Skip Links

Network World

  • Social Web 
  • Email 
  • Close

Should Apple secure its iPods?

Debate over responsibility, usefulness of device security grows
By Cara Garretson , Network World , 04/16/2007

Few corporations are likely to ban iPods in the workplace, but whether Apple and other manufacturers of MP3 players shoulder some responsibility to add security to their devices -- and how effective that security would be – is a growing debate.

Apple didn’t return multiple inquiries asking about its stance on iPod security, but plenty of others are talking about what the company should or should not do to prevent its widely popular music player from being used as a data-transfer device for stealing sensitive corporate information. While this unintended use of the iPod is not exclusive to Apple’s device – employees with malicious intent could steal data using any MP3 player, or any removable media for that matter – Apple has sold more than 100 million iPods, making it the obvious choice.

“My initial reaction was that Apple should have as much responsibility as SanDisk has for securing its USB thumb drives,” says Kurt Tappe, Apple certified engineer with JP Morgan Chase, in an e-mail. “But then I remembered that iPods do not come out of their shipping containers with the ability to be used as data drives. The user must explicitly turn that function on in iTunes. To that end, it seems to me that Apple has already gone one step beyond other drive manufacturers.”

An extensive search of the iPod and iTunes sections of Apple’s Web site turned up no information about setting the devices for data transfer, but also did not warn against the potential for misuse when iPods are set as such. However, in Apple's support section, there is an entry explaining how to enable an iPod as a storage device.

Others say Apple may not be responsible for securing its device beyond the basic lock function that it comes with, but offering such features couldn’t hurt. This could become particularly important as corporate IT departments begin to consider purchasing other Apple products, such as Mac desktops and servers, in helping Apple build confidence among security-conscious enterprises.

“I wouldn’t put this responsibility on [Apple] as mandatory; I would prefer to see Apple offer it as an add-on feature and let the market dictate its usefulness,” wrote Louis Tinto, risk manager and director of technology risk assessment with a large financial-services company, in an e-mail. He stresses that educating employees about corporate policies regarding use of such devices and having workers regularly attest to their understanding of such policies is the best first step to take in protecting against data theft via iPods.

Comments (34)
Login
Forgot your account info?

Yeah, I didBy Walt on September 28, 2007, 6:05 pmTFA said that physical and/or software locks were too complicated for your average IT site, so an iPod ban was smarter. As you say, they're not really, and I say,...

Reply | Read entire comment

a ban?By Walt on September 28, 2007, 5:56 pmA "ban on iPods" would be both too specific (i.e., wouldn't cover thumb drives, cameras, pencil & paper, etc., on which data can just as easily be stolen) and too...

Reply | Read entire comment

>Our objective is simply toBy David on April 21, 2007, 10:27 pm>Our objective is simply to reduce the risk >associated with data that is moved thorough such >means(content analysis) Is this a joke ? What is to stop someone...

Reply | Read entire comment

You Made No SenseBy Cydus on April 20, 2007, 12:20 pmPeople who tend to read these forums tend to have an understanding for physical security. Seems like your still unfamiliar with it and thats cool, just don't make...

Reply | Read entire comment

more than iPodBy Cydus on April 20, 2007, 12:16 pmI totally agree. In typical IT policies in companies they ban any type of removable storage device from accessing the network (iPod is classified as such a device)....

Reply | Read entire comment

View all comments

Add comment
Anonymous comments subject to moderator approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed
Save The Date!
What They Are Saying

The Diane's of the industry should be acknowledged for their understanding of why products fail when...- Anon

Join the Discussion