Advertisement
Promo

Mobile devices Toolkit

Microsoft push-email row escalates

David Meyer ZDNet.co.uk

Published: 08 Nov 2006 16:57 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Microsoft claims analyst allegations that its mobile phone operating system has inherent security flaws are inaccurate and should never have been published.

Last week the software giant refused to explicitly deny a report from Jack Gold, of US analyst firm J Gold Associates, that suggested enterprises might be turned off using Windows Mobile 5.0 devices, as data sent to the handsets via Direct Push was not encrypted on the device itself.

At the time, Microsoft would only reiterate that data was sent to the handset using SSL encryption, and suggested that password protection, coupled with the ability to remotely or locally wipe the handset, showed that "companies can trust the relationship between Windows Mobile devices and an Exchange Server to help control vital information".

However, on Wednesday Microsoft contacted ZDNet UK with a more detailed rebuttal of J Gold Associates' claims. Microsoft's UK and EMEA mobility business manager, Jason Langridge, said the company had been "disappointed by [the report] because we had made them aware that there were inaccuracies [in it], but the authors still chose to publish". He also repeated the claim that "the feedback from customers is that they feel the protection from the PIN code on the device, or [the fact] that we can remotely wipe it, or it can self-wipe, manages the risk".

"We don't encrypt the mail store, but we do have third parties that we work with if you wish to do that," Langridge added, suggesting companies such as Pointsec and Credant as examples. He also criticised companies such as RIM — which does offer embedded encryption on its BlackBerry handsets — for relaying email via network operations centres, saying: "The reason RIM has to encrypt the data is because there isn't end-to-end encryption. [Our] RC4 or triple-DES encryption ensures data is transmitted in a secure way without having to pass through a third-party relay."

Approached for a response, Jack Gold told ZDNet UK that Microsoft had indeed contacted him with "minor corrections" to several paragraphs of the report he had "purposely" sent them, and he had then incorporated those corrections into the final version.

"Their corrections we re related to [push email enabler] AirSync vs [local synchronisation tool] ActiveSync and how they functioned. Never did they refute the fact that data on the devices is not encrypted. They indicated that the data across the connection is encrypted via SSL, which I agree is a safe way to send the data. They never refuted that fact that data remains unencrypted on the device itself, which is, in my opinion, a significant flaw in their design," he said on Wednesday.

Gold then went on to repeat his assertion that, although client-side encryption can be incorporated by third-party products, "it will break the Direct Push (AirSync) mechanism… If they do indeed add Credant or Pointsec, then they have to go with a different synching capability and forego use of Direct Push". He also suggested that remote wiping was an inadequate level of protection, as a device can be lost for hours or more before anyone realises it is missing and sends the "kill message".

As for Microsoft's comments on RIM's approach to push email, Gold explained: "On the BlackBerry, all data is also encrypted while stored on the device even after it is received from the [network operations centre], and decoded when used. That is a key difference, and a requirement for many security compliance tests."

"The bottom line is, we stand by our original contention that Microsoft Direct Push has a significant disadvantage over BlackBerry, Good, Sybase and others when it comes to security if you are a user who is concerned about data loss," Gold added.

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
356 out of 432 people found this useful



Company/Topic Alerts

Create a new alert from the list below:














Video icon

Video

Enterprise Smartphones Special Report Special Report

Nokia E63

Nokia E63

Review Although it's missing some features (chiefly HSDPA and GPS), Nokia's E63 is a well-thought-out, ergonomic and affordable smartphone.

More Special Reports

On The Road Blog

Behind the Scenes: Next Gen Mobile Tec...

Behind the Scenes: Next Gen Mobile Technology Author: Eric Everson, Founder MyMobiSafe.com With infrastructure speeds continually improving at the network level of the world’s leading... More

Post a comment

The Right Mouse for the Job

It seems to me that the computer mouse is often almost an afterthought, or even gets no thought at all, when configuring or setting up a computer. In many cases (I might even go so... More

Post a comment

Apple patents point to haptics, finger...

Three patent applications made by Apple were published on Thursday, covering technologies including haptics, fingerprint recognition and RFID. The haptic feedback patent, if approved,... More

Post a comment

Discussions

182706 182706

translation

Saturday 4 July 2009, 12:15 AM

1 comment

Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters