1
1

00:00:00,090  -->  00:00:02,190
<v Instructor>Mobile vulnerabilities.</v>
2

2

00:00:02,190  -->  00:00:03,150
In this lesson,
3

3

00:00:03,150  -->  00:00:06,390
we're going to start talking about mobile vulnerabilities.
4

4

00:00:06,390  -->  00:00:08,670
Now, as you look around the workforce these days,
5

5

00:00:08,670  -->  00:00:10,980
you cannot go within a couple of minutes
6

6

00:00:10,980  -->  00:00:13,260
without seeing somebody on their smartphone
7

7

00:00:13,260  -->  00:00:15,750
or on their tablet or on some other kind of mobile device,
8

8

00:00:15,750  -->  00:00:18,060
maybe a smartwatch or something like that.
9

9

00:00:18,060  -->  00:00:20,670
It's just, these devices are everywhere now,
10

10

00:00:20,670  -->  00:00:23,310
and this introduces new threats and vulnerabilities
11

11

00:00:23,310  -->  00:00:25,890
to our networks and our organizations.
12

12

00:00:25,890  -->  00:00:26,910
So in this lesson,
13

13

00:00:26,910  -->  00:00:28,830
we're going to cover three specific areas
14

14

00:00:28,830  -->  00:00:30,810
associated with mobile technology.
15

15

00:00:30,810  -->  00:00:32,730
This includes the bring your own device policies
16

16

00:00:32,730  -->  00:00:34,650
that so many of our companies are using,
17

17

00:00:34,650  -->  00:00:36,690
mobile platform threats and vulnerabilities,
18

18

00:00:36,690  -->  00:00:38,310
and mobile device management
19

19

00:00:38,310  -->  00:00:40,140
and enterprise mobility management.
20

20

00:00:40,140  -->  00:00:42,750
First, let's talk about bring your own device.
21

21

00:00:42,750  -->  00:00:44,700
Now, bring your own device is a policy
22

22

00:00:44,700  -->  00:00:46,170
that allows people to, essentially,
23

23

00:00:46,170  -->  00:00:49,230
bring their own equipment into work and use it.
24

24

00:00:49,230  -->  00:00:51,180
Now, when you talk about bring your own device,
25

25

00:00:51,180  -->  00:00:52,440
it can be something generic,
26

26

00:00:52,440  -->  00:00:55,080
like mice and keyboards and headphones,
27

27

00:00:55,080  -->  00:00:58,170
or something like a laptop or a smartphone or a tablet.
28

28

00:00:58,170  -->  00:00:59,877
It really can be any device.
29

29

00:00:59,877  -->  00:01:01,410
And so it's up to your organization
30

30

00:01:01,410  -->  00:01:03,960
to define your bring your own device policy.
31

31

00:01:03,960  -->  00:01:05,460
In the most general terms,
32

32

00:01:05,460  -->  00:01:08,370
a bring your own device policy, or BYOD,
33

33

00:01:08,370  -->  00:01:11,730
is any security policy set forth by a company
34

34

00:01:11,730  -->  00:01:14,400
that allows employees to use their personal smartphones,
35

35

00:01:14,400  -->  00:01:16,530
laptops and tablets for work
36

36

00:01:16,530  -->  00:01:18,720
or connection to the corporate network.
37

37

00:01:18,720  -->  00:01:21,870
So if I have my laptop, I can bring it to work,
38

38

00:01:21,870  -->  00:01:24,450
plug it into the network and start working on it all day.
39

39

00:01:24,450  -->  00:01:26,190
When I'm done, I can unplug it from the network,
40

40

00:01:26,190  -->  00:01:27,030
and take it home,
41

41

00:01:27,030  -->  00:01:28,500
and then I can plug it into my network at home
42

42

00:01:28,500  -->  00:01:31,980
and use it for personal things or work related things.
43

43

00:01:31,980  -->  00:01:33,150
And that's really the danger
44

44

00:01:33,150  -->  00:01:35,520
when we start talking about bring your own device.
45

45

00:01:35,520  -->  00:01:37,170
Now, when we think about bring your own device,
46

