Computerworld
Analyst blasts Windows Mobile security
Security flaw in Windows Mobile wreaking havoc for enterprises
Matthew Broersma (Techworld.com)  01 November, 2006 10:07

The latest version of Windows Mobile contain an architectural security flaw that is likely to be a turn-off for enterprises, a wireless analysis firm has said.

In a report published last week, analyst Jack Gold of J. Gold Associates said the way Microsoft Exchange and Windows Mobile 5 handle data transfer leaves sensitive corporate data inadequately protected. The software can only transfer unencrypted data to devices, and Windows Mobile doesn't provide any encryption options on the device, Gold said in the report, called "Microsoft's Direct Push Insecurity".

That leaves only a password mechanism between unauthorized users and corporate data, which is unlikely to satisfy many companies' requirements, he said. In particular, companies such as financial services firms and health-care organizations, which operate under tight regulatory restrictions, are likely to need on-device encryption.

Competitors such as Good Technology, Sybase and Research In Motion allow users to encrypt files on their devices.

The problem lies with AirSync, a derivative of ActiveSync used to transfer data to devices, Gold said. ActiveSync and AirSync can only transfer datasets with specific types of formatting, meaning encrypted data can't be transferred from Exchange Server to Pocket Outlook.

The data is encrypted while in transit, via an SSL link, but not on the device. "We believe that companies considering the use of Microsoft Direct Push Exchange technology should be very cautious," Gold said in the report.

Just two weeks ago, Kaspersky Labs reported that a flaw in Windows CE meant that mobile operating system was at a particularly high risk of attack.

Computerworld Buyer's Guide - Vendors Matched to this Article

Comments

Post new comment

Login or register to link comments to your user profile, or you may also post a comment without being logged in.
The content of this field is kept private and will not be shown publicly.
Enter the fully qualified URL, eg. http://www.example.com/
  • Web page addresses and e-mail addresses turn into links automatically.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.

More information about formatting options

Add to Google
Computerworld Buyer's Guide - Vendors Matched to this Article
Zones
Zone logoZones provide focussed content from Computerworld and leading technology partners.
Newsletter Subscription
Newsletter Subscription
Sign up for our Computerworld newsletters!
Syndicate content
 

Computerworld Webinar

Thursday, June 11th, 2009
10:30am EST (Sydney, Australia)
Screening at your PC

Computerworld is hosting a 30 minute live webinar to help you to learn how unified communications can save you money, foster innovation and business agility by making it easier for people to find, reach and collaborate with one another.

Register Now

Whitepaper

Wireless LANs: Is My Enterprise At Risk?

This paper details the risks associated with wireless LANs, and offers an overview of the inherent properties of wireless LANs and differences from wired networks. Read about real-life breaches and incidents and strengthen your own defence.

Enterprise IT Buyer's Guide
Find Technology Vendors Fast
 
Find vendors by name | Find by category
Sponsored Links
 
Send Us E-mail | Privacy Policy
Features List | Media Kit | Advertising | Contact Us

Copyright 2009 IDG Communications. ABN 14 001 592 650. All rights reserved.
Reproduction in whole or in part in any form or medium without express written permission of IDG Communications is prohibited.