3 ms·
It's understood that the phone manufacturers can unlock their phones with the tools available to them -- that serves many purposes like being able to refurbish
by bazillion 11y ago
It's understood that the phone manufacturers can unlock their phones with the tools available to them -- that serves many purposes like being able to refurbish old phones. Those accessing the data who are not doing so with the intention of serving the phone owner, however, have to have a court order to access the phone. That to me speaks highly of the phone if access outside the user of the phone is limited to organization who signed the keys locking the phone (and therefore have the certificates to make signed requests to unlock).
It's not like you take it to Apple and Apple says to you "Here's the user's data.". There is something like a 60-90 day wait period while they analyze each individual request for approval, and do their due diligence to make sure access is justified. Juxtapose that with a typical android phone that can be rooted without the help of the manufacturer, and then you get that the customer is better served by one process over the other.
- schoen 11y agoYou can separate the ability to reinstall the operating system from the ability to derive the keys to decrypt a particular device (or to instruct a running device to give you root). I think this is described in Frank Stajano's Security for Ubiquitous Computing. Edit: previously in his paper with Ross Anderson https://www.cl.cam.ac.uk/~fms27/papers/1999-StajanoAnd-duckling.pdf https://www.cl.cam.ac.uk/~fms27/papers/1999-StajanoAnd-duckl... My ThinkPad can easily be reinstalled with a new OS, but my OS vendor can't give someone else my full-disk encryption keys or make them root on my device. And even with firmware-level security features we can separate "transfer ownership of device" from "access existing protected device state". I don't see any more reason that mobile phone vendors must be able to bypass screen locks or disk encryption than that desktop OS vendors must be able to do these things. (Sure, in both cases some users would want the vendor to be able to and others wouldn't.)
- rdtsc 11y agoIf Apple can get access to your data by unlocking "something" that is not the best security -- that is called a backdoor. The best security is when only you can get your data and nobody else.