Hacker News new | ask | show | jobs
by dpeck 5198 days ago
Don't connect to untrusted machines? As in, never connect to anything? What the point in having a smart phone then? (debatable why anyone needs one, I'm personally considering going to a dumb prepaid for cost/lack of need reasons)

I appreciate the paranoia, but it doesn't scale for normal users. With every page the users browses/app they install/etc there is a chance of the device executing code that's going to do something naughty. Operating under that assumption, one would hope that things like password managers would mitigate some of the long term effects of that, but as we see from this report that is not typically the case.

1 comments

I assume krupan meant never physically connect a smartphone to an untrusted PC. (That's one of the two methods for obtaining an encrypted password database described in the paper.)