Educause Security Discussion mailing list archives
Re: ipads/iphones and full disk encryption
From: David Seidl <dseidl () ND EDU>
Date: Wed, 12 Oct 2011 11:27:10 -0400
Jason, There are a couple of forensic products that can pretty easily crack iPad/iPhone encryption, and I use those as my benchmark for ease of cracking. Given those, you're right. I tend to explain it to our users in much the same way we do locks on filing cabinets: they don't keep people who really want in out, but it does mean that casual theft of data is less likely to happen. In most cases when we see a phone or device lost or stolen, it's wiped and sold, rather than having its data harvested. That may change, and isn't guaranteed to be the case, but it is what I've seen most often. If you can pair a chance of remote wipe succeeding with encryption on by default that makes it more difficult for casual data access, you're not in an ideal circumstance, but you're better off than without either. Limiting data available on the device, and having a process that you communicate broadly and actively to your campus for handling lost or stolen devices and attached accounts and cloud services also helps. David David Seidl, CISSP, GCIH Director of Information Security Office of Information Technologies University of Notre Dame Notre Dame, IN 46556 (574) 631-7305 dseidl () nd edu<mailto:dseidl () nd edu> From: The EDUCAUSE Security Constituent Group Listserv [mailto:SECURITY () LISTSERV EDUCAUSE EDU] On Behalf Of Youngquist, Jason R. Sent: Wednesday, October 12, 2011 10:44 AM To: SECURITY () LISTSERV EDUCAUSE EDU Subject: [SECURITY] ipads/iphones and full disk encryption As many of you know, ipads/iphones and other devices are being introduced into the corporate and educational institution environment. Currently we require all institutional owned laptops to be encrypted using full disk encryption. The Apple ipad/iphone supposedly has "full disk encryption" but I've done a bit of googling and it appears that the encryption is really all that it is cracked up to be (see reference URLs below). So, I'm wondering how other organizations are addressing this threat - specifically since a number of high-level folks seem to be carrying ipads with them these days with potentially sensitive information on them. I would appreciate any thoughts on this issue. http://ipadlawyer.co.uk/when-is-encryption-not-encryption http://www.zdziarski.com/blog/?p=513 http://anthonyvance.com/blog/forensics/ios4_data_protection/ http://www.zdziarski.com/blog/?p=516 http://www.networkworld.com/community/node/72955 Thanks. Jason Youngquist, CISSP Information Technology Security Engineer Technology Services Columbia College 1001 Rogers Street, Columbia, MO 65216 (573) 875-7334 jryoungquist () ccis edu<mailto:jryoungquist () ccis edu>
Current thread:
- ipads/iphones and full disk encryption Youngquist, Jason R. (Oct 12)
- Re: ipads/iphones and full disk encryption David Seidl (Oct 12)
- Re: ipads/iphones and full disk encryption Tim Doty (Oct 12)
- Re: ipads/iphones and full disk encryption Gary Flynn (Oct 12)
- Re: ipads/iphones and full disk encryption Tim Doty (Oct 12)
- Re: ipads/iphones and full disk encryption Gary Flynn (Oct 12)
