Slashdot Mirror


Ask Slashdot: Equipping a Company With Secure Android Phones?

An anonymous reader writes "I'm in charge of getting some phones for my company to give to our mobile reps. Security is a major consideration for us, so I'm looking for the most secure off-the-shelf solution for this. I'd like to encrypt all data on the phone and use encryption for texting and phone calls. There are a number of apps in the android market that claim to do this, but how can I trust them? For example, I tested one, but it requires a lot of permissions such as internet access; how do I know it is not actually some kind of backdoor? I know that Boeing is producing a secure phone, which is no doubt good — but probably too expensive for us. I was thinking of maybe installing Cyanogenmod onto something, using a permissions management app to try and lock down some backdoors and searching out a trustworthy text and phone encryption app. Any good ideas out there?"

16 of 229 comments (clear)

  1. Re:Cell phone calls are already encrypted by Anonymous Coward · · Score: 5, Informative

    And blackberry messenger is too.

    To clarify on the blackberry messenger encryption: It's encrypted by default with a global key (hardly useful) but pin to pin communications can be encrypted using an organizational key, if you subscribe to a S/MIME package.

  2. Dear slashdot by Anonymous Coward · · Score: 5, Insightful

    I'd like to know how to configure a kludge of shit (using all FOSS, of course) for my enterprise environment. I want everything under the sun plus the kitchen sink.

    Also, I'm going to be paranoid and reject anything you propose. After all, I can't be sure that anything I buy doesn't have a backdoor that the government or extra terrestrials could use to snoop on the uber secrets at my company.

  3. Apple by wood_dude · · Score: 4, Insightful

    Yes, use an iPhone ! Let the flames begin...

    1. Re:Apple by Anonymous Coward · · Score: 5, Informative

      As much as I absolutely HATE to say this, you're absolutely right.

      Blackberries suck, Android's security is left to the manufacturer (so it usually doesn't get done right), Windows Phone 7(.5) is still not ready for the Enterprise, Symbian is dead, so are Meego and Maemo...

      iPhones are locked down, have enterprise support tools, come encrypted by default. Unless you're willing to inflict Blackberries on your users, AND pay for the BES, AND pay the per-handset CAL, iPhones are your best bet.

  4. Blackberry? by twnth · · Score: 5, Informative

    Why android? is there an app you need or something? or is it a latest bling thing?

    Because Blackberry does the encrypted thing, and if you buy BES you can also set device policies and centrally administer the devices (remote wipe for example).

    1. Re:Blackberry? by BagOBones · · Score: 4, Insightful

      Because starting from scratch on RIMs BB right now could be suicide...

      - New OS devices coming in the fall with a new untested management platform
      - Over stock of current gen devices they can't sell ( way under powered compared to WP, Android, iOS)
      - Bleeding management
      - Laying off huge amounts of staff.

      --
      EA David Gardner -"... but the consumers have proven that actually what they want is fun."
    2. Re:Blackberry? by b0bby · · Score: 4, Informative

      But if you're running BES (or the free Professional if you're small), everything is encrypted end to end with your own key. That's why they are so secure; 3rd parties don't have access to your data. In India & Saudi Arabia the government has put taps on the telco provided BES, but they still can't tap your private BES communications if your server is outside.

    3. Re:Blackberry? by narcc · · Score: 4, Informative

      Even cooler, with BlackBerry Balance, you can seamlessly separate work and personal use on the device. No worries about copying corporate data to personal accounts.

      Add to that the above-par remote management features and it's not even a choice -- there is only one enterprise-ready mobile platform.

  5. RIM/Blackberry by alphax45 · · Score: 5, Insightful

    You basically described the RIM/Blackberry use case; why not use them? The Bold 9900 is actually a nice phone.

    --
    K Man
  6. Sounds like a job for... by a90Tj2P7 · · Score: 4, Informative

    ... Blackberry. Aside from encrypting phone calls themselves, everything you're asking to do is something even a basic Curve will do out of the box - encrypting the phone storage and SD card, requiring a password to install apps. And that's without using any enterprise tools to manage the devices and security policies across the board, remotely.

  7. Too expensive? by hawguy · · Score: 5, Insightful

    I know that Boeing is producing a secure phone, which is no doubt good — but probably too expensive for us

    If a secure, off the shelf phone is too expensive for you, you probably don't have the resources to build a secure phone yourself. Even the experts have trouble getting security right, an amateur will unknowingly leave big gaping holes.

    That said, Android ICS will do full filesystem encryption, make sure you use a secure passphrase and not a 4 digit PIN. Use SSL to talk to your email server to keep that traffic from being snooped. Don't use SMS's.

    Do you really need to encrypt your phone calls? Stick with a CDMA provider (supposedly it's trivial to hack GSM, but I believe CDMA is still relatively safe) and your calls are safe from all but the most determined (and well funded) eavesdropper. Unless you're worried about the US Government doing the eavesdropping, they'll just tap the call on the Telco side, so you need end-to-end encryption to protect against that.

    Skype reportedly encrypts skype-to-skype calls.

    But really, unless you're doing top-secret government work, your phone is the least of your worries. If the information is valuable, it's much easier to pay an employee to leak it than to steal your phone and hope to find the data stored on the phone. And if you are doing top-secret government work, a home-brew solution isn't going to meet the federal standards you'll be required to meet.

  8. Weak spec: Secure from what while doing what? by Fubari · · Score: 5, Informative

    You spec could honestly be stronger.
    What threats do you want to secure against? What scenarios do you want to avoid? Do you want to ensure against virus protection? Lost devices? (e.g. oh noes! our client list is on wikileaks!) Locking down data?
    For bonus points, what are the top three things your "reps" need to do?
    Just make calls? Or do texting? Or access web mail? Or...?
    And how many "reps" are there today? How many will there be next year?
    And what is your logistics model? Everybody at the same physical workplace? Distributed "virtual" office? Different countries? Different languages?
    Does your phone need to integrate with any of your workflow software?

    Try writing up five or six hundred words on the above to enhance your question - I'm sure you'll get some useful advice if you do that.

  9. Re:Good for Enterprise by Bogtha · · Score: 4, Informative

    One of my clients attempted to use Good for secure email on iOS last year. They were entirely unresponsive to even the slightest technical queries and their stuff was incompatible with other apps. Also, parent comment sounds like spam.

    --
    Bogtha Bogtha Bogtha
  10. BB by Corson · · Score: 4, Informative

    There is a... um, little known company, don't know if you ever heard of it, called Research in Motion, that has been making security on their smartphones their main priority SINCE 1999.

  11. Re:we have one by X0563511 · · Score: 4, Insightful

    Seems legit.

    --
    For large sets, this will be our guide even unto death, for the LORD will work for each type of data it is applied to...
  12. Re:good luck by X0563511 · · Score: 5, Insightful

    Blame the security "roles" not the app developers.

    Want your app to detect if you're on a call, so it doesn't blow your eardrum out with an alert tone?

    Well, then you need "Access to Phone State / Identity" ... just for an example.

    --
    For large sets, this will be our guide even unto death, for the LORD will work for each type of data it is applied to...