Skip to main content

iOS client woefully insecure?

Thread needs solution

I am only testing TI 2020 Cloud ATM although I would like to subscribe, but the iOS client bothers me. I need access to files from my iPhone and installed the iOS app which works, but it does not use TouchID that I can find, AND it does not log me out when I close the app or after a short period. My dataset is protected by my own password, and I find this behaviour very disturbing, assuming I have not missed something.

0 Users found this helpful

Henry, welcome to these public User Forums.

The security of any IOS app, including the Acronis one, is determined by the security of your phone unless you take steps to clear all stored credentials using the methods provided by your phone itself.

Your Acronis Cloud data is protected by your account credentials, which in turn will be stored within the Acronis IOS app if you have setup a backup to the Cloud from the device.  Only your credentials will give access to your Cloud data, plus if you have used password protection, you would also need to enter that password to decrypt the stored data.

Thank you, but that is not sufficient protection. Once logged in it stays logged in unless I logout manually. I think my description of "woeful" is accurate. Needs updating urgently IMO.

 

Henry, please submit Feedback direct to Acronis about your concerns using the tool provided in the Help area of the ATI GUI.

I think this will be a user preference that could go either way.  The mobile app is designed to stay active so that scheduled backups can also run without having to log in each time (otherwise the schedule wouldn't work).

If you've ever used an email client (like Outlook), you don't log out of it either, it automatically logs in and fetches mail all the time.  Other mobile apps stay logged in too (Twitter, Facebook, etc), but some offer the ability to log out, but you don't have to either.

If the mobile app doesn't meet your needs, I would consider looking for something else that does.  There aren't many options out there for Apple (iTunes or bust) and Android is really tied to Google now and doesn't log out automatically either.  In fact, you have to have a Google Account for most Android devices to do just the basics on them and it's always logged in for access to things like mail and Youtube, not to mention other settings like backups of applications, photos, etc. to the Cloud.

I'm sorry, but you are missing the point. This is a very basic security failure on the part of the mobile client, and it is not at all comparable to an email client. And as for looking for something else, what else can access a password encrypted TI 2020 cloud file/folders backup [rhetorical]. I will have to manually logout each time, but that is quite ridiculous IMO. I have or do use OneDrive and iDrive, and both offer TouchID restrictions for access.

One would think a Swiss company operating in a jurisdiction with all its (banking) secrecy laws would understand online security.

frestogaslorastaswastavewroviwroclolacorashibushurutraciwrubrishabenichikucrijorejenufrilomuwrigaslowrikejawrachosleratiswurelaseriprouobrunoviswosuthitribrepakotritopislivadrauibretisetewrapenuwrapi
Posts: 250
Comments: 7092

Henry,

thank you for taking the time to share your feedback on the security in the mobile client! I've passed it to the respective product manager for review.