
CHAPTER1 Overview C448HD C450HD | Users & Administrator's Manual
■OnlyspecificMicrosoftappsandAudioCodes-signedappsthatwerecertifiedandapproved
inthecertificationprocesscanruninKioskmode;evenifamalicioususermanagesto
installanewunauthorizedapponthefilesystem,thelauncheronthedevicewillonlyrun
thosespecificapprovedappsandthiscannotbechangedinruntime(onlywithanew
softwarecodeprovidedbyAudioCodes).
Screen Lock
AudioCodesdevicesuseascreenlockmechanismtopreventanymalicioususer/usersfrom
gainingaccesstoCalendarinformationand/orActiveDirectorylistofemployeesand/or
triggering unauthorized calls from the device. After enabling screen lock, the device
automaticallylocksafterapreconfiguredperiod;acodeisrequiredtounlockthedeviceand
resumefulloperation.
AudioCodes Private Key
ThesystemsoftwareonAudioCodesdevicesissignedwithAudioCodes'privatekey.Userscan
replace the complete software only with new software that is also signed by AudioCodes'
privatekey.
Thispreventsusersfromreplacingthecompleteover-the-air(OTA)packageofthedevicewith
anynewsystemsoftware,unlessthesoftwareisfullysignedbyAudioCodes.
Android Debug Bridge (ADB)
The device does not allow access to ADB.
AudioCodesdisabledtheAndroidDebugBridge(ADB)applicationandkeepstheTeamsapp
runninginthefrontallthetime.Asaresult,it'simpossibletoinstallotherappsfromunknown
sources,andtosideloadapps.
App Signing
Android requires all apps to be digitally- signed with a developer key before installation;
currently,theAudioCodesdevicesverifythatappsaresignedbyMicrosoft.
Appsigningpreventsmalicioususer/usersfromreplacingaMicrosoft-signedappwithanapp
that"pretends"tobeMicrosoftbutwhichlackstheprivatekeythatisknownonlytoMicrosoft.
Web Browser
TheAudioCodesdevicedoesnotincludeaWebbrowser.Userscannotbrowsetothepublic
internetorinternalintranet.AllWebservicesarecustomizedtoconnecttoOffice365services
andAudioCodes'managedservicessuchastheOneVoiceOperationsCenter(OVOC).
WithoutaWebbrowser,malicioususer/userswillnotbeabletoaccessthedeviceandbrowse
fromitasatrusteddeviceintothecustomernetwork.
-7-