Tag: iOS

  • Meta Income Down by Half | Will Apple Make it Worse? | Linux Secure Boot Fix

    Meta Income Down by Half | Will Apple Make it Worse? | Linux Secure Boot Fix

    Welcome to The Long View—where we peruse the news of the week and strip it to the essentials. Let’s work out what really matters.

    This week: Meta’s latest results are very bad, Apple wants its cut of Facebook ads, and Lennart Poettering proposes a new Secure Boot for Linux. (more…)

  • Four Secure Coding Best Practices for Mobile Apps

    Four Secure Coding Best Practices for Mobile Apps

    Mobile apps have become the primary point of innovation for many companies, and skilled mobile developers are in high demand. The business asks developers to innovate fast using the latest smartphone features and capabilities to drive high download rates, wow their users, capture customers and grow their business. Dev teams facing constant pressure to move faster may push security to the back burner, focusing on required features and delivery dates the business demands. However, many dev teams have figured out how to innovate faster with security built in by ensuring that devs understand key security requirements and coding best practices. Working with hundreds of development teams on securing thousands of mobile apps, we found four common areas of security failure that can be addressed easily.

    Use SSL via HTTPS

    Mobile app devs may instinctually use Hypertext Transfer Protocol (HTTP) for network communications. However, HTTP puts private user information out in the open for threat actors to intercept. Developers can fix this common mistake by using HTTPS instead, which encrypts data sent to and from servers via industry-standard SSL. Android developers can use the available NetworkSecurityConfig file to set up a predetermined configuration for all network connections made within the app or manually incorporate HTTPS. iOS developers can use App Transport Security (ATS) as the default feature that enforces secure communications in iOS apps and prevents any insecure connections between the mobile app and the server from being completed.

    Validate the Contents of the Certificate

    Certificates add an additional layer of security to HTTPS connections by enforcing additional validations when performing a connection. Certificates include the certificate authority (CA) that signed it and the list of hostnames known or accepted by the application. Apps that validate these components when performing connections with the server significantly reduce the risk of a man-in-the-middle (MITM) attack that can steal credentials and sensitive data.

    To verify a certificate has been issued by a valid CA, Android developers can reference the preconfigured list of CAs included on devices running the mobile operating system. Android developers can implement native classes such as HostnameVerifier to achieve proper hostname verification within their app.

    iOS developers can leverage ATS that provides built-in validation, or use methods in the NSURLSession class to manually code these instead.

    Avoid Hardcoding Resources of a Mobile App

    Attackers often use hardcoded info within the source code of a mobile app to take advantage of users. For instance, attackers can use credentials stored within app files to gain access to a user account. Attackers can also find hardcoded API keys or URLs to gather private data or take over an app entirely. Mobile app developers can prevent these areas from being compromised by not hardcoding keys, passwords and URLs into the source code. Encrypting transport and decrypting data on the backend also adds an extra layer of security.

    Use the Latest Cryptography to Protect Mobile Users

    Outdated cryptography algorithms like SHA-2, RC4 and DES allow attackers to easily break a seemingly secure mobile app. Using older algorithms may also make a mobile app non-compliant with industry regulations leaving an organization at risk of fines or legal jeopardy. Devs can avoid this problem for Android and iOS mobile apps by using the latest cryptography algorithms available, selecting those that are suitable for a specific app scenario. When signing your binary before publishing it to the store, use keys with a length of at least 2048 bits (preferably 4096 bits), and on Android use SecureRandom or SecRandomCopyBytes on iOS when generating random values for cryptographic implementations. Android devs can leverage the Keystore class and iOS devs can leverage Keychain services to store highly sensitive data. Devs should avoid insecure modes of operation, improperly generated cryptographic keys and initialization vectors (IVs) to guarantee that the information that is encrypted cannot be decrypted by a malicious actor.

    Today’s mobile app users need confidence that mobile apps are built with security in mind. While building innovative mobile apps, developers have a responsibility to learn a practical set of secure coding best practices to protect their users (and their businesses).

  • What Should Elon Musk Do? | Passwordless Future: Tense | WebKit iOS Monopoly Ends?

    What Should Elon Musk Do? | Passwordless Future: Tense | WebKit iOS Monopoly Ends?

    Welcome to The Long View—where we peruse the news of the week and strip it to the essentials. Let’s work out what really matters.

    This week: Everyone has Twitter advice for Elon, passwordless vision is vacuous, and Apple prevented from forcing Safari. (more…)

  • CircleCI Adds CI/CD Service for macOS Development

    CircleCI Adds CI/CD Service for macOS Development

    CircleCI today added a dedicated continuous integration/continuous delivery (CI/CD) edition of its namesake platform for developers building applications on the macOS platform.

    Jim Rose, CircleCI CEO, said this offering is aimed at developers that either want dedicated resources to speed up their build processes or have to address compliance and security requirements that prevent them from using shared infrastructure via the existing CircleCI cloud service.

    Most of the developers building applications on macOS platforms are creating applications that will ultimately be deployed on Apple iOS devices, noted Rose. Given the popularity of those devices, the number of organizations using CI/CD platforms to accelerate creation and updates of those applications has increased, Rose added. CircleCI estimated there are now more than 30 million developers building applications on the macOS platform that would benefit from a CI/CD platform running on dedicated bare-metal infrastructure accessed via the Amazon Web Services (AWS) cloud. CircleCI’s dedicated host provides secure access to 50% more cores and more than twice the storage capacity than is available via a CI/CD platform running on top of virtual machines.

    Other capabilities provided by CircleCI include the ability to monitor the performance of apps being developed for multiple platforms in the same pipeline. Many applications deployed on iOS are also deployed on other platforms such as Android, Windows or Linux, noted Rose.

    CircleCI also provides access to testing tools that the company recently added to its portfolio of DevOps tools. Those testing tools are especially critical given the stringent requirements developers face when trying to get approval to make their iOS applications available via the Apple Store, said Rose.

    Developer productivity is, of course, a major issue for organizations trying to strike a balance between automating software development tasks and the art that goes into building applications. While developers appreciate automation, they don’t necessarily want to feel they are working in a factory. Given the demand for their expertise, many developers will simply jump ship when they feel software development processes have become overly onerous. While many managers tend to believe they have a handle on measuring developer productivity, there is often too much focus on, for example, how many lines of code are written versus the business outcomes achieved.

    A recent CircleCI survey also found that more than half (52%) of respondents don’t allow their software developers to choose their own tools. While there is a clear need for a consistent approach to building and deploying applications, organizations will find it challenging to attract and retain the best developers if they don’t allow them to experiment with different tools.

    One way or another, however, the rate at which developers can build and deploy applications is rising as DevOps best practices are adopted. It’s not clear that organizations are going to be able to absorb all that software but, in the wake of the COVID-19 pandemic, the appetite for mobile applications that drive digital business transformation initiatives has never been greater.

  • The State of Commercial and Retail App Testing 2020

    The State of Commercial and Retail App Testing 2020

    When the folks at Testlio approached me to review their “State of App Testing 2020″ report, I had some mixed feelings. These reports can sometimes be too broad; they can say what is not, but not help a team decide where to go. Still, it would only cost me five minutes of my time to see if it was worth writing about, and it came highly recommended, so I took a look. I am glad I did. Today, I’ll analyze the report itself, hit some of the highlights from the survey results and provide some analysis to help you decide if the information is relevant for you—and what you should do about it.

    First of all, the report is short. This is a feature. You won’t have to dig through 68 pages of information—six pages just doesn’t provide an opportunity to provide “fluff.” There are no long opening editorials by someone with an impressive title and list of hypothetical things that survey respondents pick between that will “become important” next year. Instead, Testlio simply anonymized its client information and re-used it to determine averages. This replaces the multiple-choice survey (which was likely filled out by someone abstracted from the work) with the actual data of the work. Testlio knows how often its customers’ applications go to production; it knows the scores of those applications in the Google and Apple stores. From that, the company can draw inferences in the relationship of shipping speed and quality. Finally, the report is grounded in a specific domain—that is, retail and business applications. The distinction between the domains is clear enough that readers won’t walk away trying something that won’t apply to their industry.

    Let’s talk about what the report says.

    In addition to Testlio’s data, the report borrows from other sources to draw a picture. One of the most important observations they made was a connection between quality, speed and customer adoption.

    Quality Matters

    I was amazed to read that 50% of users will not download an application with a 3-star rating, and 85% won’t download one with two stars. That isn’t a huge surprise, as I was recently brought into a project rescue for an application with 2.2 stars (and yes, thousands of ratings) in the Apple store. Trusting that data, that meant the application had less than half the potential users it could have—and the core reason for the app was not to sell a product but instead to promote brand loyalty.

    That data creates a strong argument for an investment in quality in mobile software. Yet, it is also a lagging indicator of quality, the result of poor quality. Put differently, app store reviews are sort of an “aww, shoot” metric. We put the software into the wild and hope it scores well. If the score is good, we have a party. If it is bad, we say “aww, shoot.” Instead of lagging metrics, the result, my interest is in leading metrics, the cause. What actions can we take to improve the scores?

    That’s when things get really interesting.

    Release Speed Matters

    The folks at Testlio grouped mobile applications into two categories: one group that released three times per month and another that released less often. (The average for the study was 2.4 releases per month.) I recently worked with a team that used something like the Scaled Agile Framework (SAFe) to manage deploys about once a quarter, with perhaps a patch in the middle.

    As it turns out, the more frequently released software had higher review scores, about 7% on average. That’s a counterintuitive result worth examining. I am not suggesting you ship twice as often. However, it does make sense that teams that ship more frequently have a small amount of change between releases. That change is likely to be more localized. A large program with teams of teams that tries to integration-test at the end—say the last sprint out of six—is likely to have a lot of uncertainty. The developer who fixes a bug is unlikely to be the one that created it; the “fix” may have unintended consequences that are difficult to test out. At the very least, be very careful about slowing down release schedules in the name of quality, as the results may be lose-lose.

    Let’s move on to device coverage.

    Device Coverage Matters

    Although they have an identical rating system, Testlio found Android OS applications across the board ranked slightly lower than their Apple iOS cousins. That is, the average score for the top 30 commercial and retail apps on iOS is 4.6 and 4.3 on Android. Personally, I think it is fantastic to have these hard numbers at the top of the field rather than opinions from a small group who responded to a survey. The challenge with this data, like the release cadences, is that you have to infer a reason. Testlio proposed three: that acceptance to the Apple Store itself is more difficult (Apple has internal tests); that as a premier brand, Apple has a “halo” effect; and that Android devices are simply too fragmented. With 24,000 different Android devices as of 2015 and too many to count now, it is likely that some older devices have some problems that could not be tested for; thus, a few bad reviews from rare models pulls down the scores.

    One thing Testlio didn’t see shrinking was the size of the test group. The top 30 clients averaged 18 testers per week, and over the time of the survey had at least eight and as many as 38 testers. These would be the people who work on all the different devices checking for compatibility, in addition to doing the human testing that is not, or should not be, automated. What is changing is how those testers are deployed, for more visual inspection, flexing with project needs, instead of a defined group that will be a bottleneck some of the time and over-capacity at others. Personally, I’m a fan of the Agile, whole-team approach, but they make a case for test augmentation with flexibility in the mobile application space, which reminds me of Jon Bach’s chapter in the book, “How To Reduce The Cost of Software Testing.” As an editor on that book, I’ll be the first to admit we picked a terrible title. At the time, we were working through the ideas that would eventually come to be known as Lean Software Testing, which seems to be what Testlio is suggesting.

    App Testing Conclusions

    There’s a fair bit more to the survey, including the amount of device testing occurring, locations for test sourcing worldwide and how distributed testing is working, especially as remote work has become the norm.

    As I said, I was pleased to see some hard data for once, and the challenge will be figuring out what we as an industry can make of it.

    What do you think? Share your thoughts below.

  • Developing Apps for IOS 13: Things to Consider

    Developing Apps for IOS 13: Things to Consider

    Authors of numerous articles and videos have covered all the bells and whistles built into iOS 13, the latest major iteration of Apple’s mobile operating system. Rather than diving into all of these perks, though, I will focus on the changes for app developers.

    As it often happens, Apple introduced many proprietary applications that successfully supersede a number of third-party ones. It’s clear that QuickPath will now replace GBoard to enter text and provide swipe features. Also, the native secondary display feature for iPad called Sidecar will substitute Astropad and Dual Display solutions. Furthermore, custom stickers and animated emoji called Memoji can be used instead of the counterpart from Mirror AI.

    The to-do list application now comes with features that used to be a prerogative of the Things app users: you can set a date, create reminders with subtasks and configure various types of alerts based on location. The overhauled Files app allows users to share folders, connect to cloud services, leverage an archiving tool and do many other awesome things. The syncing of lyrics with Apple Music used to be a matter of installing Musixmatch solution, but iOS 13 has introduced a feature of its own for that purpose.

    There are two main conclusions you can draw from these ongoing tweaks. On the one hand, Apple is trying to hold sway over the ecosystem of the most popular applications. On the other hand, the company is developing a transparent and clear-cut array of services for integration and interoperability. 

    In other words, as long as your application hasn’t been replaced with Apple’s native counterpart, make sure its development occupies a unique niche aligned with the platform’s evolution strategy. Take into account the novelties that change the user experience and require that your coders take extra adaptation efforts.

    Dark Mode

    The 2018 macOS release came with the Dark Mode onboard. Users were expecting a similar feature for iOS back then, but it took Apple’s software engineers more time to implement it for iPhone and iPad. And here we go–Dark Mode is finally available in iOS 13. It functions as part of the Night Shift mode, and therefore the switching takes place automatically.

    It’s beyond all doubt that most users will keep the default iOS settings so that the mode is enabled depending on the time of the day. In the meantime, app developers have to do quite a bit of cumbersome work to support the new feature. They need to create UIs with variable colors while adhering to uniform graphics so people can enjoy using the app at any time with an equal degree of convenience.

    iOS 13 comes with turnkey instruments called Color Assets that minimize the amount of work required for app color theme development. iOS 11 and iOS 12 support this toolkit as well, but app makers relying on design for iOS 10 and earlier will have to stay on the sidelines of this progress.

    Standalone iPadOS

    Apple chose to depart from the general unification trend by segregating two platforms for their mobile devices. This approach gave rise to a separate branch called iPadOS. This is most likely a response to the low demand for the latest powerful iPad Pro models. Many users got the impression that the company actually created a professional, multi-functional gadget but failed to equip it with enough solutions to show its full potential. Neither applications nor compelling use cases were available to bridge the gap. The emergence of iPadOS is intended to change this as the independent, fully-fledged platform should match the hardware power.

    Overall, iPadOS bears a strong resemblance to the desktop operating system. It supports desktop-type scrolling features and the option to work with peripherals such as a mouse and trackpad. The revamped SpringBoard seems to bring some long-forgotten widgets back to the home screen. 

    Now that all of these modifications are in place, every developer should think of the iPad home screen widgets that their users might find handy. Perhaps it makes sense to add a widget rendering certain live information or providing helpful shortcuts.

    When it comes to multitasking, the all-new iPadOS appears to outperform macOS in many ways. For instance, iPad users can open multiple windows of the same app and quickly access favorite apps using the Slide Over feature.

    It means there are new scenarios the developers should consider. Among other things, they have to figure out which apps can be combined with theirs on the same screen; how to implement this without sacrificing the user experience; and what role–main or secondary–their app plays in such a tandem.

    To keep up with the new OS architecture, developers also need to ensure a resilient app layout. Enhanced multitasking means that your app will have to run seamlessly in multiple window sizes and proportions ranging from the traditional Full Screen to a swipeable tab in Slide Over mode. As a matter of fact, a similar interface design was available before; however, whereas it used to be optional, you definitely can’t disregard it anymore.

    Safari has also become a part of the maturity trend. Now it displays desktop site versions rather than mobile ones. The fundamental change, though, is that the browser has been fine-tuned at the engine level so the iPad can work with fully-functional web applications such as WordPress and G Suite. 

    Coders can benefit from this tweak as it poses a great alternative to masterminding an iPad-only application. They can save a good deal of time and money, additionally offering their users a readily available tried-and-tested web app if they have one, of course.

    Last but not least, the new Sidecar mode allows users to cast their Mac’s screen content to the iPad. This feature supports macOS Catalina. Aside from the secondary display perk, Sidecar allows you to use Apple Pencil in Mac apps. That’s one more way of leveraging iPad features without having to create a separate app version, which might make some developers question the need for such extra work.

    Data Rendering

    Dashboards are being definitely implemented in full swing in iOS 13. Lots of Apple’s native apps are using data illustrations on their main screens that reflect the event log, explain how to take advantage of new features and give comprehensive clues about various usage scenarios. This complex approach really differs from the purely functional one that used to be the case.

    The refreshed home page of Apple Maps is a good example of the current trend. It includes new tools to work with geolocation and arrange or add places to favorites. The Health app displays daily infographics, too. These features encourage users to open the application over and over.

    The ubiquity of real-time data and infographics has actually turned into a big trend for all Apple products, including smartphones, tablets, desktop computers and smartwatches. Therefore, if your app generates some potentially interesting or useful information, be sure to demonstrate it to the user. That’s what will fill the app’s dashboard. But first, you should understand what types of data your users prioritize: nifty content or strictly functional stuff.

    Photos

    The updated Photos app is one of the most conspicuous changes brought by iOS 13. You can’t go wrong if you say that creating and editing photos is currently among the main iPhone use cases. Apple developers have rethought the whole process to deliver the best graphics experience.

    The app’s home screen covers all the photo gallery browsing scenarios imaginable. It seems to have been designed specifically for hours of gazing at a time. In addition to the use of machine learning technology for choosing the most captivating images, the photo and video editor boasts amazing visualization of the settings and allows you to view the results immediately in the context of the other content. You can barely notice the process of switching between modes–from browsing to editing and taking photos. All in all, the iOS 13 Photos app exemplifies a mobile solution that surpasses its desktop counterpart in many ways.

    This is a serious challenge for developers because it calls forth a whole new level of coherent user experience in mobile app design. The users will be expecting equally elaborate and smooth apps flawlessly aligned with the rest of the iOS 13 ecosystem.

    Security

    Apple has marketed their operating systems as ultimately safe and privacy-friendly for years, consistently highlighting the leak-proof gist of both iOS and macOS as their competitive advantage. As many of you may know, it is not always the case considering how many new malware pieces target Apple users these days. 

    Trying to be on top of privacy defense, Apple updated the Location Alert feature lets the user know about background applications requesting geolocation data. Although, some programs need these details to operate properly, quite a few app authors keep such data harvesting enabled in the background just in case.

    In iOS 13, this characteristic can become a way to ruin your app’s reputation. As soon as the user gets an alert showing a bunch of points on the map that the application has been recently keeping track of, they are likely to follow the system’s recommendation and block this activity without a second thought.

    This security feature is meant to restrain developers from collecting redundant data that isn’t required for their apps to work properly. It also encourages app makers to notify users when and why they need to know their whereabouts.

    Sign in with Apple

    This feature has been anticipated for quite some time and it finally went live with the release of iOS 13. You can now use your Apple ID to sign into various websites and applications. This functionality secures the authentication routine by means of Face ID or Touch ID. Many developers will find it convenient because it introduces a simple and intuitive authentication workflow eliminating the need to store and manage passwords. The security of this process is now entirely up to Apple.

    Programming with Swift

    Apple has been endorsing the Swift programming language for a while. iOS 13 gave these initiatives a boost by introducing SwiftUI that overhauls the entire paradigm of creating applications for Apple devices. Effectively, it is a critical link between programmers and designers that was missing before. SwiftUI also propels a shift toward a reactive programming style. Apple Developer libraries now support a bevy of UI models. Furthermore, the Combine framework will be henceforth heavily used for coding. These instruments are currently in beta testing and things may change dramatically over time, though.

    Nonetheless, Apple has already provided developer tutorials aimed at facilitating the process of switching to reactive programming. The beta testing will definitely unearth a lot of roadblocks and there will be tons of bug fixes and tool replacements further on. However, Apple engineers will certainly address these issues in the long run.

    It appears that the age of Objective-C with its numerous drawbacks is doomed to fade away, succumbing to more competitive development instruments. 

    SwiftUI already allows programmers to compile applications without high coding proficiency. You can easily add modules that will complement your new app. That being said, designers and managers with entry-level skills will be able to compile prototypes of new software products.

    Overlapping Apps for iOS and macOS

    In the aftermath of the growingly close ties between iOS, macOS and the newly released iPadOS, mobile applications can now run on macOS. You actually couldn’t compile a mobile code using Apple’s desktop operating system till the summer of 2019, but now it’s possible. At the 2019 Apple Worldwide Developers Conference (WWDC 2019), experts claimed this could be done without having to use a simulator.

    However, since the layout structure of iPad applications has more in common with macOS style than the iPhone app layout does, we’re mainly talking about executing iPad apps on desktop machines. Given that some Apple apps look very much alike on different devices (Reminders and Stocks), the proprietor of the platform is expecting the developers of third-party apps to stick with the same uniformity across environments.

    It comes as no surprise that some mobile devices are starting to support desktop mouse and trackpad, and the user interfaces are being unified at the level of the smallest details. For instance, the design of the user icon has been concurrently updated in all the services and applications on iOS, iPadOS, watchOS, and macOS. To maintain the rebuilt environment, Apple is busy expanding the app development sections on their website. The company has provided UI kits even for products in beta testing and created a library of interface icons, lagging slightly behind Android in this regard.

    Summary

    To recap, it’s clear that Apple is trying to establish and push forward a convenient ecosystem for app developers. At the end of the day, this is one of the fundamental elements of a long-term competitive strategy and we may expect more changes with the advent of iOS 14.

    — David Balaban

  • Predictions 2020: The Future of the Mobile Industry

    Predictions 2020: The Future of the Mobile Industry

    The mobile device industry continues to grow in leaps and bounds. Statistics show that, today, over 5 billion people have mobile devices and there are over 9.2 billion mobile connections worldwide. Add to these statistics the fact that the number of consumers who shop and bank online continues to grow as well–presenting hackers with increasing numbers of mobile applications and end-points to target. As developers of software that protect mobile apps from reverse engineering and hacking, at Guardsquare we have a unique purview into the mobility space, and therefore have some pertinent 2020 predictions for the mobile industry.

    Mobile Payments Apps on the Rise

    As consumers’ comfort with, and reliance on, personal technology increases, we expect to see purchases via mobile payment apps grow rapidly throughout 2020. Great news for the global economy, but the downside of this trend is it will serve to exacerbate opportunities for hackers to take advantage of mobile applications and devices that are not properly secured.

    Fake Apps Abound

    Fake apps or hidden apps have historically been a problem and we don’t see that changing any time soon. In December of last year alone, almost 65,000 new fake apps were detected among the various app stores, and we expect this to become increasingly common and problematic. Consumers need to be alert when downloading new apps and developers should be wary that fake apps can negatively affect their own reputation and their company’s. 

    Developers Beware Kotlin’s Hidden Vulnerabilities

    The new development language, Kotlin, is catching on now that it has been designated Google’s preferred language for Android development. However, many developers using the language still do not fully understand security best practices, including how to protect Kotlin code against OWASP’s well-known Mobile Top 10 risks. As with many apps written in Java, apps written using Kotlin must be protected against both static and dynamic attacks using a combination of code hardening and RASP.

    iOS Is Vulnerable Too

    We believe that 2020 will be the year in which awareness increases around the security shortfalls of iOS. Many application developers still believe iOS apps are virtually immune to reverse engineering, but, in reality, all iOS versions have already been jail-broken at some point.  We anticipate developers will take better security measures to ensure the integrity of their apps by employing a multi-layered approach to security to ensure the protection of their iOS applications.

    We continue to see the more sensitive an organization’s data, the more likely it is the mobile app will become a target for hackers. According to OWASP’s Mobile Top 10, reverse-engineering and tampering ranked the eighth and ninth most prevalent mobile security risks. Verizon’s Mobile Security Index 2019 highlights that more than 80% of organizations said they are at risk from mobile security threats, and 69% said those risks increased in the last year.

    It is our hope that, in 2020, all apps—but especially apps housing sensitive customer data—evolve from going unprotected to incorporating key security measures that protect the users and the organizations.

    Want to learn more about what to expect in 2020? Join us Jan. 23 for our Predict 2020 Virtual Summit  featuring discussions from some of the industry’s best and brightest offering up their visions for the future. Sign up today for this free daylong virtual event.

    — Roel Caers

  • DevOps Chat: Managing Apple Devices with Fleetsmith

    DevOps Chat: Managing Apple Devices with Fleetsmith

    Managing Macs, iPhones, iPads and other Apple devices at scale is not something really native to iOS or OSX. Enter Fleetsmith. In sort of a Puppet-meets-Apple environment, the Fleetsmith team automates configuration, management and security of your Apple devices.

    In this DevOps Chat we sit down with Fleetsmith co-founder and CEO Zack Blum and company adviser, Puppet co-founder Luke Kanies, to discuss the mission and challenge in managing Apple devices.

    As usual, the streaming audio is immediately below, followed by the transcript of our conversation.

    Transcript

    Alan Shimel: Hey everyone. Alan Shimel staging-devopsy.kinsta.cloud and we are here for another DevOps Chat. Excuse me. This episode of DevOps Chat features an old friend and a new friend. We have, first of all, cofounder and CEO of Fleetsmith, Zack Blum, who is the new friend. Zack, welcome.

    Zack Blum:  Thanks, so much. Great to be here.

    Shimel: Okay. And then joining Zack is our old friend, Luke Kanies. And Luke really needs no introduction to our audience. Luke is the founder of Puppet.

    Luke Kanies: Famous on the internet.

    Shimel: Famous on the internet, but still puts a token in when he jumps on the subway. But anyway, Luke, welcome.

    Kanies: Thank you very much for having me.

    Shimel: So let’s get this out of the way right away. Luke, what’s your connection to Fleetsmith?

    Kanies: I have been trying to help Zack and his cofounders, trying to tell all the stories of all the ridiculous mistakes that I made in hopes that they make only new mistakes.

    Shimel: Wouldn’t that be a great thing? Man.

    Kanies: We can dream, right? We can dream.

    Shimel: Yeah. I was just going to say, if you can bottle that, man, you really would be famous. So Zack, before we even jump into Fleetsmith, then let – you know, Luke has told us what the connection is. Always interested to hear. How did you hook up with Luke and come about to – I’m going to assume you asked him to an advisor here.

    Blum:  Yeah. Well, it’s funny actually. Even before that, the interesting thing is Puppet itself was the inspiration for us starting Fleetsmith. So the connection goes really far back. I was the IT director at a company called wikia and we had this problem where we needed to manage our device fleet.  So I asked around my peers at IT and security and talked to a guy at Dropbox and asked how they did it internally. And it turns out that they use a bunch of open source tools traditionally used by DevOps pros actually to manage their laptops.

    So I went out and learned all about Puppet and realized, “Oh, my goodness. There is an amazing application opportunity here on the endpoint side.” So long story short, that guy at Dropbox, Jesse Endahl, became our cofounder and CSO; had a product. And Luke and Puppet were a major inspiration. So pretty cool.

    Shimel: Very cool. Very cool. So let’s address Fleetsmith, right? What is it you guys do?

    Blum:  Yeah. Thanks so much for asking. We do a few things. We are a modern Apple device management product. So we help companies manage their corporate Macs, iPhones, iPads, and Apple TVs. And we really try to accomplish four things for our customers. Number one is making on boarding new hires as seamless as possible. So employees ramp right away. We do that by automating new device set up. So straight out of the box, to have a computer set themselves up.

    The second one is we provide fleetwide device intelligence so that IT can see problems before employees get interrupted. We do that with really core reporting on exactly what’s going on out there. The third one is we provide employees with uniform, up-to-date computing environment. We do that through automating OS and third-party app packaging, patching, and the delivery of those as well as config for Wi-Fi printers and other tools.

    And the fourth one, the last one, is we decrease business risk for customers by allowing them to enforce, in an automated way, security best practice so features like disk encryption with automatic key escrow, remote lock and wipe. And so those are the four things we do; really try to help companies of any size, especially small and medium businesses, take those best practices and apply them in an automated way without huge teams and huge _____.

    Shimel: Excellent, man. You know, as crazy as it sounds, I almost feel like you serve an underserved business segment for first trillion dollar company ever, right?

    Blum:  Well, we think you’re right. Yeah unfortunately, too many of the companies that we come across have nothing in place at all; no visibility, no automation around this. Then there are a lot of companies who have something in place and it’s just incredibly tedious to administer. There are so many higher value things that IT and security can focus on than manual packaging of software updates.

    You know, providing great customer service to their employees, helping them do better work. So we are really excited.

    Shimel: You know, but this has always been a – I go back in my years in security. We – the company I helped found, kind of one of the pioneers in what we call the NAC market, the network access control. So it was a little different. As you would log onto a network, we would check your endpoint, whatever that might be, and make sure it conforms to whatever the policy that was set. And part of those policies were; were you up-to-date on your patches and your AVs and all that good stuff.

    Blum:  Right.

    Shimel: And even then – and by the way, this was for three letter agencies and U.S. Department of Defense networks. Even then, checking Macs was like a black hole. Right?

    Kanies: It’s always been that way.

    Shimel: I’m sorry, what?

    Kanies: It’s always been that way, for various reasons. And one of them is that they just haven’t been used as much. The second is that Macs have always been kind of cut out of IT policy. Either the Windows – the IT has always been run by Windows and they either say, no, you can’t have them, or, yes, you can have them, but don’t ever talk to us about them. So they’ve kind of always been out.

    In the last 10, 15 years, Apple has really done a great job of building a device that is better for actual usage. So it started out very much in the consumerization of IT, which is how PCs got started in the ’80s, course, as people bring their own computers in. What then they started bringing their own Macs in. Now you look at, especially small companies, and they’ve gone from, “I’ve got a couple of Macs for my designers.” To, “Everyone have a Mac and I’ve got a couple of PCs because my accounting people have to use the Windows version of Excel for whatever reason.

    Shimel: You know what? That’s exactly it. And it’s interesting that we get this kind of folks coming in. And one of my colleagues just joined here. I apologize. So when Macs were 2 percent of the market, maybe no one cared. But as we were talking off mic earlier, when you started getting to 20 percent or more of the market or thereabouts, that’s a number, right? That’s a sizable amount to worry about.

    But how much are the – and I will throw it both at Luke and Zack. How much are the guys – and due to Apple’s professed policy of not wanting to be in the enterprise or not wanting to be in that business market of being a consumer brand? Right? And as a result, you know, if it walks like a duck, it quacks like a duck, but it’s really not a duck. Right how much of that is to blame here for our, up to this point, neglect of managing Macs in the workplace?

    Blum:  You want to start on that Luke?

    Kanies: Sure. Honestly, I don’t think much is, for at least two reasons.  No. 1 is that it wouldn’t have mattered if Apple had decided they really wanted to be enterprise. They would have failed. We know that because of taking multiple cracks at trying to do enterprise stuff and all of them fail. If they are lucky, they deflate quietly and just get brushed into a corner. If they’re unlucky, they fail relatively spectacularly.

    So Apple has, in the past, fought against its own DNA and lost because that’s how it works, right?  And when you look at Microsoft today and they are resurgent. And one of the ways they are resurgent is that they are doing a better job of being who they are rather than trying to be who they are not.

    I think the second reason is that Windows was incredibly dominant for so long. The way in which Windows succeeded was very business oriented, very – and yes it was kind of user oriented at first, but that was long time ago. You know, when I came up and went to college in the 90s, my – first cut my teeth, I was a Solaris user. I was – back before there was Linux. So even then you wouldn’t choose between Windows and Mac and a corporate environment. You would choose between Windows and Solaris in a corporate environment.

    Shimel: Right.

    Kanies: And again, you had a couple of designers in the corner and they had Macs what they did was really specialized. But I don’t really think it had anything to do with Apple. If anything, Apple was struggling to hold on at all. It was less that they weren’t an enterprise company and more that, “Wow. We found like two people who can’t live without our product that we going to make sure we do everything you can to make them as happy as possible and we’re not going to worry about anybody else. ”

    And it was only when, kind of the world changed a lot, partially because Jobs came back. But partially because the world changed a lot, right? The internet came out. And the reason why you wanted a computer shifted from, “Because I need one for work,” to, “Because I need one at home.” Right? And if the iMac had been 10 years earlier, they wouldn’t have sold any because, why would you have a computer at your house in 1990. There was no – there is not nearly so much reason. But when you can dial-in, when you’ve got Internet, that really changed the world.

    Then the trends, the drivers of computing shifted from entirely business use cases to at least 50/50 personal, business use cases. And one can argue today that the majority of drivers of how people think about their relation to computing is mostly driven by consumer use cases and that pushes to the enterprise. And we’ve seen this consumerization of IT trend going back decades. It’s more of a treadmill or an escalator than it is a one-time blip. But to me, this really explains why it matters now and it didn’t matter before, because that consumer use case driving so much of the story.

    Shimel: Yeah. I mean, so Luke, I’m a little older than you, right? Solaris is … My first company, we ran you know, SPARC servers, UltraSPARC, actually. But –

    Kanies: They may be slow, but they sure are expensive.

    Shimel: Don’t even go there, man. But on top of that, I was an OS2 dude.  I loved OS. I was running OS2 really early on. I still don’t understand why Windows is here and not OS2. But that’s another story.

    Kanies: But you know, one of the things that I think has really enabled this is they used to be such a gulf, such a, frankly, a pain in the butt to move. If your colleague was on Mac and you are on Windows, you just had to give him a word file to use or spreadsheet or anything, for that matter. You know, reformatting discs and doing all that nonsense. Beyond the internet, interoperability between has really, I think forced it.  But that’s – you know, that, it speaks for itself, right? A lot of us are using Macs today. I’m on a Mac right now.

    Zack, one of the – and we shouldn’t just focus on Macs. We should focus on what the iPhones and the iPads and Apple TV and it’s is ubiquitous, man. Nothing drives security people battier then having sort of unknown devices or unmanaged devices or black holes in their network.

    Blum:  Absolutely.

    Shimel: And so I would imagine that’s the allure, if you will, of giving Fleetsmith a whirl.

    Blum:  Yeah, absolutely. And especially with the move to the internet of things. Even with computing devices like iOS and iPad, you had iPads, for example, in nontraditional computer roles like a front desk check in machine or the conference room calendar. Then you have, often, three devices comprising a conference room videoconference set up, right?

    So these aren’t as much for individual employees anymore. These are sort of use case driven, almost appliance type applications. So not only do you have these unassigned, if you will, devices floating out there, they’re just on the internet. The corporate network as far as computer management and security of devices is dead, we need to secure the endpoints wherever they are and provide visibility.

    So that’s one of the great things about a product like Fleetsmith is that we provide that things to security folks whatever network the devices on and whatever its application is. And I wanted to add one thing to what – continue Luke’s first point from before.

    Apple absolutely has been a consumer company and now that there is such a high enterprise market share, they’ve actually stepped up and are building a lot of really great management APIs, kind of recognizing that third-party providers of MDM like us are then able to run with that where that is in our DNA. We are experienced IT and security folks. So they are doing some really exciting stuff that’s enabling further penetration into the enterprise stream.

    Shimel: Absolutely. One other just question. This is something that’s kind of – it’s close to where I’ve come from in some ways. If I’m the IT guy or the security guy, I absolutely abhor having multiple management interface systems that I’ve got to work with. So I’ve got this to manage my Mac stuff and iOS. I got this to manage my Windows stuff. I got this to manage my Linux. I got my cloud management stuff.

    How – does Fleetsmith integrate with any of, sort of the larger Windows or other kinds of device management products out there?

    Blum:  Alan, you’re talking about the fabled, single pane of glass. I think that’s what I’m hearing.

    Shimel: Yeah. Well, the mythical single plane of glass, but okay.

    Blum:  That’s right. Well, you said it. To answer your question directly, we do integrate with G-Suite and Office365 so that when people adopt Fleetsmith they don’t have a ton of manual data entry for their inventory. But aside from that, as far as devices go, there’s kind of the suite – device management, there is the suite approach and the best-of-breed approach.

    Unless you have incredibly, incredibly simple needs, usually the suite approach, you know, these companies that build management for every single OS, really fall short in all but one. They really started as a signal platform and just tacked on a couple of checkboxes. So unfortunately, in today’s world the reality is that if you need zero touch deployment, you need to automate the setup of the devices and you need FileVault disk encryption with automated _____ _____ _____. You need to make sure everything is encrypted. You really need the best-of-breed solution.

    So we do all of Apple and there is some products that do all of Windows, a lot out of Microsoft. And past a certain point, those are pretty much just a requirement today.

    Kanies: I would go a little further and say I would add a different dimension that’s less platform because Puppet, for example, is promiscuously cross-platform, but almost entirely server-side. So you can use, as Zack found in the early days, you can use Puppet to manage your desktops. But what you will find is just a constant low-level of friction in doing so because so much of our workflow, so much of the experience is built around servers.

    You might say, “Why is it hard to – if you are servicing more complicated than desktops why is it hard to manage them?” The answer is, desktops are off all the time, laptops are off all the time, they check in from different networks all the time. You don’t get to decide when is a good time for the user to reboot their computer. The user really has to decide.

    You’ve got to build a completely different experience around the product. It’s something that could be done, but there was a lot of friction. So I would say that I agree with that point, that you got to pick best-of-breed. And part of that dimension is what platform you’re talking about managing. Certainly a Windows solution… A solution for Windows being used to manage your Macs is not a great idea. But also, I think a solution for servers, a solution for back in, is not a great solution to manage desktops and laptops.

    That’s really where you do need a different solution. And not that it’s impossible that you could have a company doing both, but it’s unlikely and it certainly hasn’t happened yet.

    Shimel: Got it. Got it. Got it. Guys, we are right on the top of the hour. Unfortunately, I need to end it right here. But before we do, Zack, really quickly, people can get more information about Fleetsmith at…?

    Blum:  Yeah, just go to Fleetsmith.com.

    Shimel: Okay. And you know what? Maybe we could follow up in a couple of weeks before the end of the year because I do think the whole issue of Mac management as well as non-computer – or nontraditional PC devices, whether they be iPads or some sort of IoT and whether they’re running, frankly iOS or some other non-windows, non-Linux – well, maybe Linux. The idea of keeping them compliant, with whether it be a security policy, access policies, what have you, is a really big problem a lot of companies try to tackle, but they tend to stay in the low hanging fruit way rather than maybe some of the corner cases, as bad as a corner case as it may be, you know, it’s still not the mainstream like that.

    Blum:  Yeah. Absolutely. I could talk about that all day. I would love to.

    Shimel: All right. We will schedule something. Hey Luke, I’m sorry we didn’t have enough time to really dig into what else you got going on. But maybe we can do a follow up at some point on that as well.

    Kanies: That would be great. I will warn you that most of what I’m doing next is pointedly not very DevOps. I took 20 years in one industry. It has been enough.

    Shimel: Thank you.

    Kanies: So there is a lot that I’m working on but it’s taking the lessons of the last 20 years and trying to use some of the same tools in different places with different people.

    Shimel: That’s not a bad thing either, my friend. As you said earlier, it’s life.

    Kanies: Yeah.

    Shimel: Good luck with it though, and we will be in touch. Guys, thanks for being our guests on this episode of DevOps Chat. Fleetsmith.com, that’s; F-L-E-E-T-S-M-I-T-H.com. If you’re looking to manage and secure your Macs or iOS devices, worth checking out.

    This is Alan Shimel for staging-devopsy.kinsta.cloud. Until next time, everyone, have a great day. Bye-bye.

    Kanies: Thanks so much, Alan.

    Blum:  Thanks.

    — Alan Shimel