4 ms·
yes but even in that scenario, someone would presumably need to target my phone. and if large numbers of people were attacked in such a fashion, presumably the
by justcommenting 12y ago
yes but even in that scenario, someone would presumably need to target my phone. and if large numbers of people were attacked in such a fashion, presumably the chances of detecting such an attack would also go up.
and sure, phones have a huge attack surface in general, but changing defaults in this way makes certain attack scenarios easier, even if it also happens to be convenient for other users.
- amalcon 12y agoMy point is that the process is basically the same regardless of whether or not you have the key... unless the phone is stolen, of course. That's the case you claim not to be worried about, though.
- justcommenting 12y agodepends on your counterfactual. for some commenters on this thread, that seems to be storing data in plaintext. for me, the more reasonable counterfactual is a recovery key that i have sole control over, or perhaps an encrypted backup onto a disk i have sole control over. i think we agree that encrypting data at rest isn't sufficient for keeping private data private, but it may be necessary and is probably beneficial. for some users, keeping keys in microsoft's cloud may be a good option, but i think that hinges on whether they know and understand the implications of sending their recovery keys to microsoft. for example, maybe you lose your phone and some pickpocket doesn't grab your data very easily, but maybe the local police force gets your recovery key from microsoft and finds nude photos of your significant other before returning your phone to you. i'd be pretty displeased in that case, even if it helped me get my device back. i suspect many people storing recovery keys with microsoft don't know that this is happening, and might have made different choices if they knew that and understood some of the implications.
- amalcon 12y agoRight, I was trying to speak only to the possibility of getting data off the phone without physically obtaining the device. Those scenarios don't care if the storage is encrypted, and have nothing to do with scenarios where someone else has your phone.