What an odd feature to expose to the the user. User data partition is already encrypted. It would be enough with different boot option, chosen by the workshop with usb, fastboot or key combo, they could not access data anyway. Maybe its hard to explain to non techies why they need to power off their phone before handing it to the workshop. Otherwise this just sounds like PR stunt.
Samsung’s “repair mode” lets technicians look at your phone, not your data
81–90 of 94 posts
Re: Samsung’s “repair mode” lets technicians look at your phone, not your data
#82Earlier quoted context omitted.
It’s also bs. The promise is only as good as the maker and the technology. Has it been vetted? Are there independent evaluations? Is Samsung willing accept any liabilities in the event of failure? All hype, no substance. Delete your data (with no way of verifying) and restore it on return.
If you don't trust the manufacturer of your phone, don't buy the phone.
It's impossible to listen to this advice without a huge amount of naive trust.
Re: Samsung’s “repair mode” lets technicians look at your phone, not your data
#83Companies (apple included) can invest all they want in features and press releases claiming that said features are to ensure customer privacy but - unless these features are open sourced and subject to public and recurrent scrutiny - it is just faith that they expect from customers. If you care deeply about the privacy of you data, don't hand your data on a physical device to anyone.
There are other practical indicators of how good things are. Apple, for instance, demonstrated that the iphone was sufficiently secure to provoke some novel legal maneuvering during the San Bernardino situation.
The rest was media posturing.
Re: Samsung’s “repair mode” lets technicians look at your phone, not your data
#84Earlier quoted context omitted.
Also, we know that if you use icloud, Apple saves a copy of your encryption key ...
That's true with iCloud Backup specifically, not iCloud. But unsecured notes and photos don't fall under the encryption umbrella, so syncing those means you lose privacy. Even syncing messages is safe, since messages are shared with your private encryption key. iCloud Backup and photo syncing are pretty much the bones thrown to US law enforcement.
Re: Samsung’s “repair mode” lets technicians look at your phone, not your data
#85Companies (apple included) can invest all they want in features and press releases claiming that said features are to ensure customer privacy but - unless these features are open sourced and subject to public and recurrent scrutiny - it is just faith that they expect from customers. If you care deeply about the privacy of you data, don't hand your data on a physical device to anyone.
You don't need open source. Just look at the business incentives. Samsung has no incentive at all to give 3rd party repair workers access to your private data. Even if the feature isn't bullet proof, its going to be a whole lot better than the current situation where you hand your phone and password over and come back later to pick up the phone.
Re: Samsung’s “repair mode” lets technicians look at your phone, not your data
#86Earlier quoted context omitted.
That's true with iCloud Backup specifically, not iCloud. But unsecured notes and photos don't fall under the encryption umbrella, so syncing those means you lose privacy. Even syncing messages is safe, since messages are shared with your private encryption key. iCloud Backup and photo syncing are pretty much the bones thrown to US law enforcement.
iCloud Backup is on by default. Approximately nobody uses iCloud without using iCloud Backup.
Re: Samsung’s “repair mode” lets technicians look at your phone, not your data
#87Earlier quoted context omitted.
It’s also bs. The promise is only as good as the maker and the technology. Has it been vetted? Are there independent evaluations? Is Samsung willing accept any liabilities in the event of failure? All hype, no substance. Delete your data (with no way of verifying) and restore it on return.
What would make you feel it's sufficiently vetted?
Samsung has been consumer-hostile in the mobile phone space for years, and nearly every 'vault' or 'secure enclave' or 'encrypted partition' that they've released has been broken in some fundamental and huge way since they started with the idea.[0]
Re: Samsung’s “repair mode” lets technicians look at your phone, not your data
#88Earlier quoted context omitted.
You didn't ask me, but my input is that the two most obvious to me are: open source, so the effort can be vetted in good faith--or a insured guarante, so the consequences can be abated
Tl;dr some security is better than none If it does anything to add privacy it’s a good thing, even if it can be sidestepped, it’s a good thing. Just because a lock is easily broken that doesn’t make it useless, it can still act as a deterrent for opportunistic crimes. One time I took a bike to festival. The first few days I was locking it up safely with a bike lock and chain, as I’m used to doing in the city. Eventua…
I disagree.
a bad lock that the consumer thinks is a good lock will be used to hide All The Secrets.
In other words; when a consumer is lulled into a false sense of security by a manufacturer that calls everything secure and secret, they will guard their secrets with it. Very few people actually technically vet their security rationales, so the consumer that is relying on the company, who is then in-turn providing a subpar and broken security mechanism, is more-or-less screwed and is in actuality in a worse position than they would have been had they known to keep their secrets off of the broken platform.
Your analogy fits the real life metaphor of a lock, it bends and breaks when we carry it into things like cell phones where 'a good lock' requires forethought and engineering time that a company isn't willing to sink into it; and this poor quality engineering is hidden behind a slick glass phone that by all means is beautiful.
It's easy to hide the shoddy software engineering that is inside a beautiful product. It's hard to hide a poorly crafted physical lock -- the key won't work properly, it'll be hard to install, the surface finish will be low quality, etc etc.
It's easier for the company, and ultimately more profitable, to just claim that a mechanism works and then deal with the damage to reputation later-on with the next 'WhizBang Product', especially since the mechanism itself is hard for Joe Everybody to vet in any significant way.
Re: Samsung’s “repair mode” lets technicians look at your phone, not your data
#89Earlier quoted context omitted.
What would make you feel it's sufficiently vetted?
You didn't ask me, but my input is that the two most obvious to me are: open source, so the effort can be vetted in good faith--or a insured guarante, so the consequences can be abated
Re: Samsung’s “repair mode” lets technicians look at your phone, not your data
#90What an odd feature to expose to the the user. User data partition is already encrypted. It would be enough with different boot option, chosen by the workshop with usb, fastboot or key combo, they could not access data anyway. Maybe its hard to explain to non techies why they need to power off their phone before handing it to the workshop. Otherwise this just sounds like PR stunt.
How would the workshop test the repair if they can't boot into the phone?