8 ms·
iPhone Mirroring at work may expose employees’ personal information
- dcchambers 2y agoI miss out on a lot of nice MacOS features because I refuse to sign into my personal iCloud account on my work mac, even though we are allowed to do so. Oh well. Gotta draw the line somewhere I guess.
- deleted 2y ago[deleted]
- sigio 2y agoDuh, don't mix work and private devices / data
- dhosek 2y agoI was just discussing this with a friend. The one place where I’m willing to fudge things (corporate policies permitting) is putting my personal calendar on a work machine, work calendar on my personal systems, mostly because it makes dealing with the interface between the two simpler (plus then I get meetings showing up on my watch).
- quesera 2y agoDepending on your calendaring system(s), you can subscribe to your work calendar on your personal account, and vice versa. Although you should be careful about the latter! My life is simple enough that I just dupe the occasional MTWTF personal events as "reserved blocks" onto my work calendar, and maintain my off-hours and SS personal calendar separately.
- eastbound 2y agoYou can share the free/busy information only.
- accrual 2y agoRight. I don't even let my work laptop onto my home LAN. It's hardwired into its own /30 VLAN and can only see the gateway and internet.
- GavinGruesome 2y agoSo it is on your home LAN, just on a different VLAN than your infra. (which makes sense)
- accrual 2y agoRight, shares the same PHY/layer 1, but logically separated at layer 2. :)
- Havoc 2y agoUnless you believe your employer to be malicious I doubt this brings any real world benefit
- dml2135 2y agoDon’t you need to be signed in to the same iCloud account on both your laptop and phone to use this feature? That would mean that in order to encounter this issue you already need to be using a work account on a personal device, or vice versa. Since that’t the case I fail to see how this is a large vulnerability. The article doesn’t seem to address this point (possible I just missed this).
- deleted 2y ago[deleted]
- zippergz 2y agoA shocking number of people login to their personal Apple IDs (and email accounts and banks and etc. etc. etc.) on their work computer. I personally do not, but lots of people do.
- elliotec 2y agoI’d say generally for most people, at least anecdotally, their work laptop is their only laptop because they’re expensive and have good specs. Especially for Apple products (which is the majority of the share of hardware in this anecdote), it’s natural to want and expect the continuity between devices. Employers usually allow this or don’t explicitly forbid it, and most employees aren’t exactly security conscious or willing to sacrifice convenience. So it’s not that shocking to me, but it is weird that there isn’t more education or rules around it.
- RDaneel0livaw 2y agoThis is true for me. I have a personal desktop, but for mobility (laptop) my work issued MacBook M1 Pro is the only thing I have. There's no reason at all to purchase a personal laptop since my company is fully remote and they purchased the laptop from apple and had it directly sent to me, and have never required me to install any kind of monitoring software or control software on it at all.
- 2y ago
- deckar01 2y agoThere also seems to be a bug in the VPN that requires sending all traffic when the VPN address is on a different subnet. It should be possible to manually specify subnet mask, but it seems to be ignored. I’m not sure if the VPN is advertising this incorrectly, but it worked fine before upgrading.
- seneca 2y agoIt's incredible to me how many people log into personal account on work devices. People should really research the amount of data security tools harvest.
- dghlsakjg 2y agoWhere is a good place to start this research? We have crowdstrike falcon at work, and I would love to know what they are monitoring.
- Etheryte 2y agoIt's been quite a few years since I did anything in this space, but back in the day you could get quite a lot of information simply by wrapping things in sandbox-exec [0] and progressively adding allow rules as the application inevitably blew up. It's a fair bit of manual effort, and I wouldn't be surprised if someone has written a wrapper around it that automatically figures it out, but last I checked this was the most reliable way to explicitly see what a rogue application does. [0] https://www.karltarvas.com/macos-app-sandboxing-via-sandbox-exec https://www.karltarvas.com/macos-app-sandboxing-via-sandbox-...
- SketchySeaBeast 2y agoI sometimes see my coworkers with banking tabs open when they screen share. The level of trust is astounding.
- gnu8 2y agoYou will probably find that your corporate TLS MitM proxy excludes financial institutions so that employees can do their banking without any doubt that their own company would respect the confidentiality of their finances. If not, your cybersecurity team needs some help.
- flumpcakes 2y agoYes, when I was in charge of security at previous places we did not MITM a whole category of websites including banking, health, etc.
- likeabatterycar 2y agoSo the threshold of concern by a "security" company is "they might audit your apps and find out you're gay!" Yet not a single concern about tethering an iPhone (with an external connection) to a PC on the company's internal network, bypassing all firewalls, proxies, and other protections. That is grounds for immediate dismissal at some places. I expect security people to think more like network engineers and less like teenagers gossiping in the canteen.
- unsnap_biceps 2y agoThis isn't about tethering. It's about mirroring which requires the iPhone and Mac to be on the same WiFi. And you can't route data from the Mac through the phone via mirroring
- lxgr 2y agoI don't think iPhone Mirroring requires both devices being on the same (or in fact any) Wi-Fi network. It does however require them to be signed in to the same iCloud account.
- dml2135 2y agoI’ve noticed this as well, but actually not sure how the feature works if not over the LAN. Is it bluetooth? Or synced over icloud?
- happyopossum 2y agoIt's direct peer-to-peer wifi
- floam 2y agoGoogle "awdl"
- unsnap_biceps 2y agoPairing requires bluetooth, streaming requires WiFi, https://support.apple.com/en-us/120421 https://support.apple.com/en-us/120421 Under iPhone Mirroring system requirements Your iPhone and Mac are signed in to the same Apple Account using two-factor authentication. Your iPhone and Mac have Bluetooth and Wi-Fi turned on. Your iPhone is not sharing its cellular connection (Personal Hotspot is not in use). Your Mac is not sharing its internet connection or using AirPlay or Sidecar.
- mustyoshi 2y agoThe PSA should just be don't mix your personal and work devices.
- lxgr 2y agoSpeaking of iPhone Mirroring: Doesn't this effectively downgrade two-factor authentication to a single factor for flows like "tap 'yes' on your phone to login"? I've been wondering if there is a way for iOS authenticator apps to opt out of mirroring, but haven't found anything so far.
- anderiv 2y agoDon’t think so. Push notification flows like this fall into the “something you have” category (which you still do when using mirroring) and additionally when done properly, they require biometrics verification to respond to the “tap yes”.
- Havoc 2y agoTwo phones all the way. For most knowledge workers the cost of an mid tier iPhone is inconsequential anyway
- deleted 2y ago[deleted]
- ein0p 2y agoAnyone who uses their personal iPhone and/or iCloud account for work is a moron.
- notinmykernel 2y agoFYI: Amazon has been doing this to all employees who download any work related apps, since at least 2020.