Risk
11/1/2011
01:59 PM
Connect Directly
Google+
LinkedIn
Twitter
RSS
E-Mail
50%
50%

MDM: To Sandbox Or Not To Sandbox?

Mobile device management systems take different approaches to sandboxing. Is mobile virtualization the answer?

Most enterprises must make a tradeoff when it comes to mobile device management, or MDM, systems, because providers fall into one of two camps: those, like Good Technology, that provide a single sandbox where all corporate data goes, and those, such as MaaS360 or MobileIron, where the device has some sandboxing (for email) but most of the MDM client's work is done in conjunction with the operating system's apps and features.

The two approaches have pros and cons, and some organizations have a very difficult time deciding which route to go. Well, life is set to get a bit easier now that Verizon has partnered with VMware and AT&T has linked up with Enterproid's new Toggle to bring mobile virtualization to the market.

While sandboxing is traditionally done at the application level, the new technologies from VMware and Enterproid focus on creating partitions, using virtualization, to sandbox the entire mobile device. That allows a user to run two versions of a mobile operating system at the same time on the same phone: one for work, one for personal use.

In a video from the Qualcomm QPrize event demonstrating Entreproid's technology, you can see how a mobile user can seamlessly switch between the two "phones" and have full access to all 250,000+ real apps within each partition, as if they were the only apps on the device. We can finally allow Angry Birds to be installed in the personal partition and prevent it from running in the corporate partition. Huzzah!

While you can't get your hands on the tech until later this year, it has been discussed since 2009 and has been securing a very well-known user's mobile phone for over a year: President Barack Obama uses this type of virtualization technology on his BlackBerry to separate the highly secure apps he needs to run from the rest of the phone.

The benefits to enterprises are pretty compelling, too. Mobile virtualization provides all the advantages of sandboxing--mainly, full encryption of all corporate data and easy wiping of that data--as well as the benefits of non-sandbox-based approaches; for example, employees can use native mobile apps, such as the calendar and mail clients, without having to be retrained on a quirky interface from a vendor such as NitroDesk TouchDown or Good. There are new benefits, too, such as allowing an end user to upgrade to a new version of Android while the corporate partition stays at a corporate-enforced version.

We don't recommend you hold off on your MDM or mobile strategy until these technologies are available, since all the vendors we spoke with say that'll take a few months. But definitely keep it on your radar. I think that mobile virtualization will be a game changer for the enterprise if phone manufacturers provide devices that will support the technology. The holdup there is that the phone must have enough processor power and should be a dual-core device. Almost all the new Androids are dual-core, and this is something to consider if you provide stipends or guidance for users on device selection.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
J to the C
50%
50%
J to the C,
User Rank: Apprentice
11/4/2011 | 5:26:36 PM
re: MDM: To Sandbox Or Not To Sandbox?
I just read about 3LM. Looks like it takes Android to the iOS security level(s). Have you read about Mocana as well? Eventually BYOD will become BYOA (bring your own apps).
GrantMoerschel
50%
50%
GrantMoerschel,
User Rank: Apprentice
11/3/2011 | 11:13:32 AM
re: MDM: To Sandbox Or Not To Sandbox?
These are interesting developments. As I've learned more about the MDM space, I've come to the conclusion that Good-type solutions are typically going to be a dead end because user's will revolt if they can. In high security environment they can't revolt but in most others they can. Also it'll be interesting to see how standardized OS mods like those done by 3LM.com will play into hopefully normalizing the major flavors of droid so that they can be consistently controlled. Or will these VM's simply fix it all by giving people two completely different interfaces both of which are friendly and not restrictive.

Grant Moerschel, InformationWeek contributor
jrapoza
50%
50%
jrapoza,
User Rank: Apprentice
11/2/2011 | 11:14:03 PM
re: MDM: To Sandbox Or Not To Sandbox?
I agree. Mobile VMs will be the key to managing BYOB devices in a corporate environment. As pointed out, it is probably the cleanest and easiest to manage approach.

Jim Rapoza is an InformationWeek Contributing Editor
Register for Dark Reading Newsletters
White Papers
Flash Poll
Current Issue
Cartoon
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-7392
Published: 2014-07-22
Gitlist allows remote attackers to execute arbitrary commands via shell metacharacters in a file name to Source/.

CVE-2014-2385
Published: 2014-07-22
Multiple cross-site scripting (XSS) vulnerabilities in the web UI in Sophos Anti-Virus for Linux before 9.6.1 allow local users to inject arbitrary web script or HTML via the (1) newListList:ExcludeFileOnExpression, (2) newListList:ExcludeFilesystems, or (3) newListList:ExcludeMountPaths parameter t...

CVE-2014-3518
Published: 2014-07-22
jmx-remoting.sar in JBoss Remoting, as used in Red Hat JBoss Enterprise Application Platform (JEAP) 5.2.0, Red Hat JBoss BRMS 5.3.1, Red Hat JBoss Portal Platform 5.2.2, and Red Hat JBoss SOA Platform 5.3.1, does not properly implement the JSR 160 specification, which allows remote attackers to exec...

CVE-2014-3530
Published: 2014-07-22
The org.picketlink.common.util.DocumentUtil.getDocumentBuilderFactory method in PicketLink, as used in Red Hat JBoss Enterprise Application Platform (JBEAP) 5.2.0 and 6.2.4, expands entity references, which allows remote attackers to read arbitrary code and possibly have other unspecified impact via...

CVE-2014-4326
Published: 2014-07-22
Elasticsearch Logstash 1.0.14 through 1.4.x before 1.4.2 allows remote attackers to execute arbitrary commands via a crafted event in (1) zabbix.rb or (2) nagios_nsca.rb in outputs/.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Where do information security startups come from? More important, how can I tell a good one from a flash in the pan? Learn how to separate ITSec wheat from chaff in this episode.