile phone for over a year: President Barack Obama uses this type of virtualization technology on his BlackBerry to separate the highly secure apps he needs to run from the rest of the phone.

The benefits to enterprises are pretty compelling, too. Mobile virtualization provides all the advantages of sandboxing--mainly, full encryption of all corporate data and easy wiping of that data--as well as the benefits of non-sandbox-based approaches; for example, employees can use native mobile apps, such as the calendar and mail clients, without having to be retrained on a quirky interface from a vendor such as NitroDesk TouchDown or Good. There are new benefits, too, such as allowing an end user to upgrade to a new version of Android while the corporate partition stays at a corporate-enforced version.

We don't recommend you hold off on your MDM or mobile strategy until these technologies are available, since all the vendors we spoke with say that'll take a few months. But definitely keep it on your radar. I think that mobile virtualization will be a game changer for the enterprise if phone manufacturers provide devices that will support the technology. The holdup there is that the phone must have enough processor power and should be a dual-core device. Almost all the new Androids are dual-core, and this is something to consider if you provide stipends or guidance for users on device selection.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
J to the C
50%
50%
J to the C,
User Rank: Apprentice
11/4/2011 | 5:26:36 PM
re: MDM: To Sandbox Or Not To Sandbox?
I just read about 3LM. Looks like it takes Android to the iOS security level(s). Have you read about Mocana as well? Eventually BYOD will become BYOA (bring your own apps).
GrantMoerschel
50%
50%
GrantMoerschel,
User Rank: Apprentice
11/3/2011 | 11:13:32 AM
re: MDM: To Sandbox Or Not To Sandbox?
These are interesting developments. As I've learned more about the MDM space, I've come to the conclusion that Good-type solutions are typically going to be a dead end because user's will revolt if they can. In high security environment they can't revolt but in most others they can. Also it'll be interesting to see how standardized OS mods like those done by 3LM.com will play into hopefully normalizing the major flavors of droid so that they can be consistently controlled. Or will these VM's simply fix it all by giving people two completely different interfaces both of which are friendly and not restrictive.

Grant Moerschel, InformationWeek contributor
jrapoza
50%
50%
jrapoza,
User Rank: Apprentice
11/2/2011 | 11:14:03 PM
re: MDM: To Sandbox Or Not To Sandbox?
I agree. Mobile VMs will be the key to managing BYOB devices in a corporate environment. As pointed out, it is probably the cleanest and easiest to manage approach.

Jim Rapoza is an InformationWeek Contributing Editor
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-4440
Published: 2014-12-19
Password Generator (aka Pwgen) before 2.07 generates weak non-tty passwords, which makes it easier for context-dependent attackers to guess the password via a brute-force attack.

CVE-2013-4442
Published: 2014-12-19
Password Generator (aka Pwgen) before 2.07 uses weak pseudo generated numbers when /dev/urandom is unavailable, which makes it easier for context-dependent attackers to guess the numbers.

CVE-2013-7401
Published: 2014-12-19
The parse_request function in request.c in c-icap 0.2.x allows remote attackers to cause a denial of service (crash) via a URI without a " " or "?" character in an ICAP request, as demonstrated by use of the OPTIONS method.

CVE-2014-2026
Published: 2014-12-19
Cross-site scripting (XSS) vulnerability in the search functionality in United Planet Intrexx Professional before 5.2 Online Update 0905 and 6.x before 6.0 Online Update 10 allows remote attackers to inject arbitrary web script or HTML via the request parameter.

CVE-2014-2716
Published: 2014-12-19
Ekahau B4 staff badge tag 5.7 with firmware 1.4.52, Real-Time Location System (RTLS) Controller 6.0.5-FINAL, and Activator 3 reuses the RC4 cipher stream, which makes it easier for remote attackers to obtain plaintext messages via an XOR operation on two ciphertexts.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Join us Wednesday, Dec. 17 at 1 p.m. Eastern Time to hear what employers are really looking for in a chief information security officer -- it may not be what you think.