46

00:01:37,170  -->  00:01:39,420
it brings a lot of challenges with us.
47

47

00:01:39,420  -->  00:01:41,550
The first one is deperimeterization.
48

48

00:01:41,550  -->  00:01:43,140
Now, what do I mean by this?
49

49

00:01:43,140  -->  00:01:45,180
Well, when we talk about physical security of our network,
50

50

00:01:45,180  -->  00:01:46,800
we're talking about the perimeter.
51

51

00:01:46,800  -->  00:01:49,620
If my entire network is located within my office building,
52

52

00:01:49,620  -->  00:01:51,420
it's a lot easier for me to protect
53

53

00:01:51,420  -->  00:01:54,510
than if I allow that to go outside my office building.
54

54

00:01:54,510  -->  00:01:56,160
So if you take your laptop
55

55

00:01:56,160  -->  00:01:57,480
and you bring it to work and use it,
56

56

00:01:57,480  -->  00:01:58,680
and then you take it home,
57

57

00:01:58,680  -->  00:02:00,660
well, then we've just expanded the perimeter
58

58

00:02:00,660  -->  00:02:03,540
of the office network to your house as well.
59

59

00:02:03,540  -->  00:02:05,370
Even if we don't do it logically,
60

60

00:02:05,370  -->  00:02:06,660
we have now physically done it
61

61

00:02:06,660  -->  00:02:08,550
because there's documents stored on that device
62

62

00:02:08,550  -->  00:02:09,930
that are now in your home.
63

63

00:02:09,930  -->  00:02:12,210
And so if that laptop gets stolen, that can be a problem,
64

64

00:02:12,210  -->  00:02:14,940
because we don't have the protections in place.
65

65

00:02:14,940  -->  00:02:15,990
Another big issue we have
66

66

00:02:15,990  -->  00:02:18,630
is unpatched and unsecure devices.
67

67

00:02:18,630  -->  00:02:20,550
If you're going to bring your laptop in,
68

68

00:02:20,550  -->  00:02:22,860
I don't know what the quality of that laptop is.
69

69

00:02:22,860  -->  00:02:24,750
I don't know if you've done all your security patches,
70

70

00:02:24,750  -->  00:02:26,130
if you have the latest antivirus,
71

71

00:02:26,130  -->  00:02:28,440
if you have the right security protections in place.
72

72

00:02:28,440  -->  00:02:29,273
All of those are things
73

73

00:02:29,273  -->  00:02:30,540
that you're now bringing into my network.
74

74

00:02:30,540  -->  00:02:31,950
And when you plug into it,
75

75

00:02:31,950  -->  00:02:34,470
you are now bringing those vulnerabilities in with it.
76

76

00:02:34,470  -->  00:02:37,050
And so this is something you have to think about as well.
77

77

00:02:37,050  -->  00:02:38,640
Another concern with bring your own device
78

78

00:02:38,640  -->  00:02:40,530
is strained infrastructure.
79

79

00:02:40,530  -->  00:02:43,020
Now, what I mean by this is that as a company,
80

80

00:02:43,020  -->  00:02:45,450
we're going to build our networks based on the number of users
81

81

00:02:45,450  -->  00:02:47,940
and the number of devices we expect to run on it.
82

82

00:02:47,940  -->  00:02:50,970
And so if I built my company expecting 50 employees
83

83

00:02:50,970  -->  00:02:53,280
and now I have 500 employees,
84

84

00:02:53,280  -->  00:02:54,113
and so we start saying,
85

85

00:02:54,113  -->  00:02:55,410
"Oh, it's okay, just bring your own devices
86

86

00:02:55,410  -->  00:02:57,570
'cause I don't have enough laptops and desktops for you.
87

87

00:02:57,570  -->  00:02:59,070
We'll just put up a wifi access point.
88

88

00:02:59,070  -->  00:03:00,360
You can connect to that."
89

89

00:03:00,360  -->  00:03:02,370
Well, again, that's going to strain the infrastructure
90

90

00:03:02,370  -->  00:03:03,810
because that's not going to be enough
91

91

00:03:03,810  -->  00:03:05,940
to handle the increased load that we're putting on it.
92

92

00:03:05,940  -->  00:03:08,070
So all these extra devices do increase load
93

93

00:03:08,070  -->  00:03:09,090
and it becomes something
94

94

00:03:09,090  -->  00:03:10,860
that can strain your infrastructure.
95

95

00:03:10,860  -->  00:03:13,050
Another thing is forensic complications.
96

96

00:03:13,050  -->  00:03:14,280
If you have a data breach
97

97

00:03:14,280  -->  00:03:16,290
or you suspect that that device was involved
98

98

00:03:16,290  -->  00:03:18,630
with something as part of your instant response,
99

99

00:03:18,630  -->  00:03:20,760
are you going to be able to actually look at that
100

100

00:03:20,760  -->  00:03:22,770
and go through that device?
101

101

00:03:22,770  -->  00:03:24,210
Well, maybe or maybe not,
102

102

00:03:24,210  -->  00:03:26,700
because it's not technically a corporate-owned device.
103

103

00:03:26,700  -->  00:03:28,170
This is somebody's personal device.
104

104

00:03:28,170  -->  00:03:30,360
And so if you want to look at my smartphone,
105

105

00:03:30,360  -->  00:03:31,620
well, you're going to have to get my permission.
106

106

00:03:31,620  -->  00:03:32,760
And if I don't want to give it to you,
107

107

00:03:32,760  -->  00:03:35,430
you can't do the forensic investigation that you want to do.
108

108

00:03:35,430  -->  00:03:37,020
And so this becomes another issue
109

109

00:03:37,020  -->  00:03:38,220
that you have to deal with.
110

110

00:03:38,220  -->  00:03:40,170
And the fifth and final thing we have to think about really
111

111

00:03:40,170  -->  00:03:41,880
with bring your own device is what happens
112

112

00:03:41,880  -->  00:03:44,190
when that device is lost or stolen.
113

113

00:03:44,190  -->  00:03:46,770
Again, this kind of goes back to our deperimeterization.
114

114

00:03:46,770  -->  00:03:49,170
If I take that device out of the office,
115

115

00:03:49,170  -->  00:03:50,397
now I can't protect it as well.
116

116

00:03:50,397  -->  00:03:53,220
And if I leave my smartphone in the back of a taxi cab
117

117

00:03:53,220  -->  00:03:55,620
or somebody steals my laptop from my hotel room,
118

118

00:03:55,620  -->  00:03:57,930
they now have access to all those files
119

119

00:03:57,930  -->  00:03:59,040
that are part of the corporate network
120

120

00:03:59,040  -->  00:04:00,810
that are now stored on my system.
121

121

00:04:00,810  -->  00:04:02,160
And so these are things you have to think about
122

122

00:04:02,160  -->  00:04:03,540
with bring your own device.
123

123

00:04:03,540  -->  00:04:05,190
Now, the next area we want to talk about
124

124

00:04:05,190  -->  00:04:08,610
is specific mobile platform threats and vulnerabilities
125

125

00:04:08,610  -->  00:04:09,930
because there are specific threats
126

126

00:04:09,930  -->  00:04:11,250
and vulnerabilities that are associated
127

127

00:04:11,250  -->  00:04:13,980
with just using certain mobile platforms.
128

128

00:04:13,980  -->  00:04:15,210
Now, most of the time,
129

129

00:04:15,210  -->  00:04:16,500
you're going to be using one of two
130

130

00:04:16,500  -->  00:04:18,240
mobile operating systems these days.
131

131

00:04:18,240  -->  00:04:20,730
It's either going to be Android or iOS.
132

132

00:04:20,730  -->  00:04:23,190
And so we're going to talk about both of those in this lesson.
133

133

00:04:23,190  -->  00:04:24,420
Now when we talk about Android,
134

134

00:04:24,420  -->  00:04:26,490
this is a Linux-based operating system
135

135

00:04:26,490  -->  00:04:28,080
that is made by Google.
136

136

00:04:28,080  -->  00:04:30,480
Now, the great thing about Android is it's open source,
137

137

00:04:30,480  -->  00:04:33,150
so it's really easy for cell phone manufacturers
138

