CHAPTER 1 Overview
C448HD C450HD | Users & Administrator's Manual
■
Only specific Microsoft apps and AudioCodes-signed apps that were certified and approved
in the certification process can run in Kiosk mode; even if a malicious user manages to
install a new unauthorized app on the file system, the launcher on the device will only run
those specific approved apps and this cannot be changed in run time (only with a new
software code provided by AudioCodes).
Screen Lock
AudioCodes devices use a screen lock mechanism to prevent any malicious user/users from
gaining access to Calendar information and / or Active Directory list of employees and / or
triggering unauthorized calls from the device. After enabling screen lock, the device
automatically locks after a preconfigured period; a code is required to unlock the device and
resume full operation.
AudioCodes Private Key
The system software on AudioCodes devices is signed with AudioCodes' private key. Users can
replace the complete software only with new software that is also signed by AudioCodes'
private key.
This prevents users from replacing the complete over-the-air (OTA) package of the device with
any new system software, unless the software is fully signed by AudioCodes.
Android Debug Bridge (ADB)
The device does not allow access to ADB.
AudioCodes disabled the Android Debug Bridge (ADB) application and keeps the Teams app
running in the front all the time. As a result, it's impossible to install other apps from unknown
sources, and to sideload apps.
App Signing
Android requires all apps to be digitally- signed with a developer key before installation;
currently, the AudioCodes devices verify that apps are signed by Microsoft.
App signing prevents malicious user/users from replacing a Microsoft-signed app with an app
that "pretends" to be Microsoft but which lacks the private key that is known only to Microsoft.
Web Browser
The AudioCodes device does not include a Web browser. Users cannot browse to the public
internet or internal intranet. All Web services are customized to connect to Office 365 services
and AudioCodes' managed services such as the One Voice Operations Center (OVOC).
Without a Web browser, malicious user/users will not be able to access the device and browse
from it as a trusted device into the customer network.
- 7 -