4 ms·
I’m not sure Common Criteria has much to do with it. Companies only get CC certification so their devices or applications can be used by certain government orga
by barsonme 5y ago
I’m not sure Common Criteria has much to do with it. Companies only get CC certification so their devices or applications can be used by certain government organizations.
And so no company is going to target a cert level higher than the minimum they need to meet whatever business requirements are driving them to get CC certified.
And CC certainly isn’t a good reference for good security and cryptography engineering practices. It’s not bad, but it misses a lot.
- judge2020 5y agoTo add, while Obama was told he couldn't have an iPhone[0], Trump apparently had two NSA-secured iPhones in 2018[1], so the basic OS is secure (and likely loaded with MDM, maybe even jailbroken to disable safari JIT or disable safari entirely). 0: https://www.theguardian.com/technology/2013/dec/05/barack-obama-cant-have-an-iphone-security-blackberry https://www.theguardian.com/technology/2013/dec/05/barack-ob... 1: https://web.archive.org/web/20210203152520/https://www.wired.com/story/trump-iphone-security-risk/ https://web.archive.org/web/20210203152520/https://www.wired...
- saagarjha 5y agoJailbreaking the device just to reduce its attack surface area is quite amusing
- ignoramous 5y agoSimilarly, rooting an Android phone simultaneously increases its attack surface and helps you tie down components that you otherwise couldn't without recompiling the OS. Though, in the long run, I wonder if Androids can be more secure than iPhones.
- hansel_der 5y agosecurity is often the opposite of functionality/useability. "the most secure computer has neither power nor connectivity" android has a lot more functionality than ios, hence it is less secure.