3 ms·
Also Android\iOS in general as a platform is more secure, Android\iOS are far more restrictive when it comes to users. narrowing the attack surface for casual u
by CyberRage 5y ago
Also Android\iOS in general as a platform is more secure, Android\iOS are far more restrictive when it comes to users. narrowing the attack surface for casual users.
For instance, rooting in order to install custom drivers\software is very difficult.
A single place to download content(App store) which provide tremendous control over content. detection of rogue apps, removal once they turn rogue, check assurance.
Seamless updates through a single pane of glass.(App Store again)
- pjmlp 5y agoPity that almost no one uses them as desktop platforms. Windows store and Windows Sandbox is way more advanced than any GNU/Linux offering, including kernel and hardware sandoxing with help of hardware protections. Still waiting for snap and flatpak to finally fix their security holes.
- amluto 5y agoThe Windows sandbox infrastructure may well be more advanced than seccomp in the sense of being more complicated, but I would argue that makes it worse, not better. There are many sandbox escapes based on the insane complexity of Windows integrity levels. In contrast, there have been maybe 5 known Linux kernel bugs allowing a breakout from a strict seccomp policy in the last few years.
- pjmlp 5y agoWhat hardware vendor does sell GNU/Linux systems already pre-configured with such policies?
- Craighead 5y agoPity that you don't know
- amluto 5y agoWhat hardware vendor sells the Windows sandbox preconfigured with policies? Chromium and Firefox configure the Windows sandbox and seccomp on Windows and Linux respectively. I would argue that seccomp is better. On the other hand, Windows has its app sandbox and Linux has snap and flatpak. I don’t think any of them are amazing.
- RyanPringnitz 5y agoI work on a use case that leverages Samsung DeX and secondary displays with keyboard/mouse. Applications are refactored to run on native Android, or accessed on HTML5 sites. What Win32 is left is accessed on VDI. The solution supports MFA step-up auth to login to device, local print, proxy's traffic, per app vpn. Endpoint threat detection products for Android have more capabilities than ever. You can specify approved IP addresses, countries that traffic can communicate with. You can provide a list of approved WiFi BSSID. With these mobile security SDK's embedded in native Android apps, functionality with the apps can be limited based on threat infractions. E.g. - if the device magically became rooted while authenticated in android native app, or connects to rogue BSSID; the app performs whatever actions (terminates vpn to intranet, logs threat event on public facing endpoint, force re-authenticate with MFA.)
- pjmlp 5y agoGreat, in what shop can someone buy it?
- RyanPringnitz 5y agoWhere can someone buy Samsung DeX? I believe it is natively supported on all Samsung devices. E.g. - it is possible to buy a Samsung Tab S7 at a retail store, use a secondary display with built in USB-C PDP, and then bluetooth keyboard/mouse for interaction. If you are looking to replicate the setup with MFA, proxy, per-app vpn and more; VMware's Workspace ONE product lineup will, along with Zimperium's mobile security SDK. While we can't rewrite all your apps from Win32 to Android for you, we can help you rewrite them to use OIDC and auth with a IDP of your choice. Full disclosure; I work at VMware. Personally, I think the power savings along is impressive. A tablet consumes a fraction of the power of a thin client running VDI or mATX desktop. Users get a device that feels modern, mobile-by-default and cutting edge. The business gets to realize electricity savings. At the same time, the business gets to redesign apps and services to run on mobile, so they can get rid of tech debt in win32 app design choices.
- pjmlp 5y ago