Author Topic: Aquamail bypasses PIN/wipe security policy?  (Read 4708 times)

Friedrich_NL

  • Newbie
  • *
  • Posts: 2
Aquamail bypasses PIN/wipe security policy?
« on: August 08, 2014, 12:46:29 pm »
Hi, like the app a lot.

A bit concerned though about phone security. When I've tried other mail apps the Exchange Server imposes the dreaded PIN+wipe, not so Aquamail.

Searched the web for answers on wether ActiveSync is different than Exchange Web Services (that AquaMail uses) in this respect, no luck.

E.g. tried MailWise - PIN is enforced on my current Exchange server, but not on my former employer's. Here it seems the former has a security hole.
Using AquaMail on my current server, no security is enforced (and of course not on the old one either).

Hope to hear from you soon.

/ Friedrich

Kostya Vasilyev

  • Hero Member
  • *****
  • Posts: 12740
Re: Aquamail bypasses PIN/wipe security policy?
« Reply #1 on: August 08, 2014, 03:16:05 pm »
It's true.

I never bother to implement this, since most users find this annoying.

Still, I don't understand what sort of "security hole" you're talking about.

You're describing this from the employee's point of view, not the employer, right?

If you wish to use a more secure device unlock method -- there is nothing preventing you from doing so.

If you wish to use storage encryption -- there is nothing preventing you from doing so.

If you wish to use Aqua's own PIN lock feature -- there is nothing preventing you from doing so.
Creating debug logs for diagnostics: https://www.aqua-mail.com/troubleshooting/

The official FAQ: https://www.aqua-mail.com/faq/

Лог-файлы для диагностики: https://www.aqua-mail.com/ru/troubleshooting/

Вопросы и ответы: https://www.aqua-mail.com/ru/faq/

Friedrich_NL

  • Newbie
  • *
  • Posts: 2
Re: Aquamail bypasses PIN/wipe security policy?
« Reply #2 on: August 08, 2014, 04:01:48 pm »
OK, so you (the developer) can opt out of implementing these security features. I thought they were imposed from the Exchange Server.

That means you're not bypassing, just not implementing. So, I'll ask my current employer if this is OK.

As for the 'security hole', I mean my former employer didn't even force security settings in the first place. They have no written instruction to do this manually either.

So, depending on my employer's security policy I'll keep or uninstall Aquamail.

Great work!

/ Friedrich

Kostya Vasilyev

  • Hero Member
  • *****
  • Posts: 12740
Re: Aquamail bypasses PIN/wipe security policy?
« Reply #3 on: August 08, 2014, 11:58:36 pm »
Yes, ultimately this comes down to corporate security policies.

And from my side -- on whether I'd want to get Aqua officially "Certified for Exchange", which I don't, for various reasons.
Creating debug logs for diagnostics: https://www.aqua-mail.com/troubleshooting/

The official FAQ: https://www.aqua-mail.com/faq/

Лог-файлы для диагностики: https://www.aqua-mail.com/ru/troubleshooting/

Вопросы и ответы: https://www.aqua-mail.com/ru/faq/