<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Encryption at rest on mobile device in Real User Monitoring</title>
    <link>https://community.dynatrace.com/t5/Real-User-Monitoring/Encryption-at-rest-on-mobile-device/m-p/254532#M6212</link>
    <description>&lt;P&gt;This is for a medical device application. It's unlikely that we would explicitly send PHI such as a device serial number to Dynatrace, but something like a crash report stack trace could incidentally include PHI by indicating what type of device the user has.&lt;/P&gt;</description>
    <pubDate>Thu, 29 Aug 2024 19:18:37 GMT</pubDate>
    <dc:creator>jcmanke</dc:creator>
    <dc:date>2024-08-29T19:18:37Z</dc:date>
    <item>
      <title>Encryption at rest on mobile device</title>
      <link>https://community.dynatrace.com/t5/Real-User-Monitoring/Encryption-at-rest-on-mobile-device/m-p/254436#M6203</link>
      <description>&lt;P&gt;For mobile application monitoring, is user session data encrypted when at rest before it is uploaded to Dynatrace?&lt;/P&gt;&lt;P&gt;In the documentation I read, I found the following info:&lt;/P&gt;&lt;P&gt;Data is encrypted in transit -&amp;nbsp;&lt;A href="https://docs.dynatrace.com/docs/shortlink/data-security-controls#transit" target="_blank"&gt;https://docs.dynatrace.com/docs/shortlink/data-security-controls#transit&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Data that has been uploaded to Dynatrace is encrypted with AES-256 when at rest. -&amp;nbsp;&lt;A href="https://docs.dynatrace.com/docs/shortlink/data-security-controls#rest" target="_blank"&gt;https://docs.dynatrace.com/docs/shortlink/data-security-controls#rest&lt;/A&gt;&lt;/P&gt;&lt;P&gt;OneAgent will discard data if it isn't uploaded to Dynatrace within 10 minutes -&amp;nbsp;&lt;A href="https://docs.dynatrace.com/docs/shortlink/oneagent-sdk-android-communication#offline-monitoring" target="_blank"&gt;https://docs.dynatrace.com/docs/shortlink/oneagent-sdk-android-communication#offline-monitoring&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;OneAgent tries to upload to Dynatrace in two-minute intervals by default -&amp;nbsp;&lt;A href="https://docs.dynatrace.com/docs/shortlink/cost-and-traffic-control-mobile#network-bandwidth-consumption" target="_blank"&gt;https://docs.dynatrace.com/docs/shortlink/cost-and-traffic-control-mobile#network-bandwidth-consumption&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What I am looking for is information on the security of OneAgent data during that 2-10 minutes between uploads. My use case is an application that may include personally identifiable information (PII) and protected health information (PHI) so we need to make sure it is secure before it is sent to Dynatrace in addition to in-transit and after.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2024 20:46:03 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Real-User-Monitoring/Encryption-at-rest-on-mobile-device/m-p/254436#M6203</guid>
      <dc:creator>jcmanke</dc:creator>
      <dc:date>2024-08-28T20:46:03Z</dc:date>
    </item>
    <item>
      <title>Re: Encryption at rest on mobile device</title>
      <link>https://community.dynatrace.com/t5/Real-User-Monitoring/Encryption-at-rest-on-mobile-device/m-p/254478#M6205</link>
      <description>&lt;P&gt;Data in mobile agent is locally cached in an SQLite DB.&amp;nbsp;&lt;BR /&gt;The database is not encrypted as there are challenges with creating a &lt;STRONG&gt;secure not extractable&lt;/STRONG&gt; key for older Android API version that Dynatrace supports.&lt;BR /&gt;For iOS turning on Data Protection for the app will bring improved security as files are then encrypted and inaccessible when the device is locked (&lt;A href="https://developer.apple.com/library/content/documentation/IDEs/Conceptual/AppDistributionGuide/AddingCapabilities/AddingCapabilities.html" target="_blank" rel="noopener"&gt;https://developer.apple.com/library/content/documentation/IDEs/Conceptual/AppDistributionGuide/AddingCapabilities/AddingCapabilities.html&lt;/A&gt;).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Outlook:&lt;/EM&gt; for grail data we have local database encryption on the roadmap&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Follow-up Question:&amp;nbsp;&lt;/EM&gt;is it really necessary to have health data in the monitoring data to evaluate application performance or help troubleshooting? Collected information especially for PHI should be kept to a minimum necessary.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2024 10:13:26 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Real-User-Monitoring/Encryption-at-rest-on-mobile-device/m-p/254478#M6205</guid>
      <dc:creator>Patrick_H</dc:creator>
      <dc:date>2024-08-29T10:13:26Z</dc:date>
    </item>
    <item>
      <title>Re: Encryption at rest on mobile device</title>
      <link>https://community.dynatrace.com/t5/Real-User-Monitoring/Encryption-at-rest-on-mobile-device/m-p/254532#M6212</link>
      <description>&lt;P&gt;This is for a medical device application. It's unlikely that we would explicitly send PHI such as a device serial number to Dynatrace, but something like a crash report stack trace could incidentally include PHI by indicating what type of device the user has.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2024 19:18:37 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Real-User-Monitoring/Encryption-at-rest-on-mobile-device/m-p/254532#M6212</guid>
      <dc:creator>jcmanke</dc:creator>
      <dc:date>2024-08-29T19:18:37Z</dc:date>
    </item>
  </channel>
</rss>

