Home
BYTE Newsletter
Keep up with all the BYTE News and Reviews

Subscribe
Dino Londis

Dino Londis



How Consumerization is Lowering Security Standards

Comments | Dino Londis, BYTE | August 10, 2012 11:30 AM

Category: Tablets, Smartphones, Social Networking

When Apple and Amazon unknowingly contributed to the deletion of Wired journalist Mat Honan's digital life, the two technology giants also unwittingly revealed that they haven't built adequate security into their cloud services. Apple already is under investigation by Congress to determine if it adequately protected customers' privacy when it allowed developers' access to the iPhone's unique hardware identifier.

Honan lost his data when a couple of 19-year-olds wanted his Twitter handle. They used no technical equipment except their phone. The two impersonated Honan in calls to the providers' help desks with only a few bits personal info. First they changed his Amazon password, then his iCloud password, then his Google password, and finally his Twitter account. No encryption algorithm could have prevented that hack, which took all of half an hour.

The threat to safety of cloud computing is in the numbers. Yahoo, LinkedIn, Dropbox, and e-Harmony have lost millions of customer passwords in the last three months alone. Three of them host platforms. Yahoo Small Business, for example, is driven with the user's Yahoo email password. Both Apple and Amazon host their customers' entire digital library, such as ebooks, music, personal notes, family photos--everything.

Consumerization is, in a sense, a democratization of technology where employees can pick the best products and services from the market. And the IT department is only in a position to make recommendations, yet still provide alternatives. For example, although employers are willing to incorporate employee-purchased iPhones into the enterprise, many will still issue the RIM Blackberry, which is far more secure.

And the difference between those two phones might be at the heart of consumerization of IT (CoIT)'s biggest challenge: Mob rule. No too long ago, when the IT department dictated that Blackberries were the only phone, it was acting as a benevolent dictator. Security is Blackberry's greatest strength yet it's a blip in sales to consumers.

The allure of cloud storage is its ease of use. A central repository that employees can access from anywhere on any device improves productivity because the user can work on the latest version and collaborate with colleagues and customers. If cloud providers adopted a stricter authentication policy, they risk losing customers to a competitor that promises greater convenience--which is always a trade-off for security. In a risk management assessment, cloud providers might conclude that it's better to grow exponentially with a reduced security threshold and manage the fallout from a breach, than to make a rock-solid system that no one will use.

From a wall at the Washington, D.C., International Spy Museum.

Providers already are upselling convenience over security. Even though Android is not a secure mobile platform, nearly all providers make an app for it. In March, Dropbox partnered with Facebook, making sharing documents easier with friends.

And companies aren't anxious to upset their existing password policies. Just look at the actions of Apple and Amazon, even after the Mat Honan PR nightmare. According to Wired, Apple currently is "deciding how much strictness is required."

The cornerstone of consumerization is secure public servers--i.e. the cloud--to store and manage our digital life. Even credit cards are now stored in the cloud with Google Wallet. Yet few cloud providers have demonstrated a bulletproof method to keep customer data safe. Smaller companies such as Watchdox and FileTrek that initially offered cloud-based document management services are now marketing non-cloud enterprise-based solutions for hosting customer data. It makes sense. Among other reasons, even in very large companies, impersonating a user to change a password will be quickly detected by a help desk technician because the tech will likely know the caller.

Honan had done everything right. He backed up the local copies of his files to iCloud, but iCloud's tight integration coupled with changing the password for a stranger allowed the service to reach into his hard drive and delete his personal and corporate data.

Tech giant clouds breached in 2012:

  • Yahoo -- In July, 435,000 passwords were stolen. What's worse, TrustedSec, the security firm that discovered the hack, said the passwords were stored in clear text so they could be used immediately.
  • LinkedIn -- In June, a Russian hacker lifted 6 million passwords that were inadequately encrypted. The hack revealed how little attention LinkedIn paid to security.
  • Dropbox -- In August, User names and passwords culled from other websites were tested on Dropbox accounts. One of those stolen passwords was used to access a Dropbox employee's account, which contained a project document with Dropbox user email addresses. [[Correction: An earlier version misstated the role of the Dropbox employee in this incident.]]
  • eHarmony -- In June, a hacker stole 1.5 million passwords from the dating service.
  • Apple and Amazon -- In August, both were duped by two men who wanted to steal a Twitter handle.



Related Reading


More Insights




Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

BYTE encourages readers to engage in spirited, healthy debate, including taking us to task. However, BYTE moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. BYTE further reserves the right to disable the profile of any commenter participating in said activities.

COMMENTS

Tune In to BYTE
Facebook Twitter LinkedIn Newsletter RSS
Whitepapers
whitepaper
In this paper you will learn the five trends shaping the future of enterprise mobility. Learn how the rise of social media as a business application, the lurring between work and home, the emergence of new mobile devices, the demand for tech savvy employees and changing expectations of corporate IT will fundamentally change the workplace.
whitepaper
In a survey of more than 1,700 information workers (iWorkers) in North America, notebooks, desktops, and smartphones were found to be “must-have” devices, while tablets, slates, and netbooks were relegated to “nice-to-have” status, according to a commissioned study conducted by Forrester Consulting on behalf of Dell and Intel.
Sponsored by: Dell
Upcoming Events