Samsung’s “repair mode” lets technicians look at your phone, not your data
arstechnica.com
arstechnica.com
I also wish there was a way to enable it if the touchscreen is inaccessible, as it usually is by the time I would consider seeking repairs.
All hype, no substance. Delete your data (with no way of verifying) and restore it on return.
If it does anything to add privacy it’s a good thing, even if it can be sidestepped, it’s a good thing.
Just because a lock is easily broken that doesn’t make it useless, it can still act as a deterrent for opportunistic crimes.
One time I took a bike to festival. The first few days I was locking it up safely with a bike lock and chain, as I’m used to doing in the city. Eventually I decided to just use some rope to tie it to the rack with a basic square knot. I would always half expect to come back and it would be gone, but I rode that bike home from the festival.
Even if the software is open source and provably secure (hahaha) you should probably assume that there is a way for a MOTIVATED actor to extract data from your internet connected device that THEY have possession of! Moral of the story is be smart and/or don’t put stuff on your phone you don’t want other people to see.
That said, I agree something is better than nothing, but if they want praise from a more technical audience (hacker news for this example) they're gonna need to do more than tie the proverbial square knot.
I disagree.
a bad lock that the consumer thinks is a good lock will be used to hide All The Secrets.
In other words; when a consumer is lulled into a false sense of security by a manufacturer that calls everything secure and secret, they will guard their secrets with it. Very few people actually technically vet their security rationales, so the consumer that is relying on the company, who is then in-turn providing a subpar and broken security mechanism, is more-or-less screwed and is in actuality in a worse position than they would have been had they known to keep their secrets off of the broken platform.
Your analogy fits the real life metaphor of a lock, it bends and breaks when we carry it into things like cell phones where 'a good lock' requires forethought and engineering time that a company isn't willing to sink into it; and this poor quality engineering is hidden behind a slick glass phone that by all means is beautiful.
It's easy to hide the shoddy software engineering that is inside a beautiful product. It's hard to hide a poorly crafted physical lock -- the key won't work properly, it'll be hard to install, the surface finish will be low quality, etc etc.
It's easier for the company, and ultimately more profitable, to just claim that a mechanism works and then deal with the damage to reputation later-on with the next 'WhizBang Product', especially since the mechanism itself is hard for Joe Everybody to vet in any significant way.
Samsung has been consumer-hostile in the mobile phone space for years, and nearly every 'vault' or 'secure enclave' or 'encrypted partition' that they've released has been broken in some fundamental and huge way since they started with the idea.[0]
It's impossible to listen to this advice without a huge amount of naive trust.
If you care deeply about the privacy of you data, don't hand your data on a physical device to anyone.
Do you mean the syncing of messages between logged in devices via the normal iMessage delivery mechanism (which I know is encrypted), or the "Messages in iCloud" feature?
It's hard for phone these days, but my PC's security model is I can easily lock myself out of it permanently.
Something is better than nothing. And the smoke and mirrors can still help. I agree OSS would be better, but I'll take what I can get. Even if that is just a moving ecosystem.
It was not even a sure thing that apple could do it.
The only reason Apple wouldn't do it was that it was such an embarrassment for its marketing to be shown to be a lie by something that had made national headlines.
As far as anybody being able to buy a 0-day, the price for such a 0-day is much higher for competitors' phones with better security.
Regarding the price of a 0-day, it is clear that the fbi bought it. (maybe it wasn't 0d at the time but it was an exploit.) The cost is irrelevant considering it was a state actor. In context of this discussion, apple resisted.
I'm all for more security and will take your recommendation for a vendor with more integrity. I think we have to weigh integrity vs capability, though. Good intentions don't confound tough adversaries.
The rest was media posturing.
You know independent infosec reviews are a thing, right?
Having a dedicated test image (like /recovery) is a possibility, but it wouldn't be the same environment as the user. The kernel may be different, maybe some runtime calibration data would be missing, and most customers want to see their phone working after a repair.
Having a builtin validating code as one commenter mentioned would be a godsend, but nearly all companies do everything they can to make customers not want their phones repaired.
[1] things like some sensors not working, accidentally clipping the tape with buttons, touch screen being funky (although that likely was due to non genuine screen), or my favorite - gps working but never able to get exact location)
Phones also have induction chargers on their back plates (Qi, usually to charge heaphones and stuff), that have to be enabled in software to charge.
Diagnosis software is built into iPhone so I can put a trust on it that it ain't sharing private data to the store employees.
Similarly they ran a diagnosis again at the end of repair. They did boot up the phone my themselves and ran it. Looks like they can run diagnosis on locked Phone.
This is overall much better than asking to unlock Phone.
If there was some kind of "status debug port" or whatever, the technicians could've done the various checks the sibling talks about without needing full control of my phone.
This is how my repair went through. At no point they asked for my passcode or to unlock Phone.
But, that being said, this does not address also one big hurdle for people sending their phone for repair, that is the opposite: losing all data. As a standard procedure, most technicians will reset to factory the device to see if it fixes the problem even when you send it for an unrelated issue.
ASUS warranty policy makes people click "I agree" to all their data being erased during a warranty repair. So what the repair needed is for a touch screen.
But how do you enter repair mode if your phone is broken?
I would assume someone could plug the phone in, use the mouse to enter their password and operate the UI to activate such a feature.
It will also work with any computer monitor that has a USB-C input and USB ports on it, usually, which are starting to become popular enough lately where I'm from.
I do think you have a point though. If you sent in a non-functional phone, and now it's in the shop being fixed, but the repair person needs to do a detailed check of the phone's operation, how can that be done safely without you being present? Maybe there could be a "repair mode password" that you can give out remotely and only allows the phone to enter repair mode.
I've never needed to repair a phone, but I assumed the repair shop asked for your password. (And some other comments have said as much here.) Do they not do that?
If they do, I like the idea of a "repair mode password".
> Samsung Electronics has officially unveiled the 'repair mode' service that can prevent the leakage of personal information of Galaxy smartphone users. 'Repair Mode' is a function that allows you to selectively disclose data when repairing a smartphone, and fundamentally blocks concerns about access or leakage of personal information that may occur during the repair process through some private companies. If the user executes 'Repair Mode' in the 'Battery and Device Care' menu in the 'Settings' of the smartphone, the smartphone is rebooted. After that, you won't be able to access your personal data, such as photos, messages, and accounts, and only use the default installed apps. After repairing the smartphone, the user can access personal data again after exiting the 'repair mode' and rebooting through pattern/fingerprint recognition. Samsung Electronics will first introduce 'repair mode' through software updates from the Galaxy S21 series, and plan to expand it to some other models in the future. Recently, Samsung Electronics has been continuously adding functions to protect and secure sensitive personal information to mobile devices such as smartphones and tablets. Last year, it unveiled 'Samsung Knox Vault,' an information protection technology that blocks various attacks by storing encrypted personal information in its own storage space. We released a new security solution to block. In a recent article published in the Samsung Newsroom, Shin Seung-won, managing director of the Security Team of Samsung Electronics' MX Division, said, "Technology is connecting the world closer than ever, but the risks are also increasing." "Samsung's top priority is customers “It’s about making sure you stay safe while trying out this new experience.”
For things like that, find an English language source or wait till one materializes.
If so, there is much more stored on a device then identity information.
Things that are not normally considered PII is for example your OS or even specific device model (i.e. user is using iPhone 12 Pro is not normally considered PII). As usual, it's not a crystal clear definition, so varies by context, company, industry regulations and so on.