Live data from Hacker News

The limitations of Android N Encryption

blog.cryptographyengineering.com

1–10 of 31 posts

Re: The limitations of Android N Encryption

#3
I know that apple did a lot of controversial moves in the past years, but i still get the impression that apple takes privacy seriously and tries to respect it even when there is the fundamental need for data collection [1].

[1] https://backchannel.com/an-exclusive-look-at-how-ai-and-mach...

Re: The limitations of Android N Encryption

#5
post #3

I know that apple did a lot of controversial moves in the past years, but i still get the impression that apple takes privacy seriously and tries to respect it even when there is the fundamental need for data collection [1]. [1] https://backchannel.com/an-exclusive-look-at-how-ai-and-mach...

Absolutely, and the commitment to security and privacy keeps me coming back to iOS. The iOS white paper[0] is an excellent read for anyone interested in security. Unlike android devies, iOS security is coupled to hardware HSM chips which Apple refers to the secure enclave. It's used not just to encrypt and decrypt, but to verify the entire boot process and all binaries used by the cellular chips.

Now that google is manufacturing devices I expect them to begin following Apple's example. Avoid garbage like TrustZone and do it right.

1. https://www.apple.com/business/docs/iOS_Security_Guide.pdf

Re: The limitations of Android N Encryption

#6
post #4

Geez, as much as i'd love to divorce myself from the Apple ecosystem I continually find reasons to keep my iPhone instead of opting for Android.

I'm in the same boat. Due to Apple's most recent product decisions I'm losing confidence and I'm starting to look elsewhere. After reading up on the current state of Android and especially how to increase privacy and security, it seems I'll have to stick with Apple for a while longer.

Re: The limitations of Android N Encryption

#7
Given that app developers need to actively use those iOS features, the obvious question is: How much of my app data is actually encrypted that way?

It's much harder to get these things right (e.g. you want your fancy sync and notifications to work even if the phone is locked, etc.) thus I suspect that most apps would just use the Protected Until First User Authentication class and that's about it. Is there any way to confirm or refute that?

Re: The limitations of Android N Encryption

#8
post #3

I know that apple did a lot of controversial moves in the past years, but i still get the impression that apple takes privacy seriously and tries to respect it even when there is the fundamental need for data collection [1]. [1] https://backchannel.com/an-exclusive-look-at-how-ai-and-mach...

Absolutely, and the commitment to security and privacy keeps me coming back to iOS. The iOS white paper[0] is an excellent read for anyone interested in security. Unlike android devies, iOS security is coupled to hardware HSM chips which Apple refers to the secure enclave. It's used not just to encrypt and decrypt, but to verify the entire boot process and all binaries used by the cellular chips. Now that google is m…

"Garbage"? Can you explain why?

Re: The limitations of Android N Encryption

#9

Given that app developers need to actively use those iOS features, the obvious question is: How much of my app data is actually encrypted that way? It's much harder to get these things right (e.g. you want your fancy sync and notifications to work even if the phone is locked, etc.) thus I suspect that most apps would just use the Protected Until First User Authentication class and that's about it. Is there any way to…

In fact, that is indeed the default protection level, which is strong enough for a default setting.

Re: The limitations of Android N Encryption

#10
post #8

Earlier quoted context omitted.

Absolutely, and the commitment to security and privacy keeps me coming back to iOS. The iOS white paper[0] is an excellent read for anyone interested in security. Unlike android devies, iOS security is coupled to hardware HSM chips which Apple refers to the secure enclave. It's used not just to encrypt and decrypt, but to verify the entire boot process and all binaries used by the cellular chips. Now that google is m…

"Garbage"? Can you explain why?

There's very good reasons why Apple doesn't trust it and does something different. When so much of the phone security relies on it, it's very important to get it right.

https://www.google.com/amp/www.slashgear.com/android-soc-sec...

Post reply on HN