Risk
1/23/2013
06:04 PM
Connect Directly
Twitter
RSS
E-Mail
50%
50%

New BYOD Threat: Email That Self-Destructs

Employees who bring apps like Wickr to work could bypass enterprise security systems.

Who Is Hacking U.S. Banks? 8 Facts
Who Is Hacking U.S. Banks? 8 Facts
(click image for larger view and for slideshow)
As the BYOD movement infiltrates the enterprise, IT managers have more to worry about than ever. The latest challenge: Employees who use apps to send messages that "self-destruct."

The possibility of employees dropping company secrets into Dropbox already worries IT managers, but at least such actions leave behind a trail that can be traced. What happens when employees send messages to each other and to others outside the organization that are deleted by default?

A popular app called Snapchat allows users to text self-destructing photos in real time. A similar app called Wickr takes the concept to the next level. Launched six months ago, Wickr lets users share more than just photos -- they can send encrypted multimedia messages that self-destruct after a set amount of time.

[ For more lessons learned on BYOD security, see Close The BYOD Security Hole. ]

With Wickr, you can send voice, text and audio messages, all of which delete themselves after a period of time. The app encrypts everything and it also scrubs content from the file system, making it hard for anybody to know what was sent or if anything was sent.

Wickr, which already has downloaded hundreds of thousands of times from the Apple store, offers some useful features -- for example, it provides a convenient way for journalists to communicate with sources anonymously. The Wickr app is free, but the company also offers a service that lets users send messages to groups of people. Wickr targets the messaging market, which includes apps such as WhatsApp and Voxer.

"BYOD is sweeping over the enterprise. Wickr is a way for people to have private communications on their phone without anyone seeing [them]," said Nico Sell, co-founder of Wickr and an organizer of Defcon, the largest hacker conference in the world. "We are flipping messaging on [its] head."

The industry is going to see a shift, predicted Sell. "You are going to think about how long you want something to live before you send it: [Some] kinds of messages need to live for seven years. [Other] kinds of messages -- to your spouse [for example] -- should disappear right way and not be archived."

Having that control is the main idea behind Wickr, Sell said. She has surmised from customer reviews and emails that Wickr is popular with doctors and lawyers who use it to communicate with patients and clients, and she hopes more consumers will take Wickr to the workplace. "We think of ourselves as a consumer company, and [we] are going after consumers," she said. "We give power to the people ... through anonymous free speech."

Previous
1 of 2
Next
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
JasonRemillard
50%
50%
JasonRemillard,
User Rank: Apprentice
2/7/2013 | 2:40:57 AM
re: New BYOD Threat: Email That Self-Destructs
It is interesting how 'end users' are taking 'governance' controls into their own hands this way - as with all tools - good and bad can come from it. I agree with Drew, some of this new technology is moving so quickly now that corporate policies and juristictional laws simply aren't keeping up. Imagine an HR policy on 'self destruct' messaging conduct? :)
Boons
50%
50%
Boons,
User Rank: Apprentice
1/25/2013 | 11:37:38 PM
re: New BYOD Threat: Email That Self-Destructs
Melanie, I agree. The threatening messages could be a problem. People need to be held accountable.
GAProgrammer
50%
50%
GAProgrammer,
User Rank: Apprentice
1/25/2013 | 6:52:58 PM
re: New BYOD Threat: Email That Self-Destructs
Not to mention cyber bullying, sending false information with no trace, the slippery slope goes on and on. Visit any forum and you'll see what anonymity creates - a horrible, venomous pit of nastyness, racism and sexism. This will only feed that horrible troll. Sorry, I think the bad outweighs the good in this one.
Drew Conry-Murray
50%
50%
Drew Conry-Murray,
User Rank: Ninja
1/24/2013 | 11:04:38 PM
re: New BYOD Threat: Email That Self-Destructs
I'd rather have tools like Wickr be available to help people protect speech and just accept the risk that these tools present to corporate information. Given that there are already myriad ways to get sensitive corporate information out the door, this doesn't seem to raise the risk bar much higher than it already is. What's really interesting are the legal ramifications of issues like a hostile work environment, where someone could use Wickr to send threatening messages to a coworker. That seems like a more difficult issue.

Drew Conry-Murray
Editor, Network Computing
Melanie Rodier
50%
50%
Melanie Rodier,
User Rank: Apprentice
1/24/2013 | 10:07:25 PM
re: New BYOD Threat: Email That Self-Destructs
There are of course benefits to having self-destruct messages, and it's an interesting concept, but it still seems a little dangerous from a compliance and legal and just from a general 'good citizen' standpoint not to leave any digital footprint at all...What if someone sends threatening messages that self-destruct without a trace? I think there's something to be said for people realizing that any digital behavior can be traced, for better or worse.
Register for Dark Reading Newsletters
White Papers
Flash Poll
Current Issue
Cartoon
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-0103
Published: 2014-07-29
WebAccess in Zarafa before 7.1.10 and WebApp before 1.6 stores credentials in cleartext, which allows local Apache users to obtain sensitive information by reading the PHP session files.

CVE-2014-0475
Published: 2014-07-29
Multiple directory traversal vulnerabilities in GNU C Library (aka glibc or libc6) before 2.20 allow context-dependent attackers to bypass ForceCommand restrictions and possibly have other unspecified impact via a .. (dot dot) in a (1) LC_*, (2) LANG, or other locale environment variable.

CVE-2014-2226
Published: 2014-07-29
Ubiquiti UniFi Controller before 3.2.1 logs the administrative password hash in syslog messages, which allows man-in-the-middle attackers to obtains sensitive information via unspecified vectors.

CVE-2014-3541
Published: 2014-07-29
The Repositories component in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary code via serialized data associated with an add-on.

CVE-2014-3542
Published: 2014-07-29
mod/lti/service.php in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allows remote attackers to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) is...

Best of the Web
Dark Reading Radio