In response to a blog post on Samsung Knox
samsungknox.com
samsungknox.com
http://mobilesecurityares.blogspot.co.uk/2014/10/why-samsung...
Not with a retraction.
Except repeat business from happy customers, but who cares about that?
Wait, doesn't that mean Samsung has a way to decrypt your data without the original password then? (Though I'm not familiar with MyKNOX so I'm not sure if that's what they're promising at all)
LOL no. If your security is predicated on the underlying OS perfectly enforcing permissions, then you're insecure.
> KNOX 1.0’s Personal containers, designed to let consumers experience the KNOX container, were not managed by an MDM agent. Therefore, they either store an alternative PIN or use a Samsung account to recover forgotten passwords. This KNOX 1.0 Personal container is not a part of the KNOX enterprise solution and was discontinued early this year.
My takeaway: unless you've had a 100% staff turnover this calendar year, at least some of the designers and implementers who thought it'd be OK to store a PIN in cleartext are still on the team. That's enough to make me run screaming from it.
I don't know why they are storing the key at all,
considering that it's supposed to be derived from the
password
A lot of people secure their phone with comparatively weak passwords of 4 to 6 numeric digits - I know I do!While you'd certainly want to hash that and include it in the key, using it as the sole source to derive the key wouldn't be enough. I can understand also trying to work in some sort of trusted hardware that imposes a rate limit and prevents performing attacks in parallel.
You'd still hash the user's password into the encryption key, of course. And shether Samsung has managed to get the trusted hardware right is of course another matter...