138

00:04:33,150  -->  00:04:33,983
to be able to use it,
139

139

00:04:33,983  -->  00:04:36,450
and they don't have to pay a licensing fee back to Google.
140

140

00:04:36,450  -->  00:04:38,670
So this is something that is very attractive
141

141

00:04:38,670  -->  00:04:41,190
and it makes it so it's very widely accepted.
142

142

00:04:41,190  -->  00:04:44,280
Because of this, Android has the largest market share.
143

143

00:04:44,280  -->  00:04:46,710
There are the most amount of devices out there
144

144

00:04:46,710  -->  00:04:47,880
with Android on it.
145

145

00:04:47,880  -->  00:04:51,030
And because Android is so popular across the world,
146

146

00:04:51,030  -->  00:04:53,820
there's also a larger number of older devices out there,
147

147

00:04:53,820  -->  00:04:55,590
because a lot of people will get a device
148

148

00:04:55,590  -->  00:04:57,390
that might be two or three or four years old
149

149

00:04:57,390  -->  00:04:59,010
and they'll still be using it.
150

150

00:04:59,010  -->  00:05:00,390
Now there's no more software updates
151

151

00:05:00,390  -->  00:05:01,500
or security patches for it,
152

152

00:05:01,500  -->  00:05:04,080
but those older devices are still out there.
153

153

00:05:04,080  -->  00:05:05,490
Now, one of the great things about Android
154

154

00:05:05,490  -->  00:05:08,010
is it's open nature of the operating system.
155

155

00:05:08,010  -->  00:05:09,360
One of the bad things about it is
156

156

00:05:09,360  -->  00:05:11,520
it's open nature of the operating system.
157

157

00:05:11,520  -->  00:05:13,590
A lot of people like the fact that it's open source
158

158

00:05:13,590  -->  00:05:15,270
and that anyone can build for it,
159

159

00:05:15,270  -->  00:05:16,830
but that also brings the vulnerabilities
160

160

00:05:16,830  -->  00:05:18,270
that anyone can build for it,
161

161

00:05:18,270  -->  00:05:20,490
including people who make malware.
162

162

00:05:20,490  -->  00:05:21,810
Now, another issue that we have
163

163

00:05:21,810  -->  00:05:23,250
is that there is a large usage
164

164

00:05:23,250  -->  00:05:25,470
of third party apps on Android.
165

165

00:05:25,470  -->  00:05:28,290
Now, unlike iOS devices made by Apple,
166

166

00:05:28,290  -->  00:05:31,530
you can actually run third party apps on an Android device.
167

167

00:05:31,530  -->  00:05:32,730
You don't have to install apps
168

168

00:05:32,730  -->  00:05:34,500
just through Google store,
169

169

00:05:34,500  -->  00:05:35,520
the Play Store.
170

170

00:05:35,520  -->  00:05:37,350
Instead, you can download any file you want
171

171

00:05:37,350  -->  00:05:39,420
from the internet and you can run that on your device.
172

172

00:05:39,420  -->  00:05:40,680
That gives you a lot of freedom,
173

173

00:05:40,680  -->  00:05:43,590
but it also gives you an exposure to a lot of malware.
174

174

00:05:43,590  -->  00:05:45,570
So it's something you have to consider.
175

175

00:05:45,570  -->  00:05:47,880
Now, on the other side, we have the Apple devices.
176

176

00:05:47,880  -->  00:05:50,760
And if you're running iOS, you're running this on an iPhone.
177

177

00:05:50,760  -->  00:05:52,830
In fact, it's the only place you can run iOS,
178

178

00:05:52,830  -->  00:05:55,410
because iOS is a closed operating system.
179

179

00:05:55,410  -->  00:05:58,170
It's made by Apple and it has to be run on iPhones.
180

180

00:05:58,170  -->  00:06:00,690
They will not allow you to run it on any other device.
181

181

00:06:00,690  -->  00:06:02,940
So Android can be run on pretty much anything,
182

