Canaries in the IT department

by Volker Weber


I used to check MDM policies for very simple signs of things going wrong. Chief among those policies was the camera policy. If you switched that off for "security reasons" just because you could, you were downgrading your user experience without providing security. Well, things have moved on since then, but I have new canaries in the coal mine. For BlackBerry that is Picture Password, for iOS it's TouchID. If you disabled those, please reconsider. Your users hate you. Which means you will lose, eventually.


Hear, hear. If you disable things like Touch ID, you are much likely worsening security a lot, depending on your threats.
If you think, security can be imposed, print this out and stick it to your screen:

Hubert Stettner, 2016-11-16

PS: Why would anybody disable picture password? I can somehow see why somebody would think he needs to disable biometrics in certain (very narrow) scenarios, but picture password? It is better than 'traditional' password entering, as it is a lot more shoulder surfing proof.

Hubert Stettner, 2016-11-16

In my company, TouchID is mandatory. That makes much more sense (I don't know if this can be enforced via MDM, but at least the end user has to sign a paper that he must do so...)

Thomas Muders, 2016-11-16

Hubert, I call distributed intelligence. One brain sets security policies, the other brain imposes them on users. If your login policies requires eight characters with at least one upper case, one number and one special character, you cannot allow any shortcuts, can you?

Thomas, smart company!

Volker Weber, 2016-11-16

Volker, considering the consequences from having to change the password every 60 days according to policy when using biometrics their intentions may have been very intentionally ;-))

Matthias Peplow, 2016-11-19

Why would someone disable TouchID. Is there any reason?

Malte Widenka, 2016-11-19

Well, they do. ;-)

Volker Weber, 2016-11-19

The reason I've heard people suggest disabling TouchID isn't because it isn't secure, but rather because the impact of combining it with other security policies affected operational support. So, say you require some form of complex passcode to unlock the phone (even just 6 numeric digits) AND you require that passcode to be changed every 30 days (ugh). When TouchID was first released, it was pretty easy to go several weeks without having to enter your passcode at all. Users forgot their passcodes. Help Desks went crazy. I'm out of the Ops universe these days, so I don't know if the more frequent passcode prompts Apple inserted in subsequent OS updates made that issue go away. Personally, I'd blame the passcode change policy rather than TouchID for that issue, but ...

Rob McDonagh, 2016-11-20

Rob, exactly. And yes, it is better today. Also, when having a password policy and sensible MDM, ops could always send an unlock, easily. Well.

Hubert Stettner, 2016-11-20

Old archive pages

I explain difficult concepts in simple ways. For free, and for money. Clue procurement and bullshit detection.


Paypal vowe