Microsoft push email security questioned
By Guy Matthews,
A report attacking Microsoft for a lack of security in its mobile push email platform may be unfairly critical, says a UK analyst.
US-based analyst Jack Gold of J. Gold Associates published a report last week which faults Microsoft for the way it implements the push function in its Windows Mobile 5 operating system.
The report, called Microsoft's Direct Push Insecurity, alleges insecurities in the recently upgraded mobile messaging software. The 'flaws' specifically identified in the report relate to the code which updates data wirelessly between Microsoft Exchange and the mobile client. The so-called AirSync code that sits on the client can leave the device's data unencrypted, says Gold.
"The current version of AirSync can only do a file synch of specifically formatted datasets that meet certain Microsoft data requirements," says Gold in the report. "This means that any transfer of data, from Exchange Server to Pocket Outlook, for example, must be done in an unencrypted file state."
Microsoft itself has yet to respond to the criticism, but some analysts are already expressing doubts about how much risk the potential flaw represents.
"I'd say that this is an anomaly that Microsoft needs to address rather than a full blown crisis," says Rob Bamforth of consultancy Quocirca. "Whenever a product gets more complex, then there are bound to be a couple of minor security consequences in the short term. I'd say in general that there's a huge step change in robustness between the old and new versions of Microsoft's mobile platform."
The feedback that Quocirca has been getting from end users on Microsoft and its recent spate of security controversies suggests that the vendor is heading in the right direction, says Bamforth.
"Microsoft has got better at dealing with security issues more quickly," he said. "In any case it's not always easy to pinpoint whether a particular problem is the fault of the wireless technology, the device itself or the transport mechanism. Microsoft's security vulnerabilities are an easy bandwagon to jump on."
You may also like...
Sponsored Links
advertisement
You may also like...
Latest Networking Analysis & Insight
Bring you own device: the $600 question
Inside the enterprise: A recent Cisco report claims bring your own device is gaining support from IT departments. But how much are staff willing to invest in personal technology?
- Interop 2012: Q&A, Saar Gillai, CTO, HP Networking
- Is BT the key to broadband Britain?
- Tencent: the biggest web company you’ve never heard of
- The truth about spam
- Have ISPs finally lost the DEA fight?
- Are you ready to launch IPv6 securely?
- Broadband, pricing and small businesses
- Welcome to the stay-at-home Olympics
- Q&A: Cisco on servers, storage and strategy
Latest Networking Reviews
HP t410 All-in-One Thin Client review: First look
- Swyx SwyxExpress X20 review
- Ipswitch WhatsUp Gold Premium 15
- ForeScout Technologies CounterACT 6.3.4
- ThinPrint Printer Dashboard review: First Look
- TITUS Aware for Microsoft Outlook review
- Windows Phone 7 Mango review: First Look
- Dartware InterMapper review
- Kemp Technologies LoadMaster 3600 review
- Sangfor WANACC M5500 review
advertisement
Most popular
- UK regulator shuts down Angry Birds scam
- Apple iPad 3 vs iPad 2 head-to-head review
- IBM bans use of Siri on iPhones
- Chromebooks: What's gone wrong?
- HP plans massive job cuts
- EMC World 2012: Tucci declares Documentum is here to stay
- Dell EqualLogic PS6100XS review
- Macs and Android under malware threat
- RIM loses its head of sales
- Local fibre broadband needs common standards
Register for IT PRO
You'll get exclusive member benefits including free whitepapers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.