182

00:06:02,940  -->  00:06:04,980
but iOS has to be on an iPhone.
183

183

00:06:04,980  -->  00:06:06,120
Now, there's a couple of issues
184

184

00:06:06,120  -->  00:06:07,800
when you start dealing with iOS.
185

185

00:06:07,800  -->  00:06:10,890
iOS is kind of the opposite of Android, right?
186

186

00:06:10,890  -->  00:06:13,050
But because it is a closed operating system,
187

187

00:06:13,050  -->  00:06:14,430
a lot of people don't like that.
188

188

00:06:14,430  -->  00:06:15,780
And so they like iOS,
189

189

00:06:15,780  -->  00:06:16,680
but they don't like the fact
190

190

00:06:16,680  -->  00:06:18,240
that they're being told what they can do
191

191

00:06:18,240  -->  00:06:19,080
with their own device.
192

192

00:06:19,080  -->  00:06:21,090
So they do something called jailbreaking.
193

193

00:06:21,090  -->  00:06:22,170
If you're taking your A+,
194

194

00:06:22,170  -->  00:06:23,730
you're familiar with this term.
195

195

00:06:23,730  -->  00:06:25,260
When you jailbreak a device,
196

196

00:06:25,260  -->  00:06:27,870
you essentially are going to remove all of the protections
197

197

00:06:27,870  -->  00:06:30,870
that Apple has for you and all of their restrictions.
198

198

00:06:30,870  -->  00:06:32,130
So jailbreaking devices
199

199

00:06:32,130  -->  00:06:33,570
are actually the largest threat vector
200

200

00:06:33,570  -->  00:06:34,620
that's used by attackers,
201

201

00:06:34,620  -->  00:06:36,480
because if you jailbreak the device,
202

202

00:06:36,480  -->  00:06:38,520
you no longer have the protections and restrictions
203

203

00:06:38,520  -->  00:06:39,870
that Apple gives you,
204

204

00:06:39,870  -->  00:06:42,030
and that makes you more vulnerable to attack.
205

205

00:06:42,030  -->  00:06:43,410
Just because you have an iPhone
206

206

00:06:43,410  -->  00:06:44,700
and you haven't jailbroken it,
207

207

00:06:44,700  -->  00:06:46,170
it doesn't mean you're safe though.
208

208

00:06:46,170  -->  00:06:48,870
There are vulnerabilities associated with Apple devices.
209

209

00:06:48,870  -->  00:06:50,100
In fact, a lot of hackers
210

210

00:06:50,100  -->  00:06:52,590
go after Apple devices exclusively.
211

211

00:06:52,590  -->  00:06:53,423
Why?
212

212

00:06:53,423  -->  00:06:54,900
Because a lot of people who use Apple
213

213

00:06:54,900  -->  00:06:55,980
tend to be more affluent,
214

214

00:06:55,980  -->  00:06:56,813
they have more money,
215

215

00:06:56,813  -->  00:06:58,830
so they're a better target to go after
216

216

00:06:58,830  -->  00:07:00,240
because if you can get into their devices,
217

217

00:07:00,240  -->  00:07:01,470
you can get into their bank accounts
218

218

00:07:01,470  -->  00:07:03,060
and other things like that.
219

219

00:07:03,060  -->  00:07:05,010
In fact, apple has a huge bounty
220

220

00:07:05,010  -->  00:07:07,080
for any zero-day vulnerabilities.
221

221

00:07:07,080  -->  00:07:09,510
If you can find a zero-day vulnerability for Apple,
222

222

00:07:09,510  -->  00:07:11,460
they'll pay you $1 million, right?
223

223

00:07:11,460  -->  00:07:12,293
And so that's something
224

224

00:07:12,293  -->  00:07:13,980
that makes a lot of hackers go after it,
225

225

00:07:13,980  -->  00:07:15,240
because they're trying to find ways
226

226

00:07:15,240  -->  00:07:16,950
into that operating system.
227

227

00:07:16,950  -->  00:07:18,720
Now when it comes to Apple devices,
228

228

00:07:18,720  -->  00:07:20,520
there are some zero-days out there,
229

229

00:07:20,520  -->  00:07:22,680
but generally they cost a lot of money to develop
230

230

00:07:22,680  -->  00:07:26,160
or you can buy them from other hackers for a lot of money.
231

231

00:07:26,160  -->  00:07:27,360
Generally, you're going to find
232

232

00:07:27,360  -->  00:07:28,590
that these zero-day exploits
233

233

00:07:28,590  -->  00:07:30,360
are actually used by nation state actors
234

234

00:07:30,360  -->  00:07:32,640
and APTs, advanced persistent threats,
235

235

00:07:32,640  -->  00:07:34,830
against these high value targets.
236

236

00:07:34,830  -->  00:07:36,330
So when I talk about a high value target,
237

237

00:07:36,330  -->  00:07:38,280
I don't necessarily mean somebody like me.
238

238

00:07:38,280  -->  00:07:39,810
I'm not a high value target,
239

239

00:07:39,810  -->  00:07:42,150
but they did use some of these zero-day exploits
240

240

00:07:42,150  -->  00:07:44,263
against people like Jeff Bezos, the owner of Amazon,
241

241

00:07:44,263  -->  00:07:46,470
to be able to get into his phone
242

242

00:07:46,470  -->  00:07:47,460
and be able to get information
243

243

00:07:47,460  -->  00:07:49,920
and be able to leak it and make him look bad publicly.
244

244

00:07:49,920  -->  00:07:51,960
Also, they might use it to go after government officials
245

245

00:07:51,960  -->  00:07:53,700
if they know they're using an iPhone.
246

246

00:07:53,700  -->  00:07:55,590
And this doesn't just apply to iPhones either.
247

247

00:07:55,590  -->  00:07:57,750
These zero-days could be made for Android,
248

248

00:07:57,750  -->  00:07:59,670
but again, they're different operating systems,
249

249

00:07:59,670  -->  00:08:02,490
so it would have to be a different zero-day exploit.
250

250

00:08:02,490  -->  00:08:03,900
Now the third area of this lesson
251

251

00:08:03,900  -->  00:08:06,180
that we want to talk about is mobile device management
252

252

00:08:06,180  -->  00:08:08,100
and enterprise mobility management.
253

253

00:08:08,100  -->  00:08:10,740
When I talk about MDM or mobile device management,
254

254

00:08:10,740  -->  00:08:13,530
I'm talking about the process and supporting technologies
255

255

00:08:13,530  -->  00:08:14,910
for tracking, controlling,
256

256

00:08:14,910  -->  00:08:17,850
and securing the organization's mobile infrastructure.
257

257

00:08:17,850  -->  00:08:19,230
Essentially, it's a way for us
258

258

00:08:19,230  -->  00:08:21,360
to oversee all these mobile devices,
259

259

00:08:21,360  -->  00:08:22,470
and this works really well
260

260

00:08:22,470  -->  00:08:24,540
when your organization owns the devices
261

261

00:08:24,540  -->  00:08:25,950
and issues them out to employees,
262

262

00:08:25,950  -->  00:08:26,790
because then you can put
263

263

00:08:26,790  -->  00:08:28,590
whatever restrictions you want on 'em,
264

264

00:08:28,590  -->  00:08:30,390
and MDM allows you to do that.
265

265

00:08:30,390  -->  00:08:31,770
Now, if you want to take it a step further,
266

266

00:08:31,770  -->  00:08:33,510
you can use something known as EMM,
267

267

00:08:33,510  -->  00:08:35,790
which is enterprise mobility management.
268

268

00:08:35,790  -->  00:08:37,440
This is a mobile device management suite
269

269

00:08:37,440  -->  00:08:38,790
with broader capabilities.
270

270

00:08:38,790  -->  00:08:39,810
So it can actually do things
271

271

00:08:39,810  -->  00:08:43,020
like identification and application management as well.
272

272

00:08:43,020  -->  00:08:45,330
Now you might hear these terms used interchangeably
273

273

00:08:45,330  -->  00:08:47,700
or a lot of people are still old-fashion
274

274

00:08:47,700  -->  00:08:49,110
and will call it MDM,
275

275

00:08:49,110  -->  00:08:51,900
even when they're talking about something that is EMM.
276

276

00:08:51,900  -->  00:08:53,970
Either way, we're really talking about the same thing here.
277

277

00:08:53,970  -->  00:08:56,490
We're talking about some way to manage and secure
278

278

00:08:56,490  -->  00:08:57,420
and do patch management
279

279

00:08:57,420  -->  00:09:00,780
and all those things we need to do for those mobile devices.
280

280

00:09:00,780  -->  00:09:02,430
Now, as we start talking about the features
281

281

00:09:02,430  -->  00:09:04,500
of these MDM or EMM suites,
282

282

00:09:04,500  -->  00:09:06,120
there are a handful of them.
283

283

00:09:06,120  -->  00:09:07,740
For instance, one of the features is
284

284

00:09:07,740  -->  00:09:10,470
to be able to do device enrollment and authentication.
285

285

00:09:10,470  -->  00:09:13,470
This way we can know exactly who is using that device
286

286

00:09:13,470  -->  00:09:14,580
and who it's been issued to,
287

287

00:09:14,580  -->  00:09:17,340
and basically use it as an asset tracking mechanism.
288

288

00:09:17,340  -->  00:09:20,670
Another thing we can do is remotely lock and wipe devices.
289

289

00:09:20,670  -->  00:09:22,080
So if somebody loses a device,
290

290

00:09:22,080  -->  00:09:24,450
they can call their security team or their help desk
291

291

00:09:24,450  -->  00:09:26,820
and they can actually go in, lock that device,
292

292

00:09:26,820  -->  00:09:30,360
and remotely wipe that data to ensure that it's protected.
293

293

00:09:30,360  -->  00:09:31,620
Another thing we can use these for
294

294

00:09:31,620  -->  00:09:33,510
is to identify device locations.
295

295

00:09:33,510  -->  00:09:36,210
Let's say I lost my phone in the back of a taxi cab.
296

296

00:09:36,210  -->  00:09:38,040
I can call the customer service desk
297

297

00:09:38,040  -->  00:09:39,510
and they can actually look at my phone
298

298

00:09:39,510  -->  00:09:41,077
and its GPS coordinates and say,
299

299

00:09:41,077  -->  00:09:44,010
"Oh, that taxi cab is on the corner of Main and First,
300

300

00:09:44,010  -->  00:09:45,480
you should go there and get it."
301

301

00:09:45,480  -->  00:09:46,560
Another thing you can do
302

302

00:09:46,560  -->  00:09:49,200
is you can do patch and deployment management through these.
303

303

00:09:49,200  -->  00:09:51,090
So if you have a patch or a software update
304

304

00:09:51,090  -->  00:09:52,320
that needs to be pushed out,
305

305

00:09:52,320  -->  00:09:54,300
you can do that through these mobile device management,
306

306

00:09:54,300  -->  00:09:55,380
and that way you can make sure
307

307

00:09:55,380  -->  00:09:57,630
that everybody's got the latest and greatest security
308

308

00:09:57,630  -->  00:09:59,550
to make sure that they are going to be using a device
309

309

00:09:59,550  -->  00:10:00,383
that is secure
310

310

00:10:00,383  -->  00:10:02,670
and keeping your confidential information secure.
311

311

00:10:02,670  -->  00:10:03,810
Another thing we also look at
312

312

00:10:03,810  -->  00:10:06,300
is being able to prevent root or jailbreaks.
313

313

00:10:06,300  -->  00:10:07,133
So as I said,
314

314

00:10:07,133  -->  00:10:08,430
jailbreaking your device is going to remove
315

315

00:10:08,430  -->  00:10:10,020
a lot of the permissions and restrictions
316

316

00:10:10,020  -->  00:10:12,870
that Apple puts on your device if you have an iPhone.
317

317

00:10:12,870  -->  00:10:14,910
Well, that also makes you vulnerable to attack.
318

318

00:10:14,910  -->  00:10:17,790
So as an MDM, we want to make sure that doesn't happen,
319

319

00:10:17,790  -->  00:10:20,340
so we want to make sure jailbreaking is not allowed.
320

320

00:10:20,340  -->  00:10:22,260
Another great thing we could do with this type of software
321

321

00:10:22,260  -->  00:10:25,020
is we can create encrypted containers for data.
322

322

00:10:25,020  -->  00:10:26,310
Now what I mean by this is
323

323

00:10:26,310  -->  00:10:29,100
if I have a device like my iPhone that I have,
324

324

00:10:29,100  -->  00:10:32,490
I can have a particular part of that that is cordoned off
325

325

00:10:32,490  -->  00:10:34,260
and it's a secure container that is created
326

326

00:10:34,260  -->  00:10:36,390
and all the data inside of it is encrypted.
327

327

00:10:36,390  -->  00:10:38,940
So when I'm using that device to play Angry Birds,
328

328

00:10:38,940  -->  00:10:40,620
it's not in that encrypted container,
329

329

00:10:40,620  -->  00:10:42,840
but if I'm going in there and looking at student information
330

330

00:10:42,840  -->  00:10:44,400
that relates to my business,
331

331

00:10:44,400  -->  00:10:46,710
all that information will be in that encrypted container.
332

332

00:10:46,710  -->  00:10:48,000
And again, this is another feature
333

333

00:10:48,000  -->  00:10:49,530
of these mobile device management
334

334

00:10:49,530  -->  00:10:51,960
or enterprise mobility management systems.
335

335

00:10:51,960  -->  00:10:55,320
And finally, we can also restrict features and services.
336

336

00:10:55,320  -->  00:10:57,540
I just said I was playing Angry Birds on my work phone.
337

337

00:10:57,540  -->  00:10:58,980
Do you want me to be able to do that?
338

338

00:10:58,980  -->  00:11:01,087
Well, if not, you can actually turn that off and say,
339

339

00:11:01,087  -->  00:11:03,300
"You're only allowed to have these 10 applications.
340

340

00:11:03,300  -->  00:11:05,790
You can only do these categories of things.
341

341

00:11:05,790  -->  00:11:08,070
You can't do games, but you can do productivity.
342

342

00:11:08,070  -->  00:11:10,650
You can't use VPNs, but you can use this."
343

343

00:11:10,650  -->  00:11:11,700
Those are the things you can do
344

344

00:11:11,700  -->  00:11:13,650
by restricting different features and services
345

345

00:11:13,650  -->  00:11:15,150
within those apps.
346

346

00:11:15,150  -->  00:11:17,310
Now, the final thing you can use MDMs for
347

347

00:11:17,310  -->  00:11:20,730
is to manage incidents and conduct investigations.
348

348

00:11:20,730  -->  00:11:22,500
So if I'm a support technician,
349

349

00:11:22,500  -->  00:11:24,690
I can actually use MDM for that as well,
350

350

00:11:24,690  -->  00:11:26,460
because they have the ability to share your screen
351

351

00:11:26,460  -->  00:11:28,050
so I can remotely see what you're seeing
352

352

00:11:28,050  -->  00:11:30,570
and walk you through those things and help you through that.
353

353

00:11:30,570  -->  00:11:32,940
You learned about that all the way back in A+.
354

354

00:11:32,940  -->  00:11:34,260
Now, if we're doing an investigation,
355

355

00:11:34,260  -->  00:11:36,060
because we have a data breach or something else,
356

356

00:11:36,060  -->  00:11:38,730
we could track that device in every place it's been
357

357

00:11:38,730  -->  00:11:40,800
physically in the world based on its GPS,
358

358

00:11:40,800  -->  00:11:43,290
as well as what it's connected to based on the IP addresses
359

359

00:11:43,290  -->  00:11:44,847
and the different networks it's connected to,
360

360

00:11:44,847  -->  00:11:47,460
and all that can be stored and rolled up and passed to us
361

361

00:11:47,460  -->  00:11:49,380
through those MDM systems.
362

362

00:11:49,380  -->  00:11:50,910
And so we can take all that information
363

363

00:11:50,910  -->  00:11:53,310
into a central database, something like a seam,
364

364

00:11:53,310  -->  00:11:54,270
and be able to use that
365

365

00:11:54,270  -->  00:11:56,643
as part of our larger instant response efforts.
