Home > Ask the Security Experts > Application Security Questions & Answers > Is the iPhone amenable to any method of email encryption?
Ask The Security Expert: Questions & Answers
EMAIL THIS

Is the iPhone amenable to any method of email encryption?

Michael Cobb, featured expert EXPERT RESPONSE FROM: Michael Cobb, featured expert

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 15 August 2008
Is the iPhone amenable to any method of email encryption? If not, what secure email features are present or in the works?

>
The iPhone: good looks, cool features and now, with the launch of the latest version, it's even affordable. No wonder everybody wants one. Everyone, that is, apart from network and security managers. They're the ones tasked with trying to ensure security policies covering data loss and inappropriate use of devices aren't blown away by employees who see smartphones as a fashion accessory more than a networked communications device.

A lot of criticism from IT security professionals about the iPhone's lack of security stemmed from the device's readiness to let users connect to any nearby open access point. Combine this with a lack of tools to encrypt data on its hard drive, or to wipe it if it's lost or stolen, and you can see why the BlackBerry has been favored at the enterprise level.

When it comes to sending and receiving email, though, the iPhone offers some security. By default, the iPhone uses Secure Sockets Layer (SSL) encryption for POP, IMAP and SMTP, using the mail server's digital certificate to create an encrypted connection. To take advantage of the feature, though, one needs an account with a service that provides SSL-protected email accounts, such as AOL, Yahoo!, Gmail and .Mac. Another option is to switch to webmail and access email via a browser. Not every ISP, however, offers SSL-protected webmail access.

Even though version 2.0 of the iPhone software supports the 802.1x authentication protocol (WPA2 Enterprise), this only encrypts the connection between the iPhone and the Wi-Fi gateway. One way around the limited encryption is to connect to a public Wi-Fi network using a virtual private network (VPN). Doing so creates an encrypted tunnel -- something I'd recommend for any mobile worker. A VPN encrypts all data right through the gateway, all the way to a network endpoint. The iPhone now supports three types of VPN connections: L2TP, PPTP and IPsec. You can find several services that provide a VPN for a fee, such as WiTopia.net. One note of caution, though: VPN profile information stored on an iPhone isn't encrypted and can contain a VPN shared secret stored in the clear. Another drawback when using a VPN with the iPhone is that whenever a network transition occurs, the VPN must be restarted manually.

So far we've looked at protecting emails in transit, but if a message's contents are sensitive, they also need protection while they are stored on an iPhone. There still appears to be no file encryption capabilities on the new device. Many are confused over what is actually encrypted when syncing with ActiveSync, Microsoft's synchronization tool. Thankfully, the new iPhone can now securely wipe data from the device via the optional "Secure Empty Trash" setting, which also allows a remote wipe should the device be lost.

Security is difficult to make look cool, but the iPhone 2.0 software does offer some security improvements. If it really wants to displace the BlackBerry, then I'm sure Apple will soon add more security features. If the iPhone can match the BlackBerry for security, then its compatibility with ActiveSync may give it an edge. Although delivering email directly from an Exchange email server to an iPhone means opening up a network firewall, it also means that they aren't being routed through a network operations center's (NOC) servers, such as Research in Motion Ltd.'s NOC in Canada, which can be a single point of failure, as evidenced by the massive BlackBerry email outage in April 2007 and another outage in February 2008.

More information:

  • Ed Skoudis reviews how to maintain iPhone security in the enterprise.
  • Has the mobile malware threat been overblown?


  • BROWSE BY TAG
    Application Security,   Wireless Network Security: Setup and Tools,   Handheld and Mobile Device Security Best Practices,   Enterprise Network Security,   Application and Platform Security,   Email Protection,   Email Security Guidelines, Encryption and Appliances,   Smartphone and PDA Viruses and Threats,   VIEW ALL TAGS

    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



    RELATED CONTENT
    Application Security
    Do Facebook URL security concerns justify blocking social networks?
    Is there a way to block iPhone widgets that bypass Web filters?
    Should enterprises be concerned with Twitter in the workplace?
    Are there still Google Desktop security problems?
    Can an IP spoofing tool be used to spam SPF servers?
    Will an application usage policy best control network bandwidth?
    How can URL-shortening services be manipulated?
    Is my security program ready for Web application firewall deployment?
    How to ensure the security of a shopping cart application
    When to use the service features of the Metasploit hacking tool

    Handheld and Mobile Device Security Best Practices
    Screencast: Find rogue wireless acess points with Vistumbler
    Secure your remote users in 2010
    Researchers find thousands of flawed embedded devices
    Best Mobile Data Security Products
    Should Windows Mobile updates come from Microsoft?
    MMS messaging spoof hack could have global ramifications
    How to prevent mobile phone spying
    Unified communications: Securing a converged infrastructure
    RIM patches serious BlackBerry Attachment Service flaws
    How secure are iPhone App Store mobile applications?
    Handheld and Mobile Device Security Best Practices Research

    Email Security Guidelines, Encryption and Appliances
    How to confirm the receipt of an email with security protocols
    Best Email Security Products
    Can an IP spoofing tool be used to spam SPF servers?
    WatchGuard acquires email and Web security vendor BorderWare
    McAfee to acquire email SaaS vendor MX Logic
    What does 'invoked by uid 78' mean?
    How to configure firewall ports for webmail system implementation
    Fierce competition prompted new Cisco email security options
    Cisco brings email security appliances closer to SaaS
    Cisco offers more email security choices, but lacks vision

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    asymmetric cryptography  (SearchSecurity.com)
    challenge-response system  (SearchSecurity.com)
    cryptographic checksum  (SearchSecurity.com)
    data encryption/decryption IC  (SearchSecurity.com)
    elliptical curve cryptography  (SearchSecurity.com)
    Escrowed Encryption Standard  (SearchSecurity.com)
    MPPE  (SearchSecurity.com)
    Quiz: Cryptography  (SearchSecurity.com)
    session key  (SearchSecurity.com)
    Twofish  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice



    Find Security Solutions for Your Business
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts