Live data from Hacker News

iPhone Mirroring at work may expose employees’ personal information

sevcosecurity.com

11–20 of 80 posts

Re: iPhone Mirroring at work may expose employees’ personal information

#11
post #4

Don’t you need to be signed in to the same iCloud account on both your laptop and phone to use this feature? That would mean that in order to encounter this issue you already need to be using a work account on a personal device, or vice versa. Since that’t the case I fail to see how this is a large vulnerability. The article doesn’t seem to address this point (possible I just missed this).

[deleted]

Re: iPhone Mirroring at work may expose employees’ personal information

#12
post #3

Duh, don't mix work and private devices / data

I was just discussing this with a friend. The one place where I’m willing to fudge things (corporate policies permitting) is putting my personal calendar on a work machine, work calendar on my personal systems, mostly because it makes dealing with the interface between the two simpler (plus then I get meetings showing up on my watch).

Re: iPhone Mirroring at work may expose employees’ personal information

#13
post #6

It's incredible to me how many people log into personal account on work devices. People should really research the amount of data security tools harvest.

I sometimes see my coworkers with banking tabs open when they screen share. The level of trust is astounding.

Re: iPhone Mirroring at work may expose employees’ personal information

#14
post #6

It's incredible to me how many people log into personal account on work devices. People should really research the amount of data security tools harvest.

If your employer isn't requiring you to log in with a personal account on a work device (and they're not), and your personal data doesn't have anything you'd mind your employer seeing, then why not? Because then there's no slippery slope and you're making a conscious choice. A lot of people lead really boring lives and just want the convenience of using their personal e-mail on the work device. Their employer knowing…

> Their employer knowing that the kids need to be picked up from soccer at 6 is a non-issue.

That's great and fine, until anything non-trivial in your life happens. Illness, relationship drama, recruiter conversation, off-hand low-context remarks to/from friends...

The corporate suckware hoovers up the data, and a) exposes you professionally to the company's whims of self-protection, and b) exposes the company legally to your personal imperfections.

Don't cross the streams. It would be bad.

Re: iPhone Mirroring at work may expose employees’ personal information

#15
post #9

Earlier quoted context omitted.

If your employer isn't requiring you to log in with a personal account on a work device (and they're not), and your personal data doesn't have anything you'd mind your employer seeing, then why not? Because then there's no slippery slope and you're making a conscious choice. A lot of people lead really boring lives and just want the convenience of using their personal e-mail on the work device. Their employer knowing…

One reason is that if your employer is sued your personal data/devices can get tied up in the discovery process.

How often does that really happen though, I’ve heard this argument so many times but not really the real impact it has from a real incident.

Re: iPhone Mirroring at work may expose employees’ personal information

#17
post #4

Don’t you need to be signed in to the same iCloud account on both your laptop and phone to use this feature? That would mean that in order to encounter this issue you already need to be using a work account on a personal device, or vice versa. Since that’t the case I fail to see how this is a large vulnerability. The article doesn’t seem to address this point (possible I just missed this).

A shocking number of people login to their personal Apple IDs (and email accounts and banks and etc. etc. etc.) on their work computer. I personally do not, but lots of people do.

Re: iPhone Mirroring at work may expose employees’ personal information

#18
post #4

Don’t you need to be signed in to the same iCloud account on both your laptop and phone to use this feature? That would mean that in order to encounter this issue you already need to be using a work account on a personal device, or vice versa. Since that’t the case I fail to see how this is a large vulnerability. The article doesn’t seem to address this point (possible I just missed this).

From here : https://support.apple.com/en-us/120421

> If your Mac asks whether to require Mac login to access your iPhone, choose Ask Every Time or Authenticate Automatically. You can change this later in iPhone Mirroring settings on your Mac.

Seems its an app setting to have this protected or not ?

Re: iPhone Mirroring at work may expose employees’ personal information

#19
post #12
post #3

Duh, don't mix work and private devices / data

I was just discussing this with a friend. The one place where I’m willing to fudge things (corporate policies permitting) is putting my personal calendar on a work machine, work calendar on my personal systems, mostly because it makes dealing with the interface between the two simpler (plus then I get meetings showing up on my watch).

Depending on your calendaring system(s), you can subscribe to your work calendar on your personal account, and vice versa. Although you should be careful about the latter!

My life is simple enough that I just dupe the occasional MTWTF personal events as "reserved blocks" onto my work calendar, and maintain my off-hours and SS personal calendar separately.

Re: iPhone Mirroring at work may expose employees’ personal information

#20
post #6

It's incredible to me how many people log into personal account on work devices. People should really research the amount of data security tools harvest.

Where is a good place to start this research? We have crowdstrike falcon at work, and I would love to know what they are monitoring.

It's been quite a few years since I did anything in this space, but back in the day you could get quite a lot of information simply by wrapping things in sandbox-exec [0] and progressively adding allow rules as the application inevitably blew up. It's a fair bit of manual effort, and I wouldn't be surprised if someone has written a wrapper around it that automatically figures it out, but last I checked this was the most reliable way to explicitly see what a rogue application does.

[0] https://www.karltarvas.com/macos-app-sandboxing-via-sandbox-...

Post reply on HN