Companies (apple included) can invest all they want in features and press releases claiming that said features are to ensure customer privacy but - unless these features are open sourced and subject to public and recurrent scrutiny - it is just faith that they expect from customers. If you care deeply about the privacy of you data, don't hand your data on a physical device to anyone.
There are other practical indicators of how good things are. Apple, for instance, demonstrated that the iphone was sufficiently secure to provoke some novel legal maneuvering during the San Bernardino situation.
Samsung’s “repair mode” lets technicians look at your phone, not your data
71–80 of 94 posts
Re: Samsung’s “repair mode” lets technicians look at your phone, not your data
#72Earlier quoted context omitted.
There are other practical indicators of how good things are. Apple, for instance, demonstrated that the iphone was sufficiently secure to provoke some novel legal maneuvering during the San Bernardino situation.
Which was then circumvented by a third party. The legal maneuvering wasn't that novel: despite what Apple advertised, Apple could obtain the data off the device, and the FBI simply asked Apple to do it for them.
It was not even a sure thing that apple could do it.
Re: Samsung’s “repair mode” lets technicians look at your phone, not your data
#73Earlier quoted context omitted.
Which was then circumvented by a third party. The legal maneuvering wasn't that novel: despite what Apple advertised, Apple could obtain the data off the device, and the FBI simply asked Apple to do it for them.
The point is that apple wouldn't do it. Anyone can buy a 0-day. It was not even a sure thing that apple could do it.
The only reason Apple wouldn't do it was that it was such an embarrassment for its marketing to be shown to be a lie by something that had made national headlines.
As far as anybody being able to buy a 0-day, the price for such a 0-day is much higher for competitors' phones with better security.
Re: Samsung’s “repair mode” lets technicians look at your phone, not your data
#74Re: Samsung’s “repair mode” lets technicians look at your phone, not your data
#75Earlier quoted context omitted.
The point is that apple wouldn't do it. Anyone can buy a 0-day. It was not even a sure thing that apple could do it.
It was a sure thing that Apple could do it — the FBI clearly explained how. It was such a sure thing that Apple stopped advertising it couldn't do it after the FBI showed how it could, with the quoted wording in https://www.nbcnews.com/tech/security/ios-8-even-apple-cant-... disappearing from Apple's website (but not from IA). The only reason Apple wouldn't do it was that it was such an embarrassment for its marketin…
Regarding the price of a 0-day, it is clear that the fbi bought it. (maybe it wasn't 0d at the time but it was an exploit.) The cost is irrelevant considering it was a state actor. In context of this discussion, apple resisted.
I'm all for more security and will take your recommendation for a vendor with more integrity. I think we have to weigh integrity vs capability, though. Good intentions don't confound tough adversaries.
Re: Samsung’s “repair mode” lets technicians look at your phone, not your data
#76Re: Samsung’s “repair mode” lets technicians look at your phone, not your data
#77I also call for bullshit feature. Most of the time, you send your phone because it is not working anymore, unreactive, so there will be no way to go into repair mode. But, that being said, this does not address also one big hurdle for people sending their phone for repair, that is the opposite: losing all data. As a standard procedure, most technicians will reset to factory the device to see if it fixes the problem e…
Re: Samsung’s “repair mode” lets technicians look at your phone, not your data
#78Re: Samsung’s “repair mode” lets technicians look at your phone, not your data
#79Earlier quoted context omitted.
National Security Letters or their equivalent in other jurisdictions render the "no business incentive" argument to be moot.
That is completely useless in the context of this feature. National security letters go direct to Samsung who already have full access. This feature is relating to creeps at 3rd party repair stores stealing your nudes.
It's hard for phone these days, but my PC's security model is I can easily lock myself out of it permanently.
Re: Samsung’s “repair mode” lets technicians look at your phone, not your data
#80Companies (apple included) can invest all they want in features and press releases claiming that said features are to ensure customer privacy but - unless these features are open sourced and subject to public and recurrent scrutiny - it is just faith that they expect from customers. If you care deeply about the privacy of you data, don't hand your data on a physical device to anyone.
You know independent infosec reviews are a thing, right?