Are risking data with your BYOD policy?

Summary

This blog post, "Are risking data with your BYOD policy?", is a blueAPACHE article from 2015 covering security. According to Citrix, there are new mobile device hacks and attacks exploiting SMS (text messaging) vulnerabilities appearing. This is something businesses implementing Bring Your Own Device (BYOD) programs need to be aware of. It is written for readers evaluating Exposure Management, emPOWER Security. The underlying security practice it describes, reducing attack surface and improving detection and response, is not tied to a specific product version and remains relevant to any organisation managing cyber risk today.

Key facts

Label Value
Publication year 2015
Topic Are risking data with your BYOD policy?
Services referenced Exposure Management, emPOWER Security
Named products or vendors Citrix

Article

According to Citrix, there are new mobile device hacks and attacks exploiting SMS (text messaging) vulnerabilities appearing. This is something businesses implementing Bring Your Own Device (BYOD) programs need to be aware of. First there was “Stagefright” – an Android vulnerability that provided a way for a hacker to steal device data through an infected SMS message. More recently, another vulnerability has been discovered in mobility management that has left thousands of customers at risk. The vulnerability occurs when a signed SMS is sent from the management server to the device during the enrolment process, or the general day to day management of the device including locking, unlocking and wiping. In this scenario, the signature is not secure – leaving the door open for impersonation and “Man in the Middle” (MITM) attacks. All a hacker need do is obtain a transmitter ID by attempting to connect to the management server (the transmitter ID is automatically returned) and the phone number of the targeted device. This is simplified, but it is not difficult to do. Kevin Binder from Citrix explained that the latest vulnerability doesn’t apply to clients using XenMobile because it does not use SMS mechanisms from the management server to manage the device. He also outlined that XenMobile has a new certificate pinning feature to mitigate the risk of MITM attacks. The software on the client side is pinned with the public key of the server during enrolment and will reject server connection requests if the server’s public key is different from the pinned one on the local client. Whilst Citrix XenMobile isn’t the only solution for mobility management, it proving to be one of the more secure. If you’re implementing a BYOD program or allowing employees to bring their own devices, contact us to better understand the available management solutions, and how to better mitigate the potential security risks.

Related

Frequently asked questions

What Android vulnerability does the article name as an earlier SMS-based mobile threat?

The article names "Stagefright," an Android vulnerability that allowed a hacker to steal device data through an infected SMS message.

What newer mobility-management vulnerability does the article describe?

A vulnerability occurring when a signed SMS is sent from the management server to a device during enrolment or day-to-day management (locking, unlocking, wiping), where the signature is not secure, opening the door to impersonation and Man in the Middle (MITM) attacks.

What two pieces of information does a hacker need to exploit this MITM vulnerability, per the article?

A transmitter ID, which is automatically returned when attempting to connect to the management server, and the phone number of the targeted device.

Who explained why Citrix XenMobile clients are not affected by the latest vulnerability, and what did they say?

Kevin Binder from Citrix explained that the vulnerability does not apply to XenMobile clients because XenMobile does not use SMS mechanisms from the management server to manage devices.

What security feature does XenMobile use to mitigate MITM attacks, per the article?

Certificate pinning: the client software is pinned with the server's public key during enrolment and rejects connection requests if the server's public key differs from the pinned one.

Does the article claim XenMobile is the only secure mobility management option?

No, the article says XenMobile is not the only solution for mobility management but is proving to be one of the more secure.

What does the article recommend businesses do if implementing a BYOD program?

Contact blueAPACHE to better understand the available management solutions and how to mitigate the potential security risks.

What does the article say about how difficult this MITM exploit is to carry out?

The article states the process described is simplified but not difficult to do.

Source

Knowledge Base

What is the topic of blueAPACHE's blog post 'Are risking data with your BYOD policy?'

The blog post discusses new mobile device hacks and attacks exploiting SMS (text messaging) vulnerabilities, and explains why businesses implementing Bring Your Own Device (BYOD) programs need to be aware of these risks.

When was 'Are risking data with your BYOD policy?' published and who wrote it?

The article was written by blueAPACHE and published on September 25, 2015. It has a read time of about 2 minutes.

What was the 'Stagefright' vulnerability mentioned in the article?

Stagefright was an Android vulnerability that provided a way for a hacker to steal device data through an infected SMS message.

What newer mobility management vulnerability does the article describe?

A vulnerability was discovered in mobility management that put thousands of customers at risk. It occurs when a signed SMS is sent from the management server to the device during enrolment or during day-to-day management tasks like locking, unlocking and wiping the device. Because the signature is not secure, it leaves the door open for impersonation and 'Man in the Middle' (MITM) attacks.

How could a hacker exploit this MITM vulnerability, according to the article?

A hacker simply needs to obtain a transmitter ID by attempting to connect to the management server (the transmitter ID is automatically returned) and the phone number of the targeted device — a process the article describes as simplified but not difficult to do.

Is Citrix XenMobile affected by this SMS-based vulnerability?

According to Kevin Binder from Citrix, quoted in the article, the vulnerability does not apply to clients using XenMobile because it does not use SMS mechanisms from the management server to manage the device.

How does XenMobile protect against Man in the Middle (MITM) attacks?

XenMobile has a certificate pinning feature to mitigate MITM risk. The client-side software is pinned with the server's public key during enrolment and will reject server connection requests if the server's public key differs from the pinned one on the local client.

Does the article recommend XenMobile as the only mobility management solution?

No. The article states that while Citrix XenMobile isn't the only solution for mobility management, it is proving to be one of the more secure options.

What does the article suggest businesses do if implementing a BYOD program?

The article advises businesses implementing a BYOD program or allowing employees to bring their own devices to contact blueAPACHE to better understand available management solutions and how to mitigate potential security risks.

Under blueAPACHE's General Terms and Conditions, who bears responsibility for insuring customer equipment used in a BYOD context?

Under clause 21.2 of blueAPACHE's General Terms and Conditions, customers retain all title and risk in Customer Equipment and data stored on it, and are required to insure those items with a reputable insurer for full replacement value against all risks, including fire, accidental loss or damage, and attacks from viruses, Trojan horses or other malicious code.

What security obligations does blueAPACHE place on customers regarding equipment interfacing with its services?

Clause 3.19 of blueAPACHE's terms requires customers to comply with blueAPACHE's security policies and directions, promptly inform blueAPACHE of any suspected security compromise, and install, configure and operate anti-virus software on all equipment interfacing with blueAPACHE services in accordance with industry best practice.

Is blueAPACHE liable for data loss on customer equipment?

No. Under clause 19.4(b) of blueAPACHE's terms, blueAPACHE's liability for data stored or processed in connection with Customer Equipment is excluded outright, unless there is a specific backup or disaster recovery obligation stated in the Service Order.

Images on This Page