ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Mobile devices Toolkit

Microsoft push-email row escalates

David Meyer ZDNet.co.uk

Published: 08 Nov 2006 16:57 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Microsoft claims analyst allegations that its mobile phone operating system has inherent security flaws are inaccurate and should never have been published.

Last week the software giant refused to explicitly deny a report from Jack Gold, of US analyst firm J Gold Associates, that suggested enterprises might be turned off using Windows Mobile 5.0 devices, as data sent to the handsets via Direct Push was not encrypted on the device itself.

At the time, Microsoft would only reiterate that data was sent to the handset using SSL encryption, and suggested that password protection, coupled with the ability to remotely or locally wipe the handset, showed that "companies can trust the relationship between Windows Mobile devices and an Exchange Server to help control vital information".

However, on Wednesday Microsoft contacted ZDNet UK with a more detailed rebuttal of J Gold Associates' claims. Microsoft's UK and EMEA mobility business manager, Jason Langridge, said the company had been "disappointed by [the report] because we had made them aware that there were inaccuracies [in it], but the authors still chose to publish". He also repeated the claim that "the feedback from customers is that they feel the protection from the PIN code on the device, or [the fact] that we can remotely wipe it, or it can self-wipe, manages the risk".

"We don't encrypt the mail store, but we do have third parties that we work with if you wish to do that," Langridge added, suggesting companies such as Pointsec and Credant as examples. He also criticised companies such as RIM — which does offer embedded encryption on its BlackBerry handsets — for relaying email via network operations centres, saying: "The reason RIM has to encrypt the data is because there isn't end-to-end encryption. [Our] RC4 or triple-DES encryption ensures data is transmitted in a secure way without having to pass through a third-party relay."

Approached for a response, Jack Gold told ZDNet UK that Microsoft had indeed contacted him with "minor corrections" to several paragraphs of the report he had "purposely" sent them, and he had then incorporated those corrections into the final version.

"Their corrections we re related to [push email enabler] AirSync vs [local synchronisation tool] ActiveSync and how they functioned. Never did they refute the fact that data on the devices is not encrypted. They indicated that the data across the connection is encrypted via SSL, which I agree is a safe way to send the data. They never refuted that fact that data remains unencrypted on the device itself, which is, in my opinion, a significant flaw in their design," he said on Wednesday.

Gold then went on to repeat his assertion that, although client-side encryption can be incorporated by third-party products, "it will break the Direct Push (AirSync) mechanism… If they do indeed add Credant or Pointsec, then they have to go with a different synching capability and forego use of Direct Push". He also suggested that remote wiping was an inadequate level of protection, as a device can be lost for hours or more before anyone realises it is missing and sends the "kill message".

As for Microsoft's comments on RIM's approach to push email, Gold explained: "On the BlackBerry, all data is also encrypted while stored on the device even after it is received from the [network operations centre], and decoded when used. That is a key difference, and a requirement for many security compliance tests."

"The bottom line is, we stand by our original contention that Microsoft Direct Push has a significant disadvantage over BlackBerry, Good, Sybase and others when it comes to security if you are a user who is concerned about data loss," Gold added.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Kyocera

Did you find this article useful?
352 out of 428 people found this useful



Company/Topic Alerts

Create a new alert from the list below:














Related Jobs

Senior ASP.Net / C# Developer. Gold Partner C#, ASP.Net 2.0. Stockport

The role will involve working for this Gold Partner development specialist division of a Multinational company who have been voted in the top 100 ...

C++ VC++ Software Engineer Windows Mobile Mobile comms

Huxley Associates has a new requirement for C++ VC++ software Engineer to start a new 6-month contract in the heart of the Thames Valley. For this ...

3rd Line Support Microsoft Gold Certified Partner - Richmond, London

A Wintel 3rd Line Support specialist working with a Microsoft Gold Certified Partner based in the Richmond, London for their banking clients. The ...

Featured Talkback

Put simply, what is the compelling reason to pay ~$200 extra for an Eee with Windows XP? A Windows Eee won't come with any useful applications and you'll have to buy anti-virus software to boot. The truth about low cost computing is that nobody really cares whether the machine is running Windows or Linux as long as its cheap, its easy to use and it works.

By: dogStar

Read full story:
Asus to ship 60 percent of Eee PCs with Windows XP

On The Road Blog

iPhone heaven/iPhone hell

Steve Jobs owes me nearly two hours of my life back. Or at least he would do if I wasn't so chuffed with the iPhone that finally became mine after a bum-achingly long period propped... More

3 comments

The App store spells death to Jailbrea...

I'd love to say that the quality of Apps on the Apple App store is so superior to those made for jailbroken iPhones that no one would bother jailbreaking anymore. However, this is definitely... More

6 comments

Lenovo debuts new small-business noteb...

With Intel and Vodafone along for the ride, Lenovo today launched a brand-new SL range of small-business-focussed ThinkPads, refreshed the T series (performance), R series (mainstream)... More

Post a comment

Discussions

1000030281 1000030281

Facebook Bans Firefox 3

Sunday 20 July 2008, 2:33 AM

1 comment
roger andre roger andre

SP3 Under Suspicion Again

Saturday 19 July 2008, 9:29 PM

2 comments