4 ms·
That’s going to be a hell of a security risk for us. I think it’ll be a no watches policy in the office going forward.
by sdcfgy 16d ago
That’s going to be a hell of a security risk for us. I think it’ll be a no watches policy in the office going forward.
- Krasnol 16d agoNo watches, no glasses and soon no implants....
- grey-area 16d agoSurely you'd also have to ban phones and other devices with microphones? All these devices can trivially be set up to record, so if your goal is full security, you should be a no phones workplace.
- chrisjj 16d agoMy device has no microphone. Promise. How would you verify?
- tencentshill 16d agoSome services offer modified devices without a camera or mic for high-security environments. https://www.gadgetreview.com/the-iphone-with-no-camera-and-why-nuclear-plants-pay-extra-for-it https://www.gadgetreview.com/the-iphone-with-no-camera-and-w... I imagine this is why Apple has kept the mic array and camera as separate removeable components in their devices when pretty much everything else is integrated.
- chrisjj 16d agoI have not readded those components. Promise. How would you verify?
- iamnothere 16d agoIf it’s an Apple device, it’s pretty easy to verify, if you’re not getting into the realm of spycraft. Open the stock recording app from the store and try to record after verifying the preferences allow recording. This is sufficient for catching bad actors who don’t have immense resources behind them. Even easier if it’s a managed device. If you’re worried about legit espionage, you hold the meeting or do the work in a SCIF, zero devices go in or out period, metal detectors and patdowns on both entry and exit.
- chrisjj 16d agoSo to enforce "to ban phones and other devices with microphones" you'd require the user hand over this phone and you grant access to operate it. I can imagine difficulties. > If you’re worried about legit espionage, you hold the meeting or do the work in a SCIF, zero devices go in or out period Well the problem with that is it would bar required phones and other devices.
- iamnothere 15d agoMany workplaces already require MDM for devices. Some don’t allow unmanaged onsite devices at all. It just depends on the sensitivity of the work. Maybe you haven’t been onsite at a defense contractor or a large financial firm, it can get very restrictive and you basically sign over a lot of your rights to work there. > Well the problem with that is it would bar required phones and other devices. That’s the point. Nothing goes in or out except through tightly controlled channels. SCIFs aren’t theoretical, they are in frequent use especially for anyone touching classified info. Large enterprises sometimes use similar facilities as needed for highly sensitive meetings where they can’t afford for anything to be leaked.
- chrisjj 15d agoSure, but we're discussing "the office". I can imagine this ban workplaces that aren't highly security concious.
- 15d ago
- r3trohack3r 16d agoIt’s the other way around - for secure environments there is an approved device list. If your device is not on that list, it does not go in. There is also an approved human list. And the approved humans carry responsibility and consequence when going into the space.
- chrisjj 16d agoMy device is listed model XYZ. Promise. How would you verify?
- tavavex 16d agoLook at it. This is the part where you repeat the same comment and substitute in modifying the software, opening the device and putting in listening hardware, putting a microphone under your skin, attaching a microcontroller to their outside walls to analyze vibration patterns, etc. Luckily, the world doesn't operate on pedantry. They care about removing 99% of attack vectors, the remaining 1% is covered by you being on the line. If your office permits outside recording hardware, someone 'forgetting' that their device was recording is a mishap. But if it only approves certain devices and finds out you did James Bond-level gadgetry to circumvent their measures, guess what image that'll paint on you.
- chrisjj 16d ago> But if it only approves certain devices and finds out I was thinking more of the cases it doesn't find out. 1% fail can be quite a lot.
- sdcfgy 16d agoAlready do that in some situations.
- voakbasda 16d agoGiven how much people tend to get distracted by their phones, I am surprised most workplaces do not have a phone ban.
- carlm42 16d agoThe irony is that that would probably be Apple's policy with its own offices if a competitor came up with such a feature.
- 0xDEADBEEFCAFE 16d agoAgreed, I was finally considering an Apple watch after years of hating how ugly they are but this is a hard pass for me. Back to the drawing board since now I need to consider privacy when selecting a watch brand..