Jump to content

Recommended Posts

Posted

Hello,

I'm working as a researcher in a hospital, but I'm not handling any critical data.

The hospital may be considered a target for hackers, while I do not believe that there is any reason to target me.

Currently, my Apple computer is not subject to the hospital's MDM, and I wonder about the risk of data loss

if it is included; in particular I fear that hackers may use the feature of the MDM to erase the data remotely.

I'm looking for case reports, papers or news articles helping me to assess the risks of MDM, to compare these

to the pros. I consider myself relatively well-educated in computer security, but I'm not a professional; yet

I believe that I can set up things up correctly myself with the help of expert colleagues.

Hoping for feedback,

Colt

Posted

If the MDM has the capability of wiping devices remotely (which it will), then there's a risk that if someone malicious gains control your data could be wiped. But your backup won't be!

 

If you're dealing with any personal data which the hospital is data controller for (patient or employee), they have a legal responsibility to ensure it is kept secure - which means they need to be able to prove you don't have access to it for longer than you need it. Therefore you could either access it on their systems so that they can revoke access or let you copy it onto a device that they have control of. Most MDMs have the facility to create a partition on a personal device where work data can be stored and stored without needing to wipe the whole machine.

Posted
If the MDM has the capability of wiping devices remotely (which it will), then there's a risk that if someone malicious gains control your data could be wiped. But your backup won't be!

Dear jmak,

Many thanks for the response! Yet, in my understanding, more and more frequently the malware first corrupts the (daily) backup

and only then it erases/corrupts/encrypts the data?!

Kind Regards

Colt

Posted

If you can make a backup of the work data that can't be wiped, then wiping it isn't going to help as much when they're trying to protect data.

 

Who owns the computer? Who owns what's on the computer?

Posted

In my opinion this comes down to who owns the data. If it’s the employer then it’s up to them how it is stored. If that’s on their storage local or cloud or on a laptop. If it is on a laptop then it should be an employer owned laptop.

I’m sure we can all agree storing company data on a laptop with no backup isn’t likely to be a go-er. If you own the data then you can decide and should you wish to not enrol in mdm that’s your prerogative.

Posted

Dear All,

I'm grateful for the responses so far.

But I'm primarily interested in any risk assessment: is there any educated guess whether my fear of loosing the data due to the mdm remote wiping is well-founded? I realize that it's very difficult to predict future risk. But I was hoping that someone may point me to resources where this topic has already been discussed. (I could not find anything in the Apple/Mac support groups.) Or that someone maybe has an idea about measures that may alleviate the risk significantly. Or maybe the conclusion is that it's an elephant in the room, a known issue regarding an upcoming danger of unknown proportions?

Kind Regards

Colt

Posted

Hi Colt.

 

Don't want to derail the thread but are you after this for research purposes or because you've been asked by the hospital's IT department to install the MDM and you aren't happy with it.

 

Whilst there is the threat of someone centrally wiping your device the central IT "should" have much better provision for backup and security than a one man band and you should trust they have this in place.

 

It is there responsibility to make sure this in in place. A centrally managed system is infinitely more secure and stable if looked after properly rather than numerous endpoints managed by the end user. But as you are aware nothing can ever be 100 percent.

 

If you have some of your own documents you wish to backup separately then do so but it shouldn't be you to worry about the backup and security strategy just to make sure you are doing your own bit as an end user.

Posted
Depends entirely on the people with admin access to the MDM, if they have 2FA and aren't idiots, chance is about 0, if they're average people, chance is higher.
Posted

Dear titch,

I've been asked, but it's also a research question for me. And the legal/organizational background is a bit complicated.

Colleagues who are in a similar situation in nearby hospitals are still allowed to "manage" their computers themselves,

which obviously has its pros and cons.

But I'm feeling specifically uneasy because, as I said, the hospital with all the patient data, etc, is a target for hackers,

while I'm just in an associated research unit, and I believe there is no reason why hackers should target me directly.

It would be collateral damage if I'm hacked because I'm integrated into the hospital's mdm. And there may also be malware

in the supply chain of (mdm) software to the hospital, I guess.

Kind Regards

Colt

Posted

If I found out that personally identifiable data was being allowed to be downloaded to a device not managed by the hospital I would report them to the ICO. There's no way they'd be able to maintain control of the data they're legally responsible for.

 

The only exception would be where they're working with a research organisation or supplier and I would want to see a contract specifying that the supplier is taking similar precautions.

 

Theoretically the hospital could put in place contracts with individuals, but for them to be meaningful they'd have to do a full due diligence assessment on each one and have a way of proving that their access to the data ceased and all copies deleted. The only realistic way to overcome that is with some form of MDM.

 

If you don't want your personal computer managed by the hospital, buy one that you only use for your research project.

 

If you don't trust the hospital to have systems in place to safeguard patient data, get the evidence and report them to the ICO; they have a legal duty to both protect it from unauthorised people accessing it and to ensure that it's always available to ensure patients can be treated safely.

 

Also, if you're worried that your backups are at greater risk of being list than your working copy of your data, you haven't got backups.

 

I've re-read my post and it comes across as quite harsh, but to me this is a very black and white issue. There is no room for compromise with protecting patient data.

Posted

Dear jmak,

Thanks. As I said at the beginning, I'm working as a researcher in a hospital, but I'm not handling any critical data. I should have been be more precise: no patient data except some anonymized aggregated patient data and some anonymized non-aggregated data from a non-patient study. I'm also handling meta-data related to collaborators and such who I'm working with, e.g. email addresses.

Kind Regards

Colt

Posted

I'm interested in the subject area, since I'm looking at a proposal with my employer to implement MDM on BYOD devices. Currently BYOD devices have no access to our organisations data and everyone is provided with the computing resources they need by the organisation. My view at the minute is that it would be of limited value; there are some people who'd like to use their own machine, but I'd expect quite a lot of pushback from people who wouldn't want us to control their machines. Your post pretty much backs up my instinct - although I'd probably need more evidence.

 

I've had a look around (admittedly not exhaustive) and come up with these:

 

https://www.macobserver.com/news/mdm-hack-13-iphones/

 

https://www.bleepingcomputer.com/news/security/hackers-breach-company-s-mdm-server-to-spread-android-malware/

 

https://book.hacktricks.xyz/macos/macos-security-and-privilege-escalation/macos-mdm

 

The first one worked by tricking users into signing up to an MDM server the hackers owned, so they did use the MDM to hack devices, but the MDM itself wasn't hacked.

 

The middle one is the only example I could find of an actual hack. There's not a lot of information about how the MDM server was hacked.

 

The last one is about using an MDM platform to illicitly gain access to a corporate network by enrolling devices that shouldn't be permitted. Is say that's not a vulnerability in the system - it's sloppy procedures and easily mitigated against.

 

Any system can be hacked, but given how widely MDM systems are used, that's a remarkably small haul of examples.

 

If the data you're working with really isn't private, it could just be put on a server with public access. From the point of a network manager it's pretty much equally secure as allowing you to download it.

 

I can't speak for everyone, but on this forum you're essentially asking a bunch of gamekeepers who are professionals at protecting data. I'd be amazed if anyone would let a computer they don't have control over connect to corporate resources. It's not personal - IT departments can't assess individual risk as there's not time or resources. They have to build your systems for worst case scenarios and rules and systems have to apply to everyone.

Posted

Dear jmak,

I deeply appreciate your last post; very helpful. Maybe you or others can add to the list of incidents; please keep me informed.

As an aside, I have no access to the networks of the hospital that are connected to patient data (and I don't want to); I think eduroam

is all I need. However, I need to check all my assumptions, arguments and conclusions soon.

I'm happy about more input, yet I'm very grateful for what I already got.

Colt

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...