Lemmy Today
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
King@lemy.lol to People Twitter@sh.itjust.works · 1 year ago

Would you give your phone’s password to your boss?

lemy.lol

message-square
129
link
fedilink
665

Would you give your phone’s password to your boss?

lemy.lol

King@lemy.lol to People Twitter@sh.itjust.works · 1 year ago
message-square
129
link
fedilink

https://social.joelle.us/@joelle/111798189218029748

  • 520@kbin.social
    link
    fedilink
    arrow-up
    28
    arrow-down
    25
    ·
    1 year ago

    … actually they aren’t wrong. MDMs are given special permissions including but not limited to reading your SMSes and phone records, restricting and monitoring your installed apps and even wiping your device.

    • Eddie Trax@dmv.social
      link
      fedilink
      English
      arrow-up
      52
      arrow-down
      6
      ·
      edit-2
      1 year ago

      I’m not sure what MDM you’re subjected to but I’ve been an MDM engineer for 7 years using Intune and JAMF and no, no SMS or phone records. Even the phone # is blanked out minus the last 4 digits. Yes we can wipe the devices if it’s lost\compromised but personal versus corporate owned devices are limited. I can’t see what apps you have that were personally installed. And the only info I can get are the device stats (SN, IMEI, storage, battery, memory, etc).

      • 520@kbin.social
        link
        fedilink
        arrow-up
        23
        arrow-down
        1
        ·
        edit-2
        1 year ago

        Intune and JAMF are not the only MDMs on the market. There are others that do offer these capabilities, at least on Android.

        SMS reading:

        https://support.sophos.com/support/s/article/KB-000034436?language=en_US

        Call log reading:

        https://knowledgebase.42gears.com/article/how-to-view-call-logs-on-android-phones-remotely-using-suremdm/

        And app lists:

        https://help.ivanti.com/mi/help/en_us/cld/admin/ivanti/91/all/en-us/App_Inventory.htm

        • Eddie Trax@dmv.social
          link
          fedilink
          English
          arrow-up
          10
          arrow-down
          1
          ·
          1 year ago

          Yeah I have looked at those solutions and one not on your list (MobileIron, not sure if they’re still around). I don’t know why anyone would choose those solutions but good call.

          • 520@kbin.social
            link
            fedilink
            arrow-up
            2
            ·
            1 year ago

            I also don’t know why anyone would use these either FWIW

    • LilB0kChoy@midwest.social
      link
      fedilink
      arrow-up
      42
      arrow-down
      5
      ·
      edit-2
      1 year ago

      deleted by creator

      • 520@kbin.social
        link
        fedilink
        arrow-up
        7
        arrow-down
        2
        ·
        1 year ago

        SMS reading:

        https://support.sophos.com/support/s/article/KB-000034436?language=en_US

        Call log reading:

        https://knowledgebase.42gears.com/article/how-to-view-call-logs-on-android-phones-remotely-using-suremdm/

        app lists:

        https://help.ivanti.com/mi/help/en_us/cld/admin/ivanti/91/all/en-us/App_Inventory.htm

        • LilB0kChoy@midwest.social
          link
          fedilink
          arrow-up
          6
          arrow-down
          2
          ·
          1 year ago

          deleted by creator

          • 520@kbin.social
            link
            fedilink
            arrow-up
            1
            ·
            1 year ago

            I looked through your links. I don’t see anywhere that SMS can be read.

            From the link, emphasis mine. SMC is the MDM in question

            Read SMS or MMS
            Allows an application to read SMS messages stored on your device or SIM card.
            Malicious applications may read your confidential messages.
            SMC usage:

            1. Read the initial configuration and further server notifications.
              2. Read all SMS for Backup.
            • LilB0kChoy@midwest.social
              link
              fedilink
              arrow-up
              0
              ·
              edit-2
              1 year ago

              deleted by creator

              • 520@kbin.social
                link
                fedilink
                arrow-up
                1
                ·
                1 year ago

                …why would they need to backup all SMS messages for a filtering option? That just plain does not compute.

                • LilB0kChoy@midwest.social
                  link
                  fedilink
                  arrow-up
                  1
                  ·
                  1 year ago

                  deleted by creator

    • n1ckn4m3@kbin.social
      link
      fedilink
      arrow-up
      26
      arrow-down
      7
      ·
      edit-2
      1 year ago

      Please cite any one of your sources. I’ve managed MDM for over a decade and you’re spreading misinformation.

      Absolutely none of the MDM products on the market allow for the reading of personal e-mail, SMS, phone records, etc. On the contrary, almost every single one provides an information screen during the enrollment that makes it abundantly clear that they do not (and can not) access that data. Moreover, the “wipe” of data is the removal of company data. It doesn’t wipe your phone, it just removes the work profile (Android) or deprovisions the work profile and associated apps (Apple). All of your non-work-related data is untouched.

      Quick Sources for Intune and JAMF – do your own googling for others:
      https://learn.microsoft.com/en-us/mem/intune/protect/privacy-data-collect
      https://www.jamf.com/blog/apple-mobile-device-management-faq/

      • 520@kbin.social
        link
        fedilink
        arrow-up
        15
        ·
        edit-2
        1 year ago

        Absolutely none of the MDM products on the market allow for the reading of personal e-mail, SMS, phone records, etc.

        So you’re not aware of Sophos’s MDM offering? That explicitly states they can make copies of all SMS messages?

        https://support.sophos.com/support/s/article/KB-000034436?language=en_US

        How about call logs, with SureMDM?

        https://knowledgebase.42gears.com/article/how-to-view-call-logs-on-android-phones-remotely-using-suremdm/

        Also I said nothing about personal emails.

        Moreover, the “wipe” of data is the removal of company data. It doesn’t wipe your phone, it just removes the work profile (Android) or deprovisions the work profile and associated apps (Apple). All of your non-work-related data is untouched.

        No, the ‘wipe’ can be a full factory reset.

        https://learn.microsoft.com/en-us/mem/intune/remote-actions/devices-wipe

        Edit: typo

People Twitter@sh.itjust.works

whitepeopletwitter@sh.itjust.works

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !whitepeopletwitter@sh.itjust.works

People tweeting stuff. We allow tweets from anyone.

RULES:

  1. Mark NSFW content.
  2. No doxxing people.
  3. Must be a pic of the tweet or similar. No direct links to the tweet.
  4. No bullying or international politcs
  5. Be excellent to each other.
  6. Provide an archived link to the tweet (or similar) being shown if it’s a major figure or a politician.
Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 1.23K users / day
  • 3.94K users / week
  • 9.52K users / month
  • 19.4K users / 6 months
  • 66 local subscribers
  • 7.08K subscribers
  • 1.27K Posts
  • 62.5K Comments
  • Modlog
  • mods:
  • SendMeYourTaTas@sh.itjust.works
  • pelespirit@sh.itjust.works
  • BE: 0.19.11
  • Modlog
  • Legal
  • Instances
  • Docs
  • Code
  • join-lemmy.org