3 ms·
I don't disagree. But there is some old rule about, even the best security can fail if the device is physically accessible.
by FrustratedMonky 18d ago
I don't disagree.
But there is some old rule about, even the best security can fail if the device is physically accessible.
- overfeed 18d agoThere are levels to defending against physical attacks, and Flock half-assed theirs by leaving the encryption key right on the file system, according to the reporting. Those more serious about security — like Apple — store keys in an "enclave" chip so it can't be easily extracted by an attacker doing the bare minimum
- jquery 18d agoApple did that… eventually. Early iPhones weren’t very secure. Apple only got serious after they dominated the market and reducing the theft value of iPhones became a priority.
- overfeed 18d agoEven the cheapest commodity encryption chips have had this capability for well over a decade now, Unlike Apple, Flock are not a hardware pioneer, not by a long shot. The Android documentation has an example of how to use hardware keys, and a Chinese OEM (IIRC) was found using the example key provided by Android sample code - and yet that was more effort than Flock applied, since their ARM SoC support it.