7 ms·
This feels like a big win for privacy. I just hope that it's communicated well enough that users know to enable it when they send in their phone for repairs. I
by 63 4y ago
This feels like a big win for privacy. I just hope that it's communicated well enough that users know to enable it when they send in their phone for repairs.
I also wish there was a way to enable it if the touchscreen is inaccessible, as it usually is by the time I would consider seeking repairs.
- ISL 4y agoSmart repair shops will enable it (and document it) as Step 0 in a repair. What a great way to reduce risk and liability for everyone.
- deleted 4y ago[deleted]
- randombits0 4y agoIt’s also bs. The promise is only as good as the maker and the technology. Has it been vetted? Are there independent evaluations? Is Samsung willing accept any liabilities in the event of failure? All hype, no substance. Delete your data (with no way of verifying) and restore it on return.
- deleted 4y ago[deleted]
- deleted 4y ago[deleted]
- missedthecue 4y agoWhat would make you feel it's sufficiently vetted?
- DigiDigiorno 4y agoYou didn't ask me, but my input is that the two most obvious to me are: open source, so the effort can be vetted in good faith--or a insured guarante, so the consequences can be abated
- reidjs 4y agoTl;dr some security is better than none If it does anything to add privacy it’s a good thing, even if it can be sidestepped, it’s a good thing. Just because a lock is easily broken that doesn’t make it useless, it can still act as a deterrent for opportunistic crimes. One time I took a bike to festival. The first few days I was locking it up safely with a bike lock and chain, as I’m used to doing in the city. Eventually I decided to just use some rope to tie it to the rack with a basic square knot. I would always half expect to come back and it would be gone, but I rode that bike home from the festival. Even if the software is open source and provably secure (hahaha) you should probably assume that there is a way for a MOTIVATED actor to extract data from your internet connected device that THEY have possession of! Moral of the story is be smart and/or don’t put stuff on your phone you don’t want other people to see.
- DigiDigiorno 4y agoI mostly agree. I used the phrase "good faith" for that reason. You shouldn't assume anything is 100% secure. I'm just sympathetic to a good faith attempt without too many strings attached. That said, I agree something is better than nothing, but if they want praise from a more technical audience (hacker news for this example) they're gonna need to do more than tie the proverbial square knot.
- serf 4y ago>If it does anything to add privacy it’s a good thing, even if it can be sidestepped, it’s a good thing. I disagree. a bad lock that the consumer thinks is a good lock will be used to hide All The Secrets. In other words; when a consumer is lulled into a false sense of security by a manufacturer that calls everything secure and secret, they will guard their secrets with it. Very few people actually technically vet their security rationales, so the consumer that is relying on the company, who is then in-turn providing a subpar and broken security mechanism, is more-or-less screwed and is in actuality in a worse position than they would have been had they known to keep their secrets off of the broken platform. Your analogy fits the real life metaphor of a lock, it bends and breaks when we carry it into things like cell phones where 'a good lock' requires forethought and engineering time that a company isn't willing to sink into it; and this poor quality engineering is hidden behind a slick glass phone that by all means is beautiful. It's easy to hide the shoddy software engineering that is inside a beautiful product. It's hard to hide a poorly crafted physical lock -- the key won't work properly, it'll be hard to install, the surface finish will be low quality, etc etc. It's easier for the company, and ultimately more profitable, to just claim that a mechanism works and then deal with the damage to reputation later-on with the next 'WhizBang Product', especially since the mechanism itself is hard for Joe Everybody to vet in any significant way.
- serf 4y agonot the one you asked, but probably this same initiative pushed by a more reputable company. Samsung has been consumer-hostile in the mobile phone space for years, and nearly every 'vault' or 'secure enclave' or 'encrypted partition' that they've released has been broken in some fundamental and huge way since they started with the idea.[0] [0]: https://www.cvedetails.com/vendor/822/Samsung.html https://www.cvedetails.com/vendor/822/Samsung.html
- xeromal 4y agoIf you don't trust the manufacturer of your phone, don't buy the phone.
- randombits0 4y agoI can’t trust any of them. I still have a phone. I don’t trust it.
- stjohnswarts 4y agothen don't get it repaired and chuck it if it breaks ? Or fix it yourself?
- randombits0 4y agoI don’t trust it already. It does not have access to data I want private so it doesn’t matter what I do when it breaks. That’s the point.
- Etherlord87 4y agoThis could be generalized (and extrapolated) to: don't interact with what/who you don't trust. It's impossible to listen to this advice without a huge amount of naive trust.