3 ms·
Given that app developers need to actively use those iOS features, the obvious question is: How much of my app data is actually encrypted that way? It's much h
by __michaelg 10y ago
Given that app developers need to actively use those iOS features, the obvious question is: How much of my app data is actually encrypted that way?
It's much harder to get these things right (e.g. you want your fancy sync and notifications to work even if the phone is locked, etc.) thus I suspect that most apps would just use the Protected Until First User Authentication class and that's about it. Is there any way to confirm or refute that?
- leonatan 10y agoIn fact, that is indeed the default protection level, which is strong enough for a default setting.
- __michaelg 10y agoSure, but it's not any better than the Android FDE, and thus kind of defeating the point of the article. If everyone just uses the default setting, then iOS's encryption is theoretically and architecturally better, but it won't make a difference in practice.
- leonatan 10y agoIt's a compromise between security and usability, like always. And it is good for most cases. When higher security is needed, developer can choose to override and implement a different mechanism.