Look Ma, no data center

by Volker Weber

I have heard this Microsoft "push mail"* story often enough now. "You don't need to send your mails through an intermediary server." Of course you do. Your server is on a private network (at least I hope it is) and your handheld is on the operator's private network. If they want to talk to each other, they need somebody to call. The difference is: With a Blackberry, RIM operates this data center. With MS "push mail", your admins do it. They host a frontend server in your DMZ, and this server must be able to talk to your private net. Two questions:

  1. Do you allow a publicly accessible server in your DMZ to talk to your private network?
  2. Do you trust your administrators to secure a server more than you trust RIM's?

If you can answer both questions with "yes", you may consider Exchange "push mail". And you can do this of course if you are just running your Exchange server with direct access from the Internet.

*) I call it "push mail" instead of push mail, since the handheld polls your server for mail. At least every 20 minutes. And when it gets a new IP. And when it loses the connection.

Comments

Well, it is not just about whether you trust your own admins more than RIMs. Most german enterprises have banned (or are about to ban) Blackberrys because they cannot control who accesses RIMs data centers. Just to mention the NSA, who does not only terror defense but a lot of other "research work" which might help to put the US industry into a front position in some cases.
Another side of this story is of course control of data flow in the operators networks - the same issue might occur here.
If you want to secure data - keep it in your brains.

Axel Koerv, 2006-08-23 11:00

1. yes. That's basic setup for 2tier apps, e.g. webserver in DMZ, database server internal, firewall in between. Even the Onebridge/ExtendedSystems/iAnywhere solution works that way.

2. of course! (I'm the admin :-)

Most german enterprises have banned (or are about to ban)

Axel, that is a pretty bold claim. Can I have some numbers? Frankly, I find this hard to believe just by sampling the queue when boarding an aircraft. I know all the FUD around RIM's infrastructure. But all the research I have seen so far has proven it as what it is: Unsubstantiated FUD.

See the url for something I wouldn't consider FUD.

If they use ImageMagick, they are by definition insecure.

And the answer to question 2) is yes by all means.
The answer to question 1) depends. I like to keep all email in the internal network and block any kind of forwarding, web-access and so on except for VPN for some trusted users.

But if there was strong demand for push mail, opening port 443 to the mobile network and establishing a stronger password policy for all users that use those Exchange-features like DirectPush, OWA and HTTPS-RPC would be the way to go.

Sad there's no way to block keyboard-logging internet cafes and other nightmares

RIM is Canadain company no a US company... We don't have the NSA or anything like it

Post a comment











Shall I remember this for you?




Use your full name and a working email address. Unless you want your comment to be removed. No kidding.



Recent comments

Volker Weber on Everybody's PIN Number: Revealed! at 22:00
Chris Linfoot on Everybody's PIN Number: Revealed! at 21:57
Jan-Piet Mens on Everybody's PIN Number: Revealed! at 21:39
Marco Klop on Synchronizing iPhone with ... Lotus Notes at 18:55
sunny gerscky on Pwnage 2.0 released at 16:00
Tobias Lange on Remember, it's always the cable at 13:16
Volker Weber on Remember, it's always the cable at 12:21
Ian White on Remember, it's always the cable at 11:56
Andy Brunner on Remember, it's always the cable at 11:37
Ben Rose on Remember, it's always the cable at 11:33
Ben Poole on It has only been less than two hours at 09:44
Frank L. Quednau on It has only been less than two hours at 09:29
Martin Hiegl on It has only been less than two hours at 08:27
Stephan H. Wissel on Notes.ini parameter RunFaster=1 is finally here at 05:24
Volker Weber on It has only been less than two hours at 01:33
Thomas "Duffbert" Duff on It has only been less than two hours at 01:26
Chris Linfoot on Planet Lotus not picking up Christopher's feed at 21:56
Yancy Lent on Planet Lotus not picking up Christopher's feed at 19:48
Bruce Elgort on Robin Bloor: Why Google Chrome Will Dominate at 18:51
Mac Guidera on Planet Lotus not picking up Christopher's feed at 16:04
Kevan Emmott on 824 Chrome users so far today at 15:56
Chris Linfoot on Planet Lotus not picking up Christopher's feed at 14:54
Lars Berntrop-Bos on Planet Lotus not picking up Christopher's feed at 13:12
Andreas Braukmann on 824 Chrome users so far today at 11:33
Nick Daisley on Robin Bloor: Why Google Chrome Will Dominate at 10:14

Ceci n'est pas un blog

vowe.net is a personal website published by Volker Weber a.k.a. vowe. I am an author, consultant and systems architect based in Darmstadt, Germany.

rss Click here to subscribe

Hello

About me
Contact
Publications
Certificates
Frequently asked questions

Twitter Updates

More >

Poll

Can you bring a camera phone to work?

Getting poll results. Please wait...

Local time is 22:25

visitors.gif
160 visitors online

News

Other sources of news, imported into my own format to make them more accessible:

Heise Online
Schlagzeilen
Weather

Archives

As most of my articles roll off the front page rather quickly, I am making an archive of previous posts available here. You can also use the handy search box at the top of the page if you are looking for something particular.

Last 30 days
More archives

Got the T-shirt?

Got the T-shirt?
Are you buying from the US?

Systems Architecture

This site runs on an Apache web server on top of the Linux operating system. The content is managed with MovableType which is implemented in Perl. Last but not least the HTML code your browser sees is put together with PHP.

© 1992-2008 Volker Weber.
All Rights Reserved.

Impressum