Live data from Hacker News

iPhone Mirroring at work may expose employees’ personal information

sevcosecurity.com

31–40 of 80 posts

Re: iPhone Mirroring at work may expose employees’ personal information

#31
post #18
post #4

Don’t you need to be signed in to the same iCloud account on both your laptop and phone to use this feature? That would mean that in order to encounter this issue you already need to be using a work account on a personal device, or vice versa. Since that’t the case I fail to see how this is a large vulnerability. The article doesn’t seem to address this point (possible I just missed this).

From here : https://support.apple.com/en-us/120421 > If your Mac asks whether to require Mac login to access your iPhone, choose Ask Every Time or Authenticate Automatically. You can change this later in iPhone Mirroring settings on your Mac. Seems its an app setting to have this protected or not ?

This setting is to establish a new mirroring session, but presumably that iOS app install metadata is collected at the very first connection and then cached on macOS.

Re: iPhone Mirroring at work may expose employees’ personal information

#32

So the threshold of concern by a "security" company is "they might audit your apps and find out you're gay!" Yet not a single concern about tethering an iPhone (with an external connection) to a PC on the company's internal network, bypassing all firewalls, proxies, and other protections. That is grounds for immediate dismissal at some places. I expect security people to think more like network engineers and less lik…

This isn't about tethering. It's about mirroring which requires the iPhone and Mac to be on the same WiFi. And you can't route data from the Mac through the phone via mirroring

Re: iPhone Mirroring at work may expose employees’ personal information

#33

So the threshold of concern by a "security" company is "they might audit your apps and find out you're gay!" Yet not a single concern about tethering an iPhone (with an external connection) to a PC on the company's internal network, bypassing all firewalls, proxies, and other protections. That is grounds for immediate dismissal at some places. I expect security people to think more like network engineers and less lik…

What do you mean by "tethering an iPhone to a PC"? iPhone Mirroring does not grant the iPhone any privileges to data on the Mac, as far as I know.

Also, there are two orthogonal concerns at play here: Companies generally don't want personal devices (at least those not covered by MDM) to hold company data, but companies also might not want to inadvertently hold personal data of their employees.

Re: iPhone Mirroring at work may expose employees’ personal information

#34

So the threshold of concern by a "security" company is "they might audit your apps and find out you're gay!" Yet not a single concern about tethering an iPhone (with an external connection) to a PC on the company's internal network, bypassing all firewalls, proxies, and other protections. That is grounds for immediate dismissal at some places. I expect security people to think more like network engineers and less lik…

This isn't about tethering. It's about mirroring which requires the iPhone and Mac to be on the same WiFi. And you can't route data from the Mac through the phone via mirroring

I don't think iPhone Mirroring requires both devices being on the same (or in fact any) Wi-Fi network. It does however require them to be signed in to the same iCloud account.

Re: iPhone Mirroring at work may expose employees’ personal information

#35
post #6

It's incredible to me how many people log into personal account on work devices. People should really research the amount of data security tools harvest.

In my case I "lend" my personal device for work (Git, Slack, Figma, Miro... use one Chrome for work and Chrome Beta for personal). So I suppose there's no software running behind the scenes. Should I still worry in this case?

Re: iPhone Mirroring at work may expose employees’ personal information

#36

So the threshold of concern by a "security" company is "they might audit your apps and find out you're gay!" Yet not a single concern about tethering an iPhone (with an external connection) to a PC on the company's internal network, bypassing all firewalls, proxies, and other protections. That is grounds for immediate dismissal at some places. I expect security people to think more like network engineers and less lik…

[deleted]

Re: iPhone Mirroring at work may expose employees’ personal information

#37
Speaking of iPhone Mirroring: Doesn't this effectively downgrade two-factor authentication to a single factor for flows like "tap 'yes' on your phone to login"?

I've been wondering if there is a way for iOS authenticator apps to opt out of mirroring, but haven't found anything so far.

Re: iPhone Mirroring at work may expose employees’ personal information

#38
post #26

Earlier quoted context omitted.

I sometimes see my coworkers with banking tabs open when they screen share. The level of trust is astounding.

You will probably find that your corporate TLS MitM proxy excludes financial institutions so that employees can do their banking without any doubt that their own company would respect the confidentiality of their finances. If not, your cybersecurity team needs some help.

Yes, when I was in charge of security at previous places we did not MITM a whole category of websites including banking, health, etc.

Re: iPhone Mirroring at work may expose employees’ personal information

#39
post #6

It's incredible to me how many people log into personal account on work devices. People should really research the amount of data security tools harvest.

I sometimes see my coworkers with banking tabs open when they screen share. The level of trust is astounding.

It certainly sounds foolish at first, but what's the real risk? Is your employer really going transfer themselves your balance or snoop on your utility bills?

Now if you loaded a crypto wallet on your work device, that would be another story..

Re: iPhone Mirroring at work may expose employees’ personal information

#40
post #4

Don’t you need to be signed in to the same iCloud account on both your laptop and phone to use this feature? That would mean that in order to encounter this issue you already need to be using a work account on a personal device, or vice versa. Since that’t the case I fail to see how this is a large vulnerability. The article doesn’t seem to address this point (possible I just missed this).

A shocking number of people login to their personal Apple IDs (and email accounts and banks and etc. etc. etc.) on their work computer. I personally do not, but lots of people do.

IT in companies using Apple devices must be an absolutely miserable position.
Post reply on HN