3 ms·
> Without device encryption many devices wouldn't have drive encryption at all and therefore the NSA (with possession of the device) could trivially retrieve th
by justcommenting 12y ago
> Without device encryption many devices wouldn't have drive encryption at all and therefore the NSA (with possession of the device) could trivially retrieve that data.
This argument gets to the heart of mass surveillance vs. targeted/individualized surveillance. I personally prefer a world where someone would have to do something like steal my device to gain access to my data to a world where everyone's data is compromised by default all of the time. Maybe that makes me an outlier, but if I had owned one of these devices, I'd be pretty outraged...not unlike some were in the midst of the recent iCloud brouhaha.
- smtddr 12y agoNope, you're not an outlier. If someone steals your device, be it random theft or FBI/NSA storm your home, at least you know exactly what was taken and when and you probably know why(fair or otherwise). Much better for your state of mind to know for sure whether or not your data has been taken rather than what we have now - a constant state of paranoia because none of us really know what the NSA is up to. For the most part, I just assume any internet-capable device is compromised. One thing I still suspect is outside of NSA's wide-sweeping data collecting is proper usage of Steganography. http://en.wikipedia.org/wiki/Steganography http://en.wikipedia.org/wiki/Steganography >>For example, a sender might start with an innocuous image file and adjust the color of every 100th pixel to correspond to a letter in the alphabet, a change so subtle that someone not specifically looking for it is unlikely to notice it. I cannot comprehend that the NSA is scanning every image on the internet looking for patterns like that. If I were planning on some anti-establishment action, that's what I'd do. It would also be pretty cool for someone to make a tool that does this automatically. For regular people who just want plain privacy, keep on whistleblowing, keep on naming and shaming, keep on making the NSA's strategies not work by posting more and more tools & techniques to render their surveillance useless.... until we reach some kind of critical point that even the average-joe can't ignore.
- deleted 12y ago[deleted]
- deleted 12y ago[deleted]
- UnoriginalGuy 12y ago> I personally prefer a world where someone would have to do something like steal my device to gain access to my data to a world where everyone's data is compromised by default all of the time. That's a blatant strawman as that isn't what is being discussed here at all. In BOTH cases (with device encryption or without) the data is held on your device and only on your device. If you choose to upload it to OneDrive/iCloud/Google Drive/etc then that is your business but outside the scope of this "issue." > Maybe that makes me an outlier, but if I had owned one of these devices, I'd be pretty outraged...not unlike some were in the midst of the recent iCloud brouhaha. This issue is nothing like that issue. The fact you seem to think it is means you don't really understand this issue or that issue or both. This issue is that device encryption encrypts your drive, it then backs up your key by default to OneDrive. The data itself is still held on the device encrypted (unless you saved it to OneDrive or copied it into that virtual filesystem). The iCloud "issue" was that iCloud allowed infinite password guesses against an account without warning the owner or imposing a limit on the number of wrong attempts. iCloud is opt-in (during iOS setup), so people opted to have files stored there.
- justcommenting 12y agono. fwiw wrt icloud, i was referring to yosemite uploading certain pieces of user data outside many users' default assumptions about icloud's behavior to draw a general parallel in that some users may feel their trust has been violated when they don't know or understand how these systems behave and then find that out from someone else. i never claimed the systems behaved similarly in a technical sense--only that people might feel similarly.
- amalcon 12y agoMicrosoft would still be able to access the data on your device remotely without this copy of the key. They would just need to push an update to your phone that pulls the data out when you unlock it yourself.
- justcommenting 12y agoyes but even in that scenario, someone would presumably need to target my phone. and if large numbers of people were attacked in such a fashion, presumably the chances of detecting such an attack would also go up. and sure, phones have a huge attack surface in general, but changing defaults in this way makes certain attack scenarios easier, even if it also happens to be convenient for other users.
- amalcon 12y agoMy point is that the process is basically the same regardless of whether or not you have the key... unless the phone is stolen, of course. That's the case you claim not to be worried about, though.
- justcommenting 12y agodepends on your counterfactual. for some commenters on this thread, that seems to be storing data in plaintext. for me, the more reasonable counterfactual is a recovery key that i have sole control over, or perhaps an encrypted backup onto a disk i have sole control over. i think we agree that encrypting data at rest isn't sufficient for keeping private data private, but it may be necessary and is probably beneficial. for some users, keeping keys in microsoft's cloud may be a good option, but i think that hinges on whether they know and understand the implications of sending their recovery keys to microsoft. for example, maybe you lose your phone and some pickpocket doesn't grab your data very easily, but maybe the local police force gets your recovery key from microsoft and finds nude photos of your significant other before returning your phone to you. i'd be pretty displeased in that case, even if it helped me get my device back. i suspect many people storing recovery keys with microsoft don't know that this is happening, and might have made different choices if they knew that and understood some of the implications.