It may be eventually useful
But that doesn’t make crap smell better
As much as I hate to do this to you…here, go read this: http://www.cio.com/article/2974697/macbook/most-apple-devices-lack-proper-security-for-the-enterprise.html
Sigh.
Sigh.
SIGGGHHHHHHHH
Or, if you prefer it in meme form:
Shit like that usually means you’re too stupid for even hyenas to eat.
Now, if you’re thinking “normally I put the stupid out of my thoughts as fast as possible, but this one does have a familiar flavor”, well, you’re right. It’s by Matt Kapko, CIO.com Senior Writer, who covers social media. And mobile enterprise as well. You’ve seen me talking about his…outflow…before, most notably here:
https://bynkii.tumblr.com/post/175256406870/superannuation-on-display
Yes, that’s the guy who sprayed…that…all over the internet.
Evidently, he covers both social media and enterprise mobile the same way. It seems to involved drinking half a keg of cheap beer, eating a pound of laxatives, then seeing what he can divine from what he finds drying in the sun the next morning.
This post, dear reader(s) is shit. It is pure shit, nigh-perfect shit. It is couched in all the terms designed to get hits, but make no mistake, it is in fact, shit, and it shows that Matt Kapko, and evidently, CIO.com, have in fact gone full klein bottle, and should only be used for lining the bottoms of bird cages. Not birds you like, some of them may be able to read.
Where to start…well, first, he talks about a survey initiated by Centrify. He can’t be arsed to link to it, so I will: It’s here. First of all, what’s the usual conclusion when someone talks about a survey, but doesn’t link to it? If you said “It means they’re pushing an agenda and are probably misstating the data, the interpretation, or both”, well, you’re probably right. Let’s see, hm? According to Matt:
Nearly half of all U.S. employees use at least one Apple device at work, but most of those gadgets lack common security protocols required by many enterprises, according to a new survey commissioned by Centrify, a company that sells enterprise security and management software for Apple products.
(my emphasis added)
According to the survey:
Santa Clara, CA — Centrify Corporation, the leader in securing identities from cyberthreats, today announced findings from a recent survey it commissioned to determine penetration and security compliance of Apple devices in the workplace. Conducted by Dimensional Research, the Centrify Apple survey demonstrates that while people widely use Apple devices for work, lack of security and management of those devices exposes companies to significant liabilities.
(my emphasis added again)
So by the end of his first paragraph, Matt’s already misstated what the survey said. The survey talked about a lack of security and management for those devices. There is a world, a world of difference between that, and Matt’s conclusiong that most Apple “gadgets”, (BY THE WAY…you catch that? Not “devices”, but “gadgets”. “Devices” are serious, “gadgets” are toys. Word choice matters kids, and Unca John catches that shit) lack common security protocols required by many enterprises. Matt’s pretty baldly implying, if not actually stating that you can’t properly configure and secure Apple devices…sorry, gadgets. Not that they aren’t, which is as we’ll see, what the Centrify survey is saying, but that they can’t. Big difference.
Next:
Last month, Centrify asked 1,004 business professionals about how they use computers and smartphones in the workplace. Respondents used a total of 1,309 Apple devices at work, including 191 Macs, 387 iPads and 731 iPhones, according to Centrify. All of the respondents were employed full-time at companies with at least 20 employees, from various industries including healthcare and financial services, according to Centrify
O RLY?
Of the total 2,249 U.S. workers surveyed, nearly half (45 percent) use at least one Apple device for work purposes.
NO! NOT RLY!
Look, when an author can’t be arsed to get basic, trivially verifiable facts contained in a survey correct, one must find not a grain, but a salt asteriod to apply to the rest of their conclusions. But since we’re knee-deep in the effluvia already, (SUNK TIME FALLACY IS NOT ALWAYS BAD) let’s keep wading:
The survey, which was conducted by Dimensional Research, found that 45 percent of respondents use at least one Apple device for work, to access corporate email, documents and business applications. Of those gadgets, 63 percent were employee-owned. More than half, or 51 percent, of all the users’ Apple devices were secured by single-word passwords or numerical PINs, and 58 percent of those devices had no software or policies to enforce the use of stronger passwords. The survey also found that 56 percent of Apple device users shared their passwords with others, and only 17 percent had company-supplied password managers.
Okay, that’s kind of lame, but that has nothing to do with Matt’s implication, that Apple devices lack “common security protocols”. In fact, you can specifically enforce stronger passwords in a variety of ways. From Apple’s Configuration Profile Reference, the “Passcode Policy Payload” section, you can set:
disabling simple passcodes
force the use of a PIN
set the max number of failed login attempts before the device is locked
set the max inactivity period before the device locks
set the passcode age period, aka “you must pick a new passcode every ndays”
Set the minimum number of complex characters a passcode must contain
Set the minimum length of the passcode
Require alphanumeric, not just numeric passcodes
Set the passcode history, up to remembering the last 50 passcodes
Set the max grace period, in minutes a phone can be locked without needing a passcode to unlock
Oh my, it looks like Apple “gadgets” do in fact support the “common security protocols” Matt thinks they don’t. (That is actually a subset of the overall security configuration options, and doesn’t even come close to what you can do on the Mac, but it suffices for our needs here.)
But Matt goes right on taking data that only shows people aren’t securing their devices properly, and using it to support his implication that you can’t:
In addition, only 28 percent of respondents’ Apple devices had company-provided device management solutions, and 35 percent of the people work for companies that enforce data encryption on Apple devices. Almost 60 percent of the Macs represented in the survey were used to access confidential company information, and 65 percent of those systems were used to access sensitive or regulated customer information, according to the survey.
And none of that, none. of. that. is because Apple keeps you from securing their computers and mobile devices. I’m sorry, “gadgets”. That’s people who don’t do it, for whatever the reason, but it’s not because you can’t do it, as implied by the title and Matt’s “common security protocols” nonsense.
Finally:
The results spotlight the high usage rates of unmanaged Apple devices in the workplace, according to Centrify, and they reinforce the risks organizations face when IT professionals don’t have the necessary resources to make sure devices comply with security policies.
And now we have Matt burying his own goddamned thesis. This is not a “can’t” issue, it’s a “don’t” issue, and the reasons behind it are about what we expect from bad CIOs (the kind that seem to love Matt’s sphinctorial musings): they don’t have the resources to manage the devices correctly.
Again, while not good, not Apple’s fault. Matt seems to like to push this kind of bullshit, and yet he keeps dumping it on the internet instead of into a garden. Such a waste.
Now I have one other issue to take here, but with a different author. Dan Moren, writing about this for Six Colors says:
So it’s always wise to ask yourself: where, exactly, do these stories come from?
Nearly half of all U.S. employees use at least one Apple device at work, but most of those gadgets lack common security protocols required by many enterprises, according to a new survey commissioned by Centrify, a company that sells enterprise security and management software for Apple products. [emphasis added]
Shocker.
Dan misses the mark here. Centrify’s survey didn’t say that, and I think he was maybe a bit lazy in not taking the time to actually read the survey. In fact, in the survey page, Centrify directly contradicts Matt’s implication:
“Centrify’s Apple survey spotlights the massive exposures that occur when devices do not comply with standard corporate security policies,” said Bill Man, chief product officer, Centrify. “In particular, customer data represents a huge liability. Disclosure of regulated information such as healthcare records could expose corporations to fines and other legal action. Most importantly, there are solutions on the market today that can handily secure Apple devices without sacrificing user productivity. It’s time for IT to take action.”
My emphasis added.
Centrify is not the one implying you can’t secure Apple devices correctly, that’s Matt’s idiocy. Centrify straight up says you can via a variety of methods, the problem is that people aren’t using existing resources. Dan, unlike Matt, should know better than this, and he knows how to find things like surveys, especially when they’re right there on the Centrify home page (at least that’s where I found it.)
Dan, stop being lazy, you don’t get to get away with that.
This is the second time that Matt Kapko, published by CIO.com has written something about Apple in the enterprise that is completely full of shit, to the point of being farcical, and he misstates a fairly obvious survey to do so.
I can’t think of any good reason to take him, or CIO.com seriously about Apple in the enterprise at this point.











