Live data from Hacker News

iPhone Mirroring at work may expose employees’ personal information

sevcosecurity.com

71–80 of 80 posts

Re: iPhone Mirroring at work may expose employees’ personal information

#72
post #46

Earlier quoted context omitted.

As a consultant, I work with Linux, macOS and Windows. Depends on the client and the project. I can't remember last time I even heard about a malware in someone else's Windows machine, let alone my Windows machine. I don't know what you mean by debugging installers. Sounds like an outdated opinion. Just like those "lol PHP bad" regurgitations and linking outdated articles about it.

The sysadmins at my job frequently find malware artifacts on our servers, because we exclusively use Windows server. And the expectation is you RDP in to get stuff done, which means there's a big potential for human failure. Also most Windows software is just taken off the web and installed with administrator privileges. Sure, there are package managers. In practice, they're rarely used on Windows. From a technical s…

macOS used to have a decent security story until some QoL started requiring disabling SIP.

They gutted the OS so much that users start disabling security features.

And don't get me started with atrocious window manager from macOS. Took a decade to improve it slightly. Still far away from some Linux DE and Windows. I don't enjoy having to buy apps to fix macOS. There are some open source tools for some things but for others it's cost effective to just buy.

Re: iPhone Mirroring at work may expose employees’ personal information

#73
post #61

Earlier quoted context omitted.

Most tech companies (except some really big ones or those with compliance requirements) are quite flexible around this issue.

I would qualify that "tech companies that don't know what they're doing wrt IT". Apple does have some features to allow a bit of flexibility, but unless you do all of your work via VDI or similar, I'd consider non-MDM devices to be a huge red flag,

It's called trusting your employees, especially if they are engineers. Maybe that's why "nobody wants to work anymore".

Re: iPhone Mirroring at work may expose employees’ personal information

#74
post #73

Earlier quoted context omitted.

I would qualify that "tech companies that don't know what they're doing wrt IT". Apple does have some features to allow a bit of flexibility, but unless you do all of your work via VDI or similar, I'd consider non-MDM devices to be a huge red flag,

It's called trusting your employees, especially if they are engineers. Maybe that's why "nobody wants to work anymore".

MDM does not imply surveillance. I wouldn't use it if it did. It does mean I can enforce full disk encryption and remotely wipe a machine if it is stolen, though.

Re: iPhone Mirroring at work may expose employees’ personal information

#75
post #73

Earlier quoted context omitted.

It's called trusting your employees, especially if they are engineers. Maybe that's why "nobody wants to work anymore".

MDM does not imply surveillance. I wouldn't use it if it did. It does mean I can enforce full disk encryption and remotely wipe a machine if it is stolen, though.

Found the system admin

Re: iPhone Mirroring at work may expose employees’ personal information

#76
post #75

Earlier quoted context omitted.

MDM does not imply surveillance. I wouldn't use it if it did. It does mean I can enforce full disk encryption and remotely wipe a machine if it is stolen, though.

Found the system admin

[flagged]

Re: iPhone Mirroring at work may expose employees’ personal information

#77
post #31
post #18

Earlier quoted context omitted.

From here : https://support.apple.com/en-us/120421 > If your Mac asks whether to require Mac login to access your iPhone, choose Ask Every Time or Authenticate Automatically. You can change this later in iPhone Mirroring settings on your Mac. Seems its an app setting to have this protected or not ?

This setting is to establish a new mirroring session, but presumably that iOS app install metadata is collected at the very first connection and then cached on macOS.

This is a nice feature of the apple ecosystem to be fair, but I do think the issue is with connecting work and personal accounts/devices

Re: iPhone Mirroring at work may expose employees’ personal information

#78

So the threshold of concern by a "security" company is "they might audit your apps and find out you're gay!" Yet not a single concern about tethering an iPhone (with an external connection) to a PC on the company's internal network, bypassing all firewalls, proxies, and other protections. That is grounds for immediate dismissal at some places. I expect security people to think more like network engineers and less lik…

Bypassing firewalls and proxies how?

Re: iPhone Mirroring at work may expose employees’ personal information

#79
post #56
post #34

Earlier quoted context omitted.

I don't think iPhone Mirroring requires both devices being on the same (or in fact any) Wi-Fi network. It does however require them to be signed in to the same iCloud account.

I’ve noticed this as well, but actually not sure how the feature works if not over the LAN. Is it bluetooth? Or synced over icloud?

Google "awdl"
Post reply on HN