3 ms·
Are you really arguing that highly portable mobile devices shouldn't be proof against an in-person attack by someone you know, say over the course of a shower,
by irons 16y ago
Are you really arguing that highly portable mobile devices shouldn't be proof against an in-person attack by someone you know, say over the course of a shower, or having left your phone on your desk over lunch? Of course that's a security hole. (So is single-user mode.)
- daeken 16y agoThere are two important things here: 1) If someone has physical access to your computer/car/phone/whatever, you should consider it compromised already; it's all just a matter of how easy it is for the first person to do it. (Smart cow problem) 2) Real-world security, at the end of the day, is a tradeoff between safety and user friendliness. This is why it doesn't make sense for Hacker News to use two-factor authentication, but it does make sense for your bank. Every additional security feature has its tradeoffs; adding new ones lightly is as bad an idea as not considering security at all.
- irons 16y agoA minute ago you were saying that a vulnerability requiring physical access wasn't a security hole. Now you're saying I should consider my phone compromised because other people have physical access to it. I don't see how you can hold both positions.
- daeken 16y agoEverything from leaving JTAG interfaces active (which many devices do) to enabling you to reflash a phone without authentication (which the iPhone does) could be considered vulnerabilities. We deal with these because they make more sense than the alternative.