- Is the Cisco MARS mission going to abort?
- First iPhone worm spreads Rick Astley wallpaper
- 10 stunning 3D buildings made with Google SketchUp
- Open source software ready for big business
- Four reasons to buy (and one reason to avoid) the Droid
Few corporations are likely to ban iPods in the workplace, but whether Apple and other manufacturers of MP3 players shoulder some responsibility to add security to their devices -- and how effective that security would be – is a growing debate.
Apple didn’t return multiple inquiries asking about its stance on iPod security, but plenty of others are talking about what the company should or should not do to prevent its widely popular music player from being used as a data-transfer device for stealing sensitive corporate information. While this unintended use of the iPod is not exclusive to Apple’s device – employees with malicious intent could steal data using any MP3 player, or any removable media for that matter – Apple has sold more than 100 million iPods, making it the obvious choice.
“My initial reaction was that Apple should have as much responsibility as SanDisk has for securing its USB thumb drives,” says Kurt Tappe, Apple certified engineer with JP Morgan Chase, in an e-mail. “But then I remembered that iPods do not come out of their shipping containers with the ability to be used as data drives. The user must explicitly turn that function on in iTunes. To that end, it seems to me that Apple has already gone one step beyond other drive manufacturers.”
An extensive search of the iPod and iTunes sections of Apple’s Web site turned up no information about setting the devices for data transfer, but also did not warn against the potential for misuse when iPods are set as such. However, in Apple's support section, there is an entry explaining how to enable an iPod as a storage device.
Others say Apple may not be responsible for securing its device beyond the basic lock function that it comes with, but offering such features couldn’t hurt. This could become particularly important as corporate IT departments begin to consider purchasing other Apple products, such as Mac desktops and servers, in helping Apple build confidence among security-conscious enterprises.
“I wouldn’t put this responsibility on [Apple] as mandatory; I would prefer to see Apple offer it as an add-on feature and let the market dictate its usefulness,” wrote Louis Tinto, risk manager and director of technology risk assessment with a large financial-services company, in an e-mail. He stresses that educating employees about corporate policies regarding use of such devices and having workers regularly attest to their understanding of such policies is the best first step to take in protecting against data theft via iPods.
Another important consideration for Apple is that some enterprises are beginning to use iPods as corporate devices and will want to integrate them into their security plans, so offering such protection could become a make-or-break issue for selling into these accounts.
According to a press release issued by NextSentry, which makes desktop software that prevents unauthorized copying of data to removable media and which issued the warning of iPods in the workplace, these devices have been purchased by the thousands by manufacturing companies, financial-services firms and healthcare suppliers as a means to train, educate and inform their employees.
Comments (34)
Take away my iPod? I'd quit firstBy Anonymous on April 10, 2007, 10:02 amSheesh... What ever happened to trust between an employee and the employer? Re: Can an iPod bring down your company? If my company told me that I could...
Reply | Read entire comment
The iPod is the threat? HowBy Anonymous on April 10, 2007, 11:20 amThe iPod is the threat? How many companies let their employees walk out the door with a laptop? How many let employees visit SSL secured websites. These are equally...
Reply | Read entire comment
Almost all MP3 players haveBy Anonymous on April 10, 2007, 11:49 amAlmost all MP3 players have the capability to act as a repository for copying and removing data, not just iPods from Apple. The question really is how do we as managers...
Reply | Read entire comment
RE: The iPod is the threat? HowBy Anonymous on April 10, 2007, 12:20 pmWhat? Did you not read the article?? People with laptop's are usually entrusted with those devices...they sign IT policies or their system's are locked down to...
Reply | Read entire comment
Whenever I see someone toutBy Anonymous on April 10, 2007, 1:27 pmWhenever I see sompone tout a product as 1E6 times better than anything else, I smell vested interest. This is clearly the case of a solution looking for a problem....
Reply | Read entire comment
Well, there you go then..By Anonymous on April 10, 2007, 1:53 pmWell, there you go then.. there's that difference. Our laptops and PC's are locked down tight and if the end user requires "admin" access we remotely take care of...
Reply | Read entire comment
View all comments