nudeniom.blogg.se

Apple sandbox cloud
Apple sandbox cloud












apple sandbox cloud

To sidestep the problem of late adopters and ensure the highest level of device security possible, it’s a good idea to consider moving configuration data out of the managed app environment and store it somewhere else, eliminating the problem of lone users who either deliberately avoid updates or simply forget. Worth noting, however, is that 70 percent of iOS devices don’t get updated after critical security rollouts, sometimes for months. Escaping the TrapĪs reported by Apple Insider, the device-maker has already released a fix for this iOS sandbox problem with version 8.4.1. Improved automation is a foundation for effective mobile deployments, but Apple’s sandbox could quickly turn into a sinkhole. In effect, this is a good idea gone awry. By designing a fake corporate app and then convincing enterprise users to download it either by advertising or via targeted phishing emails, cybercriminals could infiltrate corporate systems, download configuration settings and then leverage them to access sensitive information. Although the system is supposed to limit access and only allow specific apps to read this config data, Appthority found that any app could grab all the details. Rather than requiring IT admins to continually enter app configuration data - for example, server or corporate network details - the managed app configuration system automatically stores and distributes common configurations.īut there’s a problem. This level of compromise is made possible thanks to a feature introduced in iOS 7 that streamlined the process of rolling out MDM-supervised apps. The possible impact? Security firm Appthority, which discovered the bug, said attackers “with access to an MDM managed device can read all managed configuration settings for an unpatched device.” Sinking Into the iOS SandboxĪccording to SC Magazine, the new vulnerability - CVE-2015-5749, dubbed Quicksand - poses significant risk for any company using mobile device management (MDM) clients or mobile apps distributed with MDM that rely on the Managed App Configuration setting. Now, a new iOS sandbox vulnerability threatens to wash away enterprise bring-your-own-device (BYOD) castles. Once considered a bastion of mobile security, Apple has come under fire in recent months even the company’s walled-garden model of app distribution and approval hasn’t been successful in curbing the spread of mobile malware.














Apple sandbox cloud