Educause Security Discussion mailing list archives

Re: ipads/iphones and full disk encryption


From: David Seidl <dseidl () ND EDU>
Date: Wed, 12 Oct 2011 11:27:10 -0400

Jason,

There are a couple of forensic products that can pretty easily crack iPad/iPhone encryption, and I use those as my 
benchmark for ease of cracking. Given those, you're right.

I tend to explain it to our users in much the same way we do locks on filing cabinets: they don't keep people who 
really want in out, but it does mean that casual theft of data is less likely to happen. In most cases when we see a 
phone or device lost or stolen, it's wiped and sold, rather than having its data harvested.  That may change, and isn't 
guaranteed to be the case, but it is what I've seen most often.

If you can pair a chance of remote wipe succeeding with encryption on by default that makes it more difficult for 
casual data access, you're not in an ideal circumstance, but you're better off than without either. Limiting data 
available on the device, and having a process that you communicate broadly and actively to your campus for handling 
lost or stolen devices and attached accounts and cloud services also helps.

David

David Seidl, CISSP, GCIH
Director of Information Security
Office of Information Technologies
University of Notre Dame
Notre Dame, IN 46556
(574) 631-7305
dseidl () nd edu<mailto:dseidl () nd edu>



From: The EDUCAUSE Security Constituent Group Listserv [mailto:SECURITY () LISTSERV EDUCAUSE EDU] On Behalf Of 
Youngquist, Jason R.
Sent: Wednesday, October 12, 2011 10:44 AM
To: SECURITY () LISTSERV EDUCAUSE EDU
Subject: [SECURITY] ipads/iphones and full disk encryption

As many of you know, ipads/iphones and other devices are being introduced into the corporate and educational 
institution environment.  Currently we require all institutional owned laptops to be encrypted using full disk 
encryption.  The Apple ipad/iphone supposedly has "full disk encryption" but I've done a bit of googling and it appears 
that the encryption is really all that it is cracked up to be (see reference URLs below).  So, I'm wondering how other 
organizations are addressing this threat - specifically since a number of high-level folks seem to be carrying ipads 
with them these days with potentially sensitive information on them.

I would appreciate any thoughts on this issue.

http://ipadlawyer.co.uk/when-is-encryption-not-encryption
http://www.zdziarski.com/blog/?p=513
http://anthonyvance.com/blog/forensics/ios4_data_protection/
http://www.zdziarski.com/blog/?p=516
http://www.networkworld.com/community/node/72955


Thanks.
Jason Youngquist, CISSP
Information Technology Security Engineer
Technology Services
Columbia College
1001 Rogers Street, Columbia, MO  65216
(573) 875-7334
jryoungquist () ccis edu<mailto:jryoungquist () ccis edu>


Current thread: