Box is releasing a number of new security updates to Box Mobile to better protect our users and their content when accessing Box via a mobile device. These enhancements will help our customers ensure that their content on Box is not leaked or exposed due to compromised endpoint devices.
These new updates to Box Mobile will include:
- Enhanced support for Box Verified Enterprise (BVE) on mobile devices, ensuring a seamless and secure login process
- New implementation of Proof Key for Code Exchange (PKCE), which hardens our authentication process against authorization code interception attacks
- Enforcement of App Transport Security (ATS) within the Box for iOS application, offering further protection against eavesdropping and tampering threats
- Expanded Device Trust checks for iOS devices, increasing the number of checks and ensuring only compliant devices are allowed access to Box
- Improved certificate validation for Android devices, providing greater protection against man-in-the-middle attacks by ensuring the app communicates only with trusted, verified servers
Box is committed to providing our customers with frictionless content protection across all of their devices, and these enhancements are a continuation of that effort. If you would like to learn more about Box Mobile security, please look here.