MDM mayhem? New privacy fears raised over BYOD management

Using phone on train

Mobile device management (MDM) is, of course, a vital part of many organisation's security strategy with the rise of BYOD, but there's a flipside to this software with new research pointing to just how intrusive MDM can be when it comes to riding roughshod over employees' privacy.

This is according to Bitglass, a data protection outfit which carried out an experiment entitled 'MDMayhem' whereby it tracked the mobile devices of several volunteer employees using MDM software in a bid to see how far they could push in terms of compromising user privacy.

Bitglass notes that the MDM software was configured to install a security certificate to the devices and all traffic was routed through a corporate VPN, meaning the researchers could decrypt SSL traffic. This is a common setup with MDM to allow for the likes of sniffing out malware and similar dangers.

Privacy? Don't bank on it

The guinea pig users were tracked with this setup for a week, and the Bitglass researchers were able to view the staff members' personal email inboxes, social media accounts, and even username and password details used to login to sensitive accounts such as online banking. These login details were sent through the company network in plain text, too.

The software also allowed for the perusal of browsing history (and things like product searches on Amazon) alongside search queries, with the latter involving some health-based searches, another telling privacy infringement.

The researchers also said that communications sent by third-party apps could be intercepted, even on iOS where app sandboxing should theoretically help to protect privacy. Bitglass said it was able to read personal messages sent via Gmail and Messenger on iOS.

Furthermore, the MDM software could forcibly turn on GPS with a mobile device, without the user's knowledge, enabling the tracking of the employee's movements, not just inside but also outside of work time.

All this adds up to a very concerning level of privacy infringement. As Bitglass observes: "Without a security solution that respects user privacy, employees will simply work around IT." And in that case, nobody wins.

Via: Betanews

Darren is a freelancer writing news and features for TechRadar (and occasionally T3) across a broad range of computing topics including CPUs, GPUs, various other hardware, VPNs, antivirus and more. He has written about tech for the best part of three decades, and writes books in his spare time (his debut novel - 'I Know What You Did Last Supper' - was published by Hachette UK in 2013).

Latest in Security
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Data leak
A major Keenetic router data leak could put a million households at risk
Code Skull
Interpol operation arrests 300 suspects linked to African cybercrime rings
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Multiple routers hit by new critical severity remote command injection vulnerability, with no fix in sight
Code Skull
This dangerous new ransomware is hitting Windows, ARM, ESXi systems
An abstract image of a lock against a digital background, denoting cybersecurity.
Critical security flaw in Next.js could spell big trouble for JavaScript users
Latest in News
DeepSeek
Deepseek’s new AI is smarter, faster, cheaper, and a real rival to OpenAI's models
Open AI
OpenAI unveiled image generation for 4o – here's everything you need to know about the ChatGPT upgrade
Apple WWDC 2025 announced
Apple just announced WWDC 2025 starts on June 9, and we'll all be watching the opening event
Hornet swings their weapon in mid air
Hollow Knight: Silksong gets new Steam metadata changes, convincing everyone and their mother that the game is finally releasing this year
OpenAI logo
OpenAI just launched a free ChatGPT bible that will help you master the AI chatbot and Sora
An aerial view of an Instavolt Superhub for charging electric vehicles
Forget gas stations – EV charging Superhubs are using solar power to solve the most annoying thing about electric motoring