Jailbreaking: Don’t blame the player, blame the game

Analysis
Jun 1, 20126 mins

Jailbroken devices being banned in BYOD policies are wrong

There has been much written (here, here and here) lately about what threat jailbroken and/or rooted devices pose to organizations. Should they be handled as special cases as part of a BYOD policy? Should they be just flat-out banned from the network because they pose greater risks? Should we have special AV and security products aimed at jailbroken and rooted devices? Lots of questions raised, little in the way of hard answers, but lots of opinions, as usual.

I’m sure much of this has to do with the recent release of the Absinthe 2.0 (2.04 if you want the latest version) jailbreak that includes jailbreaking all of the latest versions of iPhones and iPads. On top of this there has been a lot of thoughts and comments recently around the whole area of BYOD policies in general. My friend and fellow Network World writer Jon Oltsik has a good article on that here.

RELATED: Is The Jailbreak Community Contaminated By Leeches?

The knee-jerk reaction has been to say that jailbroken devices represent an increased risk to the network and should be banned; That security companies should produce special versions of their mobile security programs to protect against the enhanced threat that these devices present. As the owner of both a jailbroken iPhone and a rooted Touchpad with Android, I have some mixed feelings on this.

RELATED: BYOD Security Gotchas: Policy creation and enforcement have become a real problem

First as to Android. I have encountered several programs that will not let me watch DRM-protected content because they detect my device is rooted. Putting aside my ill feelings towards DRM in general, I resent the limitation. I have done nothing illegal in rooting my Touchpad. Isn’t Android supposed to be open source anyway? Not being able to come up with a DRM scheme that covers rooted devices is not a reason to deny me the ability to view this content on a lawful device. I am made to suffer because you can’t make a better mousetrap.

As far as using rooted Android on the network, there seems to be less push back on this than on iPhone, probably due to the fact that Android already has less of a “walled garden” security policy to begin with. Android users have much more leeway to download, install and run applications that don’t have to go through the Cupertino Ministry of Propaganda for approval. This may in fact represent a higher degree of security risk, but it also represents a higher degree of freedom. I am all about freedom on this issue I am afraid. I would err on the side of user education before I would want big brother vetting all of my choices for me. So, my BYOD policies on Android would include an education on where, when and how to download and use apps. Like the old commercial says, an educated consumer is your best customer.

Jailbroken iPhones and iPads are another story. While claiming to not be enterprise tools (and if you ask some developers they will confirm this, as it is a pain in the butt to develop commercial enterprise iPad apps), Apple’s products have broken down the back door and are pandemic on many work networks. It is generally agreed that because all apps must go through the app store to be installed, Apple’s mousetrap is more secure than the Android model. However, it also gives Apple final say over what you can and cannot run on your own device. Many millions of people just can’t abide by that. They have taken to the perfectly legal practice of jailbreaking their phones. Of course, this now means that you can install applications that have not been approved by Apple. Therein lies the rub.

This ability to add unapproved applications and code has led many to say that jailbroken devices are therefore an increased security risk and should be banned from the network. Others say that the ability to add non-Apple-approved devices should neccissate the addition of additional security software that not only is not needed on non-jailbroken devices, but is impossible to run on non-jailbroken devices because Apple does not give security programs access to what they need to do the job. So as long as the device is jailbroken anyway, why not take advantage of that and give it the security it deserves?

Of course, most folks only add applications through Cydia, which becomes just another appstore and doesn’t have the ability to just add apps and code without it. But that is beside the point. I actually would welcome security programs optimized for jailbroken devices. If I have the enhanced access on my device that Apple refuses to give me, why not use it for enhanced security as well. I think this is far superior than relying on Apple’s benevolent dictator model of security that we have now. So enhanced security for jailbroken devices is fine.

Banning jailbroken devices is another story, though. I think that is silly. First of all, most who jailbreak their devices are more sophisticated than the usual zombies who march to the easy-is-good Apple mantra. They know how to jailbreak, so probably know more about being wary of security risks as well.  

Apple has created a system where if you want freedom over the device you own you have no choice but to jailbreak. Banning these devices is putting the blame and punishment on the wrong party. It should go back to Apple.

For all of the walls they put around their garden, time and time again we see that the jailbreak community is able to bust them down. Let me tell you this: if the jailbreak community can break down the walls time and time again, don’t think for an instant that the bad guys can’t. All we have is a mistaken sense of security with these Apple devices. By thinking that only jailbroken devices are a security threat we are setting ourselves up for a big fail.

Let me get down off my soapbox now. But when it comes to jailbroken and rooted devices, don’t blame the player, blame the game.