this post was submitted on 22 Jan 2024
666 points (94.6% liked)
People Twitter
5283 readers
984 users here now
People tweeting stuff. We allow tweets from anyone.
RULES:
- Mark NSFW content.
- No doxxing people.
- Must be a tweet or similar
- No bullying or international politcs
- Be excellent to each other.
founded 1 year ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
It depends how the MDM is implemented. If it allows locking and wiping the entire device, no. If it makes a sandbox for the work stuff, and it only grant them access to control, lock and wipe that sandbox then I don't mind.
That's what we do for personal devices, corporate devices are fully managed/supervised.
Yeah my work MDM is setup this way with Android Enterprise. Everything work-related is isolated to that area and there is no other access to the full device. I can even have all those apps shut off after-hours or when on vacation so I don't get notifications during personal time. My boss knows to text/call me if there is something urgent that comes up.
Software is imperfect and you shouldn't trust that future updates will not add that ability.
Typically, the app needs to ask for permissions like that, though. On Android, they need to ask to become a "Device admin", and they need to specify what specifically they'll use that access for. I imagine (though I'm unsure since it's never happened to me) they need to ask to update those permissions if they want their uses to change.
Agreed, but its not perfect. I recall but couldn't recover a link to a story about some application bypassing android or iPhone permissions.
Another big recent flaw allowed apps without the permission to draw over other apps.
https://blog.checkpoint.com/research/android-permission-security-flaw/
Yeah I don't care about having a work profile.
Also there are cross the wall permissions in the special permissions in the settings in